VPN
CLI configuration
FortiGate-500A Administration Guide
01-28006-0100-20041105
279
Example
Use the following command to edit an IPSec VPN phase 1 configuration with the
following characteristics:
• Phase 1 configuration name:
Simple_GW
• Remote peer address type:
Dynamic
• Encryption and authentication proposal:
des-md5
• Authentication method:
psk
• Pre-shared key:
Qf2p3O93jIj2bz7E
• Mode:
aggressive
• Dead Peer Detection:
enable
• Long idle:
1000
• Short idle:
150
• Retry count:
5
• Retry interval:
30
config vpn ipsec phase1
edit Simple_GW
set Type dynamic
set proposal des-md5
set authmethod psk
set psksecret Qf2p3O93jIj2bz7E
set mode aggressive
set dpd enable
set dpd-idlecleanup 1000
set dpd-idleworry 150
set dpd-retrycount 5
set dpd-retryinterval 30
end
ipsec phase2
In addition to the advanced IPSec Phase 2 settings, the
config vpn ipsec
phase2
CLI command provides a way to bind the VPN tunnel selected in a Phase 2
configuration to a specific network interface. This setting may be required under
special circumstances to disable channel redundancy, but is not required for most
configurations.
Command syntax pattern
config vpn ipsec phase2
edit <name_str>
set <keyword> <variable>
end
config vpn ipsec phase2
edit <name_str>
unset <keyword>
end
Summary of Contents for FortiGate FortiGate-500A
Page 24: ...24 01 28006 0100 20041105 Fortinet Inc Customer service and technical support Introduction...
Page 46: ...46 01 28006 0100 20041105 Fortinet Inc Changing the FortiGate firmware System status...
Page 72: ...72 01 28006 0100 20041105 Fortinet Inc FortiGate IPv6 support System network...
Page 80: ...80 01 28006 0100 20041105 Fortinet Inc Dynamic IP System DHCP...
Page 110: ...110 01 28006 0100 20041105 Fortinet Inc FortiManager System config...
Page 116: ...116 01 28006 0100 20041105 Fortinet Inc Access profiles System administration...
Page 134: ...134 01 28006 0100 20041105 Fortinet Inc Shutdown System maintenance...
Page 248: ...248 01 28006 0100 20041105 Fortinet Inc CLI configuration Users and authentication...
Page 324: ...324 01 28006 0100 20041105 Fortinet Inc CLI configuration Antivirus...
Page 386: ...386 01 28006 0100 20041105 Fortinet Inc Glossary...
Page 394: ...394 01 28006 0100 20041105 Fortinet Inc Index...