12.03.2015 Views

FortiGate Administration Guide - FirewallShop.com

FortiGate Administration Guide - FirewallShop.com

FortiGate Administration Guide - FirewallShop.com

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Manual Key<br />

VPN IPSEC<br />

VPN Tunnel<br />

Select the tunnel that provides access to the private<br />

network behind the <strong>FortiGate</strong> unit.<br />

Inbound NAT<br />

Enable<br />

Configure other settings as required.<br />

Route-based VPN Internet browsing configuration<br />

Configure an additional firewall policy as follows:<br />

Source Interface/Zone Select the IPSec interface.<br />

Source Address Name Select All<br />

Destination Interface/Zone Select the <strong>FortiGate</strong> unit public interface.<br />

Destination Address Name Select All<br />

Action<br />

Select ACCEPT.<br />

NAT<br />

Enable<br />

Configure other settings as required.<br />

Manual Key<br />

If required, you can manually define cryptographic keys for establishing an IPSec<br />

VPN tunnel. You would define manual keys in situations where:<br />

• Prior knowledge of the encryption and/or authentication key is required (that is,<br />

one of the VPN peers requires a specific IPSec encryption and/or<br />

authentication key).<br />

• Encryption and authentication needs to be disabled.<br />

In both cases, you do not specify IPSec phase 1 and phase 2 parameters; you<br />

define manual keys on the VPN > IPSEC > Manual Key page instead.<br />

Note: It may not be safe or practical to define manual keys because network administrators<br />

must be trusted to keep the keys confidential, and propagating changes to remote VPN<br />

peers in a secure manner may be difficult.<br />

For general information about how to configure an IPSec VPN, see the <strong>FortiGate</strong><br />

IPSec VPN User <strong>Guide</strong>.<br />

Figure 227:Manual Key list<br />

Edit<br />

Delete<br />

Create New<br />

Tunnel Name<br />

Remote Gateway<br />

Create a new manual key configuration. See “Creating a new<br />

manual key configuration” on page 355.<br />

The names of existing manual key configurations.<br />

The IP addresses of remote peers or dialup clients.<br />

<strong>FortiGate</strong> Version 3.0 MR5 <strong>Administration</strong> <strong>Guide</strong><br />

354 01-30005-0203-20070830

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!