11.03.2015 Views

FortiGate IPSec VPN User Guide - FirewallShop.com

FortiGate IPSec VPN User Guide - FirewallShop.com

FortiGate IPSec VPN User Guide - FirewallShop.com

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Contents<br />

Authentication ............................................................................................. 35<br />

Configure the hub............................................................................................ 35<br />

Define the hub-spoke <strong>VPN</strong>s........................................................................ 35<br />

Define the hub-spoke firewall policies......................................................... 36<br />

Configuring <strong>com</strong>munication between spokes (policy-based <strong>VPN</strong>) ............. 37<br />

Configuring <strong>com</strong>munication between spokes (route-based <strong>VPN</strong>) .............. 38<br />

Using a zone as a concentrator............................................................ 38<br />

Using a zone with a policy as a concentrator ....................................... 38<br />

Using firewall policies as a concentrator .............................................. 39<br />

Configure the spokes ..................................................................................... 40<br />

Configuring firewall policies for hub-to-spoke <strong>com</strong>munication .................... 40<br />

Configuring firewall policies for spoke-to-spoke <strong>com</strong>munication ................ 41<br />

Dynamic spokes configuration example....................................................... 42<br />

Configure the hub (<strong>FortiGate</strong>_1) ................................................................. 43<br />

Define the IPsec configuration.............................................................. 43<br />

Define the firewall policies .................................................................... 43<br />

Configure <strong>com</strong>munication between spokes.......................................... 44<br />

Configure the spokes .................................................................................. 45<br />

Define the IPsec configuration.............................................................. 45<br />

Define the firewall policies .................................................................... 46<br />

Dynamic DNS configurations ......................................................... 49<br />

Configuration overview................................................................................... 49<br />

Dynamic DNS infrastructure requirements ................................................ 50<br />

General configuration steps .......................................................................... 50<br />

Configure the dynamically-addressed <strong>VPN</strong> peer ......................................... 51<br />

Configure the fixed-address <strong>VPN</strong> peer ......................................................... 53<br />

FortiClient dialup-client configurations......................................... 55<br />

Configuration overview................................................................................... 55<br />

Peer identification ....................................................................................... 56<br />

Automatic configuration of FortiClient dialup clients ................................... 56<br />

How the <strong>FortiGate</strong> unit determines which settings to apply .......... 56<br />

Using virtual IP addresses .......................................................................... 57<br />

FortiClient dialup-client infrastructure requirements .................................. 58<br />

FortiClient-to-<strong>FortiGate</strong> <strong>VPN</strong> configuration steps ....................................... 59<br />

Configure the <strong>FortiGate</strong> unit........................................................................... 59<br />

Configuring <strong>FortiGate</strong> unit <strong>VPN</strong> settings ..................................................... 60<br />

Configuring the <strong>FortiGate</strong> unit as a <strong>VPN</strong> policy server ............................... 62<br />

Configuring DHCP service on the <strong>FortiGate</strong> unit ........................................ 62<br />

Configure the FortiClient Host Security application ................................... 64<br />

Configuring FortiClient to work with <strong>VPN</strong> policy distribution ....................... 64<br />

Configuring FortiClient manually................................................................. 64<br />

<strong>FortiGate</strong> <strong>IPSec</strong> <strong>VPN</strong> Version 3.0 <strong>User</strong> <strong>Guide</strong><br />

4 01-30005-0065-20070716

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!