12.03.2015 Views

FortiGate Administration Guide - FirewallShop.com

FortiGate Administration Guide - FirewallShop.com

FortiGate Administration Guide - FirewallShop.com

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

VPN IPSEC<br />

Auto Key<br />

Figure 225:New Phase 2<br />

Name Type a name to identify the phase 2 configuration.<br />

Phase 1 Select the phase 1 tunnel configuration. See “Creating a new phase 1<br />

configuration” on page 345. The phase 1 configuration describes how<br />

remote VPN peers or clients will be authenticated on this tunnel, and how<br />

the connection to the remote peer or client will be secured.<br />

Advanced Define advanced phase 2 parameters. See “Defining phase 2 advanced<br />

settings” on page 351.<br />

Defining phase 2 advanced settings<br />

In phase 2, the <strong>FortiGate</strong> unit and the VPN peer or client exchange keys again to<br />

establish a secure <strong>com</strong>munication channel between them. The P2 Proposal<br />

parameters select the encryption and authentication algorithms needed to<br />

generate keys for protecting the implementation details of Security Associations<br />

(SAs). The keys are generated automatically using a Diffie-Hellman algorithm.<br />

A number of additional advanced phase 2 settings are available to enhance the<br />

operation of the tunnel. To modify IPSec phase 2 advanced parameters, go to<br />

VPN > IPSEC Auto Key (IKE), select Create Phase 2, and then select<br />

Advanced.For information about how to choose the correct advanced phase 2<br />

settings for your particular situation, see the <strong>FortiGate</strong> IPSec VPN User <strong>Guide</strong>.<br />

Figure 226:Phase 2 advanced settings<br />

Add<br />

<strong>FortiGate</strong> Version 3.0 MR5 <strong>Administration</strong> <strong>Guide</strong><br />

01-30005-0203-20070830 351

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!