03.04.2013 Views

fortigate-ipsec-40-mr3

fortigate-ipsec-40-mr3

fortigate-ipsec-40-mr3

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Clients, servers, and peers IPsec VPN concepts<br />

Clients, servers, and peers<br />

Figure 3: VPN tunnel between a FortiClient PC and a FortiGate unit<br />

Office network<br />

10.10.1.0/24<br />

Office fice FortiGa FortiGate unit<br />

a.1.2.3 b.4.5.6<br />

VPN tunnel<br />

On the PC, the FortiClient application acts as the local VPN gateway. Packets destined<br />

for the office network are encrypted, encapsulated into IPsec packets, and sent through<br />

the VPN tunnel to the FortiGate unit. Packets for other destinations are routed to the<br />

Internet as usual. IPsec packets arriving through the tunnel are decrypted to recover the<br />

original IP packets.<br />

A FortiGate unit in a VPN can have one of the following roles:<br />

server — responds to a request to establish a VPN tunnel.<br />

client — contacts a remote VPN gateway and requests a VPN tunnel.<br />

FortiClient PC<br />

peer — brings up a VPN tunnel or responds to a request to do so.<br />

The site-to-site VPN shown in Figure 2 is a peer-to-peer relationship. Either FortiGate unit<br />

VPN gateway can establish the tunnel and initiate communications. The<br />

FortiClient-to-FortiGate VPN shown in Figure 3 is a client-server relationship. The<br />

FortiGate unit establishes a tunnel when the FortiClient PC requests one.<br />

A FortiGate unit cannot be a VPN server if it has a dynamically-assigned IP address. VPN<br />

clients need to be configured with a static IP address for the server.<br />

A FortiGate unit acts as a server only when the remote VPN gateway has a dynamic IP<br />

address or is a client-only device or application, such as FortiClient.<br />

As a VPN server, a FortiGate unit can also offer automatic configuration for FortiClient<br />

PCs. The user needs to know only the IP address of the FortiGate VPN server and a valid<br />

user name/password. FortiClient downloads the VPN configuration settings from the<br />

FortiGate VPN server. For information about configuring a FortiGate unit as a VPN server,<br />

see the FortiClient Administration Guide.<br />

IPsec VPNs for FortiOS 4.0 MR3<br />

16 01-434-112804-20120111<br />

http://docs.fortinet.com/

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!