12.03.2015 Views

FortiGate Administration Guide - FirewallShop.com

FortiGate Administration Guide - FirewallShop.com

FortiGate Administration Guide - FirewallShop.com

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

VPN IPSEC<br />

Auto Key<br />

Quick Mode<br />

Selector<br />

Optionally specify the source and destination IP addresses to be used as<br />

selectors for IKE negotiations. If the <strong>FortiGate</strong> unit is a dialup server, the<br />

default value 0.0.0.0/0 should be kept unless you need to circumvent<br />

problems caused by ambiguous IP addresses between one or more of<br />

the private networks making up the VPN. You can specify a single host IP<br />

address, an IP address range, or a network address. You may optionally<br />

specify source and destination port numbers and/or a protocol number.<br />

If you are editing an existing phase 2 configuration, the Source address<br />

and Destination address fields are unavailable if the tunnel has been<br />

configured to use firewall addresses as selectors. This option exists only<br />

in the CLI. See the dst-addr-type, dst-name, src-addr-type and<br />

src-name keywords for the vpn ipsec phase2 <strong>com</strong>mand in the<br />

<strong>FortiGate</strong> CLI Reference.<br />

Source address<br />

Source port<br />

Destination<br />

address<br />

Destination port<br />

Protocol<br />

If the <strong>FortiGate</strong> unit is a dialup server, type the<br />

source IP address that corresponds to the local<br />

sender(s) or network behind the local VPN peer (for<br />

example, 172.16.5.0/24 or<br />

172.16.5.0/255.255.255.0 for a subnet, or<br />

172.16.5.1/32 or<br />

172.16.5.1/255.255.255.255 for a server or<br />

host, or 192.168.10.[80-100] or<br />

192.168.10.80-192.168.10.100 for an<br />

address range). A value of 0.0.0.0/0 means all IP<br />

addresses behind the local VPN peer.<br />

If the <strong>FortiGate</strong> unit is a dialup client, source address<br />

must refer to the private network behind the<br />

<strong>FortiGate</strong> dialup client.<br />

Type the port number that the local VPN peer uses to<br />

transport traffic related to the specified service<br />

(protocol number). The range is 0 to 65535. To<br />

specify all ports, type 0.<br />

Type the destination IP address that corresponds to<br />

the recipient(s) or network behind the remote VPN<br />

peer (for example, 192.168.20.0/24 for a subnet,<br />

or 172.16.5.1/32 for a server or host, or<br />

192.168.10.[80-100] for an address range). A<br />

value of 0.0.0.0/0 means all IP addresses behind<br />

the remote VPN peer.<br />

Type the port number that the remote VPN peer uses<br />

to transport traffic related to the specified service<br />

(protocol number). The range is 0 to 65535. To<br />

specify all ports, type 0.<br />

Type the IP protocol number of the service. The<br />

range is 0 to 255. To specify all services, type 0.<br />

Internet browsing configuration<br />

You can enable VPN users to browse the Internet through the <strong>FortiGate</strong> unit. You do this<br />

with firewall policies. The required policies are different for policy-based and route-based<br />

VPNs. For more information about firewall policies, see “Configuring firewall<br />

policies” on page 271.<br />

Policy-based VPN Internet browsing configuration<br />

Configure an additional firewall policy as follows:<br />

Source Interface/Zone<br />

Source Address Name<br />

Destination Interface/Zone<br />

Destination Address Name<br />

Action<br />

Select the <strong>FortiGate</strong> unit public interface.<br />

Select All<br />

Select the <strong>FortiGate</strong> unit public interface.<br />

Select the remote network address name.<br />

Select IPSEC.<br />

<strong>FortiGate</strong> Version 3.0 MR5 <strong>Administration</strong> <strong>Guide</strong><br />

01-30005-0203-20070830 353

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!