12.03.2015 Views

FortiGate Administration Guide - FirewallShop.com

FortiGate Administration Guide - FirewallShop.com

FortiGate Administration Guide - FirewallShop.com

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Configuring peers and peer groups<br />

User<br />

Table 33: AV/Firewall supported product detection<br />

Product AV Firewall<br />

Norton Internet Security 2006 Y Y<br />

Trend Micro PC-cillin Y Y<br />

McAfee Y Y<br />

Sophos Anti-Virus Y N<br />

Panda Platinum 2006 Internet Security Y Y<br />

F-Secure Y Y<br />

Secure Resolutions Y Y<br />

Cat Computer Services Y Y<br />

AhnLab Y Y<br />

Kaspersky Y Y<br />

ZoneAlarm Y Y<br />

Configuring peers and peer groups<br />

You can define peers and peer groups used for authentication in some VPN<br />

configurations and for PKI certificate authentication. Use the CLI config user<br />

peer and config user peergrp <strong>com</strong>mands to do this. For more information,<br />

see the “User” chapter of the <strong>FortiGate</strong> CLI Reference.<br />

Authentication settings<br />

You can define global settings for user authentication, including authentication<br />

timeout, supported protocols, and authentication certificates.<br />

Authentication timeout controls how long an authenticated firewall connection can<br />

be idle before the user must authenticate again.<br />

When user authentication is enabled on a firewall policy, the authentication<br />

challenge is normally issued for any of the four protocols (dependent on the<br />

connection protocol):<br />

• HTTP (can also be set to redirect to HTTPS)<br />

• HTTPS<br />

• FTP<br />

• Telnet<br />

The selections made in the Protocol Support list of the Authentication Settings<br />

screen control which protocols support the authentication challenge. The user<br />

must connect with a supported protocol first so they can subsequently connect<br />

with other protocols. If HTTPS is selected as a method of protocol support, it<br />

allows the user to authenticate with a customized Local certificate.<br />

<strong>FortiGate</strong> Version 3.0 MR5 <strong>Administration</strong> <strong>Guide</strong><br />

394 01-30005-0203-20070830

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!