VPN
CLI configuration
FortiGate-3000 Administration Guide
01-28006-0010-20041105
281
2
Under Peer Options, select one of these options:
• To accept a specific certificate holder, select Accept this peer certificate only and
select the certificate that belongs to that certificate holder. The certificate must be
added to the FortiGate configuration through the
config user peer
CLI
command before it can be selected here. For more information, see the “config
user” chapter of the
CLI Reference Guide
.
• To accept a group of certificate holders, select Accept this peer certificate group
only and select the certificate that belongs to the group. The group must be added
to the FortiGate configuration through the
config user peergrp
CLI command
before it can be selected here. For more information, see the “config user” chapter
of the
CLI Reference Guide
.
3
If you want to define the DN of the FortiGate unit, select Advanced, and from the Local
ID list, select the DN of the FortiGate unit.
4
Select OK.
CLI configuration
This guide only covers Command Line Interface (CLI) commands, keywords, or
variables (in bold) that are not represented in the web-based manager. For complete
descriptions and examples of how to use CLI commands see the
FortiGate CLI
Reference Guide
.
ipsec phase1
In the web-based manager, the Dead Peer Detection option can be enabled when you
define advanced Phase 1 options. The
config vpn ipsec phase1
CLI command
supports additional options for specifying a long and short idle time, a retry count, and
a retry interval.
Command syntax pattern
config vpn ipsec phase1
edit <name_str>
set <keyword> <variable>
end
config vpn ipsec phase1
edit <name_str>
unset <keyword>
end
Summary of Contents for FortiGate 3000
Page 18: ...Contents 18 01 28006 0010 20041105 Fortinet Inc ...
Page 52: ...52 01 28006 0010 20041105 Fortinet Inc Changing the FortiGate firmware System status ...
Page 78: ...78 01 28006 0010 20041105 Fortinet Inc FortiGate IPv6 support System network ...
Page 86: ...86 01 28006 0010 20041105 Fortinet Inc Dynamic IP System DHCP ...
Page 116: ...116 01 28006 0010 20041105 Fortinet Inc FortiManager System config ...
Page 122: ...122 01 28006 0010 20041105 Fortinet Inc Access profiles System administration ...
Page 252: ...252 01 28006 0010 20041105 Fortinet Inc CLI configuration Users and authentication ...
Page 390: ...390 01 28006 0010 20041105 Fortinet Inc Glossary ...
Page 398: ...398 01 28006 0010 20041105 Fortinet Inc Index ...