VPN
ipsec phase1
FortiGate-100 Administration Guide
01-28006-0003-20041105
273
2
Under Peer Options, select one of these options:
• To accept a specific certificate holder, select Accept this peer certificate only and
select the certificate that belongs to that certificate holder. The certificate must be
added to the FortiGate configuration through the
config user peer
CLI
command before it can be selected here. For more information, see the “config
user” chapter of the
CLI Reference Guide
.
• To accept a group of certificate holders, select Accept this peer certificate group
only and select the certificate that belongs to the group. The group must be added
to the FortiGate configuration through the
config user peergrp
CLI command
before it can be selected here. For more information, see the “config user” chapter
of the
CLI Reference Guide
.
3
If you want to define the DN of the FortiGate unit, select Advanced, and from the Local
ID list, select the DN of the FortiGate unit.
4
Select OK.
CLI configuration
This guide only covers Command Line Interface (CLI) commands, keywords, or
variables (in bold) that are not represented in the web-based manager. For complete
descriptions and examples of how to use CLI commands see the
FortiGate CLI
Reference Guide
.
ipsec phase1
In the web-based manager, the Dead Peer Detection option can be enabled when you
define advanced Phase 1 options. The
config vpn ipsec phase1
CLI command
supports additional options for specifying a long and short idle time, a retry count, and
a retry interval.
Command syntax pattern
config vpn ipsec phase1
edit <name_str>
set <keyword> <variable>
end
config vpn ipsec phase1
edit <name_str>
unset <keyword>
end
Summary of Contents for FortiGate 100
Page 24: ...24 01 28006 0003 20041105 Fortinet Inc FortiLog documentation Introduction ...
Page 72: ...72 01 28006 0003 20041105 Fortinet Inc Transparent mode VLAN settings System network ...
Page 80: ...80 01 28006 0003 20041105 Fortinet Inc DHCP IP MAC binding settings System DHCP ...
Page 114: ...114 01 28006 0003 20041105 Fortinet Inc Access profile options System administration ...
Page 232: ...232 01 28006 0003 20041105 Fortinet Inc CLI configuration Firewall ...
Page 244: ...244 01 28006 0003 20041105 Fortinet Inc peergrp Users and authentication ...
Page 320: ...320 01 28006 0003 20041105 Fortinet Inc service smtp Antivirus ...
Page 366: ...366 01 28006 0003 20041105 Fortinet Inc syslogd setting Log Report ...
Page 380: ...380 01 28006 0003 20041105 Fortinet Inc Glossary ...
Page 388: ...388 01 28006 0003 20041105 Fortinet Inc Index ...