248
01-28006-0068-20041105
Fortinet Inc.
Phase 1 advanced options
VPN
Phase 1 advanced options
Figure 122:Phase 1 advanced settings
Pre-shared Key
If you select Preshared Key for Authentication Method, enter the preshared
key.
The key must contain at least 6 printable characters and should only be
known by network administrators. For optimum protection against currently
known attacks, the key should consist of a minimum of 16 randomly chosen
alphanumeric characters.
The VPN peers must use the same preshared key.
Certificate
Name
If you select RSA Signature for Authentication Method, enter the name of the
digital certificate. For information on how to use digital certificates, see
“Certificates” on page 268
.
Peer Options
Depending on the Remote Gateway and Mode settings, you may have a
choice of peer options to authenticate remote dialup clients or VPN peers with
local IDs, peer IDs, or certificate names. The local ID, peer ID, or certificate
name that you specify must match the local ID, peer ID, or certificate name of
the remote client or peer for the remote client or peer to start a VPN session
with the FortiGate unit.
•
Select Accept any peer ID to accept the local ID or peer ID of any remote
client or VPN peer.
•
Select Accept this peer ID to accept a remote client or group that has a
particular local ID or peer ID. Enter the value.
•
Select Accept peer ID in dialup group to accept remote clients that belong
to a particular dialup group. Select the group of dialup users.
•
Select Accept this peer certificate only to accept a remote client or group
that has a particular digital certificate. The certificate must be added to the
FortiGate configuration through the
config user peer
CLI command
before it can be selected here. For more information, see the “config user”
chapter of the
CLI Reference Guide
. See also
“Enabling VPN access for
specific certificate holders” on page 272
.
•
Select Accept this peer certificate group only to accept a group of
certificate holders. The group must be added to the FortiGate
configuration through the
config user peer
and
config user
peergrp
CLI commands before it can be selected here. For more
information, see the “config user” chapter of the
CLI Reference Guide
.
Summary of Contents for FortiGate FortiGate-100A
Page 24: ...24 01 28006 0068 20041105 Fortinet Inc FortiLog documentation Introduction...
Page 72: ...72 01 28006 0068 20041105 Fortinet Inc Transparent mode VLAN settings System network...
Page 80: ...80 01 28006 0068 20041105 Fortinet Inc DHCP IP MAC binding settings System DHCP...
Page 114: ...114 01 28006 0068 20041105 Fortinet Inc Access profile options System administration...
Page 232: ...232 01 28006 0068 20041105 Fortinet Inc CLI configuration Firewall...
Page 244: ...244 01 28006 0068 20041105 Fortinet Inc peergrp Users and authentication...
Page 320: ...320 01 28006 0068 20041105 Fortinet Inc service smtp Antivirus...
Page 366: ...366 01 28006 0068 20041105 Fortinet Inc syslogd setting Log Report...
Page 380: ...380 01 28006 0068 20041105 Fortinet Inc Glossary...
Page 388: ...388 01 28006 0068 20041105 Fortinet Inc Index...