12.03.2015 Views

FortiGate Administration Guide - FirewallShop.com

FortiGate Administration Guide - FirewallShop.com

FortiGate Administration Guide - FirewallShop.com

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Auto Key<br />

VPN IPSEC<br />

To define basic IPSec phase 1 parameters, go to VPN > IPSEC > Auto Key (IKE)<br />

and select Create Phase 1. For information about how to choose the correct<br />

phase 1 settings for your particular situation, see the <strong>FortiGate</strong> IPSec VPN User<br />

<strong>Guide</strong>.<br />

Figure 223:New Phase 1<br />

Name<br />

Remote Gateway<br />

IP Address<br />

Dynamic DNS<br />

Local Interface<br />

Type a name to represent the phase 1 definition. The maximum<br />

name length is 15 characters for an interface mode VPN, 35<br />

characters for a policy-based VPN. If Remote Gateway is Dialup<br />

User, the maximum name length is further reduced depending on the<br />

number of dialup tunnels that can be established: by 2 for up to 9<br />

tunnels, by 3 for up to 99 tunnels, 4 for up to 999 tunnels, and so on.<br />

For a tunnel mode VPN, the name should reflect the origination of<br />

the remote connection. For a route-based tunnel, the <strong>FortiGate</strong> unit<br />

also uses the name for the virtual IPSec interface that it creates<br />

automatically.<br />

Select the nature of the remote connection:<br />

• If the remote peer has a static IP address, select Static IP<br />

Address.<br />

• If one or more FortiClient or <strong>FortiGate</strong> dialup clients with<br />

dynamic IP addresses will connect to the <strong>FortiGate</strong> unit, select<br />

Dialup User.<br />

• If a remote peer that has a domain name and subscribes to a<br />

dynamic DNS service will be connecting to the <strong>FortiGate</strong> unit,<br />

select Dynamic DNS.<br />

If Static IP Address is selected, type the IP address of the remote<br />

peer.<br />

If Dynamic DNS is selected, type the domain name of the remote<br />

peer.<br />

This option is available in NAT/Route mode only. Select the name of<br />

the interface through which remote peers or dialup clients connect to<br />

the <strong>FortiGate</strong> unit. The <strong>FortiGate</strong> unit obtains the IP address of the<br />

interface from System > Network > Interface settings (see<br />

“Interface” on page 79) unless you are configuring an IPSec<br />

interface, in which case you can specify a different IP address in the<br />

Local Gateway IP field under Advanced settings (see “Local<br />

Gateway IP” on page 349).<br />

<strong>FortiGate</strong> Version 3.0 MR5 <strong>Administration</strong> <strong>Guide</strong><br />

346 01-30005-0203-20070830

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!