258
01-28007-0144-20041217
Fortinet Inc.
Concentrator
VPN
Concentrator
In a hub-and-spoke configuration, connections to a number of remote peers radiate
from a single, central FortiGate unit. Site-to-site connections between the remote
peers do not exist; however, VPN tunnels between any two of the remote peers can
be established through the FortiGate unit “hub”.
In a hub-and-spoke network, all VPN tunnels terminate at the hub. The peers that
connect to the hub are known as “spokes”. The hub functions as a concentrator on the
network, managing all VPN connections between the spokes. VPN traffic passes from
one tunnel to the other through the hub.
You define a concentrator to include spokes in the hub-and-spoke configuration.
To define a concentrator
1
Go to
VPN > IPSEC > Concentrator
.
2
Follow the guidelines in these sections:
•
“Concentrator list” on page 258
•
“Concentrator options” on page 259
Concentrator list
Figure 129:IPSec VPN concentrator list
Authentication
Algorithm
Select one of the following message digests:
•
MD5-Message Digest 5 algorithm, which produces a 128-bit message
digest.
•
SHA1-Secure Hash Algorithm 1, which produces a 160-bit message
digest.
Authentication Key
If you selected:
•
MD5, type a 32-character hexadecimal number (0-9, a-f) separated
into two segments of 16 characters.
•
SHA1, type 40-character hexadecimal number (0-9, a-f) separated
into one segment of 16 characters and a second segment of 24
characters.
Concentrator
If the tunnel will be included in a hub-and-spoke configuration, you may
select the concentrator from the list. The hub must be added to the
FortiGate configuration before it can be selected here. See
“Concentrator” on page 258
.
Summary of Contents for FortiGate FortiGate-60M
Page 12: ...Contents 12 01 28007 0144 20041217 Fortinet Inc Index 369 ...
Page 44: ...44 01 28007 0144 20041217 Fortinet Inc Changing the FortiGate firmware System status ...
Page 74: ...74 01 28007 0144 20041217 Fortinet Inc FortiGate IPv6 support System network ...
Page 82: ...82 01 28007 0144 20041217 Fortinet Inc Dynamic IP System DHCP ...
Page 116: ...116 01 28007 0144 20041217 Fortinet Inc Access profiles System administration ...
Page 234: ...234 01 28007 0144 20041217 Fortinet Inc Protection profile Firewall ...
Page 246: ...246 01 28007 0144 20041217 Fortinet Inc CLI configuration Users and authentication ...
Page 278: ...278 01 28007 0144 20041217 Fortinet Inc CLI configuration VPN ...
Page 340: ...340 01 28007 0144 20041217 Fortinet Inc Using Perl regular expressions Spam filter ...
Page 358: ...358 01 28007 0144 20041217 Fortinet Inc CLI configuration Log Report ...
Page 376: ...376 01 28007 0144 20041217 Fortinet Inc Index ...