03.04.2013 Views

fortigate-ipsec-40-mr3

fortigate-ipsec-40-mr3

fortigate-ipsec-40-mr3

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Phase 2 parameters<br />

Basic phase 2 settings<br />

FortiOS Handbook<br />

This section describes the phase 2 parameters that are required to establish<br />

communication through a VPN.<br />

The following topics are included in this section:<br />

Basic phase 2 settings<br />

Advanced phase 2 settings<br />

Configure the phase 2 parameters<br />

Advanced phase 2 settings<br />

After IPsec VPN phase 1 negotiations complete successfully, phase 2 negotiation begins.<br />

Phase 2 parameters define the algorithms that the FortiGate unit can use to encrypt and<br />

transfer data for the remainder of the session. The basic phase 2 settings associate IPsec<br />

phase 2 parameters with a phase 1 configuration.<br />

When defining phase 2 parameters, you can choose any set of phase 1 parameters to set<br />

up a secure connection and authenticate the remote peer.<br />

For more information on phase 2 settings in the web-based manager, see “Phase 2<br />

configuration” on page 31<br />

The information and procedures in this section do not apply to VPN peers that perform<br />

negotiations using manual keys. Refer to “Manual-key configurations” on page 183<br />

instead.<br />

The following additional advanced phase 2 settings are available to enhance the<br />

operation of the tunnel:<br />

P2 Proposals<br />

Replay detection<br />

Perfect forward secrecy (PFS)(<br />

Keylife<br />

Quick mode selectors<br />

FortiOS Handbook v3: IPsec VPNs<br />

01-434-112804-20120111 57<br />

http://docs.fortinet.com/

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!