VPN
Phase 1 basic settings
FortiGate-100A Administration Guide
01-28006-0068-20041105
247
Phase 1 basic settings
Figure 121:Phase 1 basic settings
Gateway Name
Type a name for the remote VPN peer. The remote peer can be either a
gateway to another network or an individual client on the Internet.
Remote
Gateway
Select a Remote Gateway address type.
If the remote VPN peer has a static IP address, select Static IP Address. See
“Gateway-to-gateway VPN” on page 278
.
If the remote VPN peer has a dynamically assigned IP address (DHCP or
PPPoE), or if the remote VPN peer has a static IP address that is not required
in the peer identification process, select Dialup User. See
“Dialup VPN” on
page 279
.
If the remote VPN peer uses Dynamic DNS, select Dynamic DNS. See
“Dynamic DNS VPN” on page 279
.
Depending upon the Remote Gateway address type you have selected,
certain fields may become available or be removed.
IP Address
If you select Static IP Address for Remote Gateway, enter the IP address of
the gateway or client.
Dynamic DNS
If you select Dynamic DNS for Remote Gateway, enter the Dynamic DNS
(DDNS) name. DDNS allows a computer to keep the same domain name
even if its IP address changes.
Mode
Select Aggressive or Main (ID Protection) mode. Both modes establish a
secure channel. When using aggressive mode, the VPN peers exchange
identifying information in the clear. When using main mode, identifying
information is hidden.
Aggressive mode is typically used when one VPN peer has a dynamic (dialup)
address and uses its ID as part of the authentication process. Main mode is
typically used when both VPN peers have static IP addresses.
When using aggressive mode, Diffie-Hellman (DH) groups cannot be
negotiated. Therefore, you should enter matching DH configurations on the
VPN peers when you use aggressive mode.
The VPN peers must use the same mode.
Authentication
Method
Either Preshared Key or RSA Signature.
Summary of Contents for FortiGate FortiGate-100A
Page 24: ...24 01 28006 0068 20041105 Fortinet Inc FortiLog documentation Introduction...
Page 72: ...72 01 28006 0068 20041105 Fortinet Inc Transparent mode VLAN settings System network...
Page 80: ...80 01 28006 0068 20041105 Fortinet Inc DHCP IP MAC binding settings System DHCP...
Page 114: ...114 01 28006 0068 20041105 Fortinet Inc Access profile options System administration...
Page 232: ...232 01 28006 0068 20041105 Fortinet Inc CLI configuration Firewall...
Page 244: ...244 01 28006 0068 20041105 Fortinet Inc peergrp Users and authentication...
Page 320: ...320 01 28006 0068 20041105 Fortinet Inc service smtp Antivirus...
Page 366: ...366 01 28006 0068 20041105 Fortinet Inc syslogd setting Log Report...
Page 380: ...380 01 28006 0068 20041105 Fortinet Inc Glossary...
Page 388: ...388 01 28006 0068 20041105 Fortinet Inc Index...