Contents
FortiGate-500A Administration Guide
01-28006-0100-20041105
9
L2TP .............................................................................................................................. 267
Setting up a L2TP-based VPN.................................................................................... 268
Enabling L2TP and specifying an L2TP range............................................................ 268
Configuring a Windows 2000 client for L2TP.............................................................. 269
Configuring a Windows XP client for L2TP ................................................................. 270
Certificates ...................................................................................................................... 272
Viewing the certificate list............................................................................................ 273
Generating a certificate request.................................................................................. 273
Installing a signed certificate ...................................................................................... 275
Enabling VPN access for specific certificate holders ................................................. 276
CLI configuration............................................................................................................. 277
ipsec phase1............................................................................................................... 277
ipsec phase2............................................................................................................... 279
ipsec vip ...................................................................................................................... 280
Authenticating peers with preshared keys ...................................................................... 282
Gateway-to-gateway VPN............................................................................................... 282
Dialup VPN ..................................................................................................................... 283
Dynamic DNS VPN ......................................................................................................... 283
Manual key IPSec VPN................................................................................................... 284
Adding firewall policies for IPSec VPN tunnels............................................................... 284
Setting the encryption policy direction ........................................................................ 284
Setting the source address for encrypted traffic ......................................................... 284
Setting the destination address for encrypted traffic................................................... 285
Adding an IPSec firewall encryption policy ................................................................. 285
Internet browsing through a VPN tunnel ......................................................................... 285
Configuring Internet browsing through a VPN tunnel.................................................. 286
IPSec VPN in Transparent mode.................................................................................... 287
Special rules ............................................................................................................... 287
Hub and spoke VPNs...................................................................................................... 288
Configuring the hub..................................................................................................... 288
Configuring spokes ..................................................................................................... 290
Redundant IPSec VPNs.................................................................................................. 291
Configuring redundant IPSec VPNs............................................................................ 291
Configuring IPSec virtual IP addresses .......................................................................... 292
Troubleshooting .............................................................................................................. 294
IPS ....................................................................................................................... 295
Signature......................................................................................................................... 296
Predefined................................................................................................................... 296
Custom........................................................................................................................ 300
Anomaly .......................................................................................................................... 302
Anomaly CLI configuration.......................................................................................... 305
Configuring IPS logging and alert email.......................................................................... 306
Default fail open setting .................................................................................................. 306
Summary of Contents for FortiGate FortiGate-500A
Page 24: ...24 01 28006 0100 20041105 Fortinet Inc Customer service and technical support Introduction...
Page 46: ...46 01 28006 0100 20041105 Fortinet Inc Changing the FortiGate firmware System status...
Page 72: ...72 01 28006 0100 20041105 Fortinet Inc FortiGate IPv6 support System network...
Page 80: ...80 01 28006 0100 20041105 Fortinet Inc Dynamic IP System DHCP...
Page 110: ...110 01 28006 0100 20041105 Fortinet Inc FortiManager System config...
Page 116: ...116 01 28006 0100 20041105 Fortinet Inc Access profiles System administration...
Page 134: ...134 01 28006 0100 20041105 Fortinet Inc Shutdown System maintenance...
Page 248: ...248 01 28006 0100 20041105 Fortinet Inc CLI configuration Users and authentication...
Page 324: ...324 01 28006 0100 20041105 Fortinet Inc CLI configuration Antivirus...
Page 386: ...386 01 28006 0100 20041105 Fortinet Inc Glossary...
Page 394: ...394 01 28006 0100 20041105 Fortinet Inc Index...