VPN
Phase 2
FortiGate-60M Administration Guide
01-28007-0144-20041217
253
2
Follow the general guidelines in these sections:
•
“Phase 2 list” on page 253
•
“Phase 2 basic settings” on page 253
•
“Phase 2 advanced options” on page 254
For information about how to choose the correct phase 2 settings for your particular
situation, refer to the
FortiGate VPN Guide
.
Phase 2 list
Figure 124:IPSec VPN Phase 2 list
Phase 2 basic settings
Figure 125:Phase 2 basic settings
Note:
The procedures in this section assume that you want the FortiGate unit to generate
unique IPSec encryption and authentication keys automatically. In situations where a remote
VPN peer requires a specific IPSec encryption and/or authentication key, you must configure
the FortiGate unit to use manual keys instead. For more information, see
“Manual key” on
page 255
.
Create New
Select Create New to create a new phase 2 tunnel configuration.
Tunnel Name
The names of existing tunnel configurations.
Remote Gateway
The names of the phase 1 configurations that are associated with the
tunnel configurations.
Lifetime (sec/kb)
The tunnel key lifetime.
Status
The current status of the tunnel. If Down, the tunnel is not processing
traffic. If Up, the tunnel is currently processing traffic. Unknown is
displayed for dialup tunnels.
Timeout
If the tunnel is processing VPN traffic, the Timeout value specifies
amount of time left before the next phase 2 key exchange. When the
phase 2 key expires, a new key is generated without interrupting service.
Edit, view or delete phase 2 configurations.
Summary of Contents for FortiGate FortiGate-60M
Page 12: ...Contents 12 01 28007 0144 20041217 Fortinet Inc Index 369 ...
Page 44: ...44 01 28007 0144 20041217 Fortinet Inc Changing the FortiGate firmware System status ...
Page 74: ...74 01 28007 0144 20041217 Fortinet Inc FortiGate IPv6 support System network ...
Page 82: ...82 01 28007 0144 20041217 Fortinet Inc Dynamic IP System DHCP ...
Page 116: ...116 01 28007 0144 20041217 Fortinet Inc Access profiles System administration ...
Page 234: ...234 01 28007 0144 20041217 Fortinet Inc Protection profile Firewall ...
Page 246: ...246 01 28007 0144 20041217 Fortinet Inc CLI configuration Users and authentication ...
Page 278: ...278 01 28007 0144 20041217 Fortinet Inc CLI configuration VPN ...
Page 340: ...340 01 28007 0144 20041217 Fortinet Inc Using Perl regular expressions Spam filter ...
Page 358: ...358 01 28007 0144 20041217 Fortinet Inc CLI configuration Log Report ...
Page 376: ...376 01 28007 0144 20041217 Fortinet Inc Index ...