12.03.2015 Views

FortiGate Administration Guide - FirewallShop.com

FortiGate Administration Guide - FirewallShop.com

FortiGate Administration Guide - FirewallShop.com

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Auto Key<br />

VPN IPSEC<br />

Accept this<br />

peer certificate<br />

only<br />

Accept this<br />

peer certificate<br />

group only<br />

Defining phase 1 advanced settings<br />

The advanced P1 Proposal parameters select the encryption and authentication<br />

algorithms that the <strong>FortiGate</strong> unit uses to generate keys for the IKE exchange.<br />

Additional advanced phase 1 settings can be selected to ensure the smooth<br />

operation of phase 1 negotiations.<br />

To modify IPSec phase 1 advanced parameters, go to VPN > IPSEC ><br />

Auto Key (IKE), select Create Phase 1, and then select Advanced. For<br />

information about how to choose the correct advanced phase 1 settings for your<br />

particular situation, see the <strong>FortiGate</strong> IPSec VPN User <strong>Guide</strong>.<br />

Figure 224:Phase 1 advanced settings<br />

Authenticate remote peers or dialup clients using a security<br />

certificate. Select the certificate from the list adjacent to the option.<br />

You must add peer certificates to the <strong>FortiGate</strong> configuration through<br />

the User > PKI page before you can select them here. For more<br />

information, see “PKI authentication” on page 384.<br />

This option is available when Authentication Method is set to RSA<br />

Signature.<br />

Use a certificate group to authenticate dialup clients that have<br />

dynamic IP addresses and use unique certificates.<br />

Select the name of the peer group from the list. You must first create<br />

the group through the config user peergrp CLI <strong>com</strong>mand<br />

before you can select it. For more information, see the “user” chapter<br />

of the <strong>FortiGate</strong> CLI Reference. Members of the peer group must be<br />

certificates added through the User > PKI page or the config<br />

user peer CLI <strong>com</strong>mand.<br />

This option is available when Authentication Method is set to RSA<br />

Signature and Remote Gateway is set to Dialup User.<br />

Advanced Define advanced phase 1 parameters. See “Defining phase 1<br />

advanced settings” on page 348.<br />

Add<br />

<strong>FortiGate</strong> Version 3.0 MR5 <strong>Administration</strong> <strong>Guide</strong><br />

348 01-30005-0203-20070830

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!