12.03.2015 Views

FortiGate Administration Guide - FirewallShop.com

FortiGate Administration Guide - FirewallShop.com

FortiGate Administration Guide - FirewallShop.com

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

User<br />

Authentication settings<br />

When you enable user authentication on a firewall policy, the end users using the<br />

firewall policy will be challenged to authenticate themselves. In the case of user ID<br />

and password authentication, end users must provide their user name and<br />

password. In case of certificate authentication (HTTPS or HTTP redirected to<br />

HTTPS only), you can install customized certificates on the <strong>FortiGate</strong> unit and the<br />

end users can also have customized certificates installed on their browsers.<br />

Otherwise, the end users will see a warning message and have to accept the<br />

default <strong>FortiGate</strong> certificate, which the end users’ browsers may deem as invalid.<br />

Note: When you use certificate authentication, if you do not specify any certificate when<br />

you create the firewall policy, the global settings will be used. If you specify a certificate, the<br />

per-policy setting will overwrite the global setting. For information about how to use<br />

certificate authentication, see <strong>FortiGate</strong> Certificate Management User <strong>Guide</strong>.<br />

Go to User > Authentication > Authentication to configure user authentication<br />

global settings.<br />

Figure 267:Authentication Settings<br />

Authentication Settings<br />

Authentication TImeout<br />

Protocol Support<br />

Certificate<br />

Apply<br />

Enter a number, in minutes, from 1 to 480. The default value<br />

for Authentication Timeout is 30.<br />

Select protocol(s) to challenge during user authentication.<br />

• HTTP<br />

• Redirect HTTP Challenge to a Secure Channel (HTTPS) -<br />

if required, redirect an HTTP challenge to an HTTPS<br />

• HTTPS<br />

• FTP<br />

• Telnet<br />

If using HTTPS protocol support, select the Local certificate<br />

from the drop-down list for user authentication. Only available<br />

if HTTPS protocol support is selected (including redirection<br />

from HTTP). The default is ‘self-sign’.<br />

Apply selections for user Authentication Settings.<br />

<strong>FortiGate</strong> Version 3.0 MR5 <strong>Administration</strong> <strong>Guide</strong><br />

01-30005-0203-20070830 395

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!