03.04.2013 Views

fortigate-ipsec-40-mr3

fortigate-ipsec-40-mr3

fortigate-ipsec-40-mr3

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

FortiOS Handbook<br />

Internet-browsing configuration<br />

This section explains how to support secure web browsing performed by dialup VPN<br />

clients, and/or hosts behind a remote VPN peer. Remote users can access the private<br />

network behind the local FortiGate unit and browse the Internet securely. All traffic<br />

generated remotely is subject to the security policy that controls traffic on the private<br />

network behind the local FortiGate unit.<br />

The following topics are included in this section:<br />

Configuration overview<br />

Configuration overview<br />

Creating an Internet browsing security policy<br />

Routing all remote traffic through the VPN tunnel<br />

A VPN provides secure access to a private network behind the FortiGate unit. You can<br />

also enable VPN clients to access the Internet securely. The FortiGate unit inspects and<br />

processes all traffic between the VPN clients and hosts on the Internet according to the<br />

Internet browsing policy. This is accomplished even though the same FortiGate interface<br />

is used for both encrypted VPN client traffic and unencrypted Internet traffic.<br />

In Figure 21, FortiGate_1 enables secure Internet browsing for FortiClient Endpoint<br />

Security users such as Dialup_1 and users on the Site_2 network behind FortiGate_2,<br />

which could be a VPN peer or a dialup client.<br />

Figure 21: Example Internet-browsing configuration<br />

Site_1<br />

Dialup_1<br />

FortiGate_1<br />

FortiGate_<br />

Users browse<br />

internet through<br />

the VPN tunnel<br />

Web server<br />

FG_Dialup_2<br />

_Dialup_2<br />

Site_2<br />

You can adapt any of the following configurations to provide secure Internet browsing:<br />

a gateway-to-gateway configuration (see “Gateway-to-gateway configurations” on<br />

page 69)<br />

a FortiClient dialup-client configuration (see “FortiClient dialup-client configurations”<br />

on page 115)<br />

FortiOS Handbook v3: IPsec VPNs<br />

01-434-112804-20120111 147<br />

http://docs.fortinet.com/

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!