03.04.2013 Views

fortigate-ipsec-40-mr3

fortigate-ipsec-40-mr3

fortigate-ipsec-40-mr3

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

IPsec VPN concepts Security Association<br />

Security Association<br />

To configure default Phase 2 settings on a FortiGate unit, you need only select the name<br />

of the corresponding Phase 1 configuration. In FortiClient, no action is required to enable<br />

default Phase 2 settings.<br />

For more detailed information about Phase 2 settings, see “Phase 2 parameters” on<br />

page 57.<br />

The establishment of a Security Association (SA) is the successful outcome of Phase 1<br />

negotiations. Each peer maintains a database of information about VPN connections. The<br />

information in each SA can include cryptographic algorithms and keys, keylife, and the<br />

current packet sequence number. This information is kept synchronized as the VPN<br />

operates. Each SA has a Security Parameter Index (SPI) that is provided to the remote<br />

peer at the time the SA is established. Subsequent IPsec packets from the peer always<br />

reference the relevant SPI. It is possible for peers to have multiple VPNs active<br />

simultaneously, and correspondingly multiple SPIs.<br />

FortiOS Handbook v3: IPsec VPNs<br />

01-434-112804-20120111 19<br />

http://docs.fortinet.com/

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!