12.03.2015 Views

FortiGate Administration Guide - FirewallShop.com

FortiGate Administration Guide - FirewallShop.com

FortiGate Administration Guide - FirewallShop.com

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Manual Key<br />

VPN IPSEC<br />

Remote SPI<br />

Remote Gateway<br />

Local Interface<br />

Encryption<br />

Algorithm<br />

Type a hexadecimal number (up to 8 characters, 0-9, a-f) that<br />

represents the SA that handles inbound traffic on the local <strong>FortiGate</strong><br />

unit. The valid range is from 0x100 to 0xffffffff. This value must<br />

match the Local SPI value in the manual key configuration at the<br />

remote peer.<br />

Type the IP address of the public interface to the remote peer. The<br />

address identifies the recipient of ESP datagrams.<br />

This option is available in NAT/Route mode only. Select the name of<br />

the interface to which the IPSec tunnel will be bound. The <strong>FortiGate</strong><br />

unit obtains the IP address of the interface from System > Network<br />

> Interface settings (see “Interface” on page 79).<br />

Select one of the following symmetric-key encryption algorithms:<br />

• DES-Digital Encryption Standard, a 64-bit block algorithm that<br />

uses a 56-bit key.<br />

• 3DES-Triple-DES, in which plain text is encrypted three times by<br />

three keys.<br />

• AES128-A 128-bit block algorithm that uses a 128-bit key.<br />

• AES192-A 128-bit block algorithm that uses a 192-bit key.<br />

• AES256-A 128-bit block algorithm that uses a 256-bit key.<br />

Note: The algorithms for encryption and authentication cannot both<br />

be NULL.<br />

Encryption Key<br />

Authentication<br />

Algorithm<br />

If you selected:<br />

• DES, type a 16-character hexadecimal number (0-9, a-f).<br />

• 3DES, type a 48-character hexadecimal number (0-9, a-f)<br />

separated into three segments of 16 characters.<br />

• AES128, type a 32-character hexadecimal number (0-9, a-f)<br />

separated into two segments of 16 characters.<br />

• AES192, type a 48-character hexadecimal number (0-9, a-f)<br />

separated into three segments of 16 characters.<br />

• AES256, type a 64-character hexadecimal number (0-9, a-f)<br />

separated into four segments of 16 characters.<br />

Select one of the following message digests:<br />

• MD5-Message Digest 5 algorithm, which produces a 128-bit<br />

message digest.<br />

• SHA1-Secure Hash Algorithm 1, which produces a 160-bit<br />

message digest.<br />

Note: The Algorithms for encryption and authentication cannot both<br />

be NULL.<br />

Authentication Key If you selected:<br />

• MD5, type a 32-character hexadecimal number (0-9, a-f)<br />

separated into two segments of 16 characters.<br />

• SHA1, type 40-character hexadecimal number (0-9, a-f)<br />

separated into one segment of 16 characters and a second<br />

segment of 24 characters.<br />

IPSec Interface<br />

Mode<br />

Create a virtual interface for the local end of the VPN tunnel.<br />

This <strong>com</strong>mand is available only in NAT/Route mode.<br />

<strong>FortiGate</strong> Version 3.0 MR5 <strong>Administration</strong> <strong>Guide</strong><br />

356 01-30005-0203-20070830

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!