
VPN
Phase 2
FortiGate-1000A/FA2 Administration Guide
01-28011-0254-20051115
267
To configure phase 2 settings
1
Go to
VPN > IPSEC > Phase 2
.
2
Follow the general guidelines in these sections:
•
“Phase 2 list” on page 267
•
“Phase 2 basic settings” on page 268
•
“Phase 2 advanced options” on page 268
For information about how to choose the correct phase 2 settings for your particular
situation, refer to the
FortiGate VPN Guide
.
Phase 2 list
Figure 130:IPSec VPN Phase 2 list
Note:
The procedures in this section assume that you want the FortiGate unit to generate
unique IPSec encryption and authentication keys automatically. In situations where a remote
VPN peer requires a specific IPSec encryption and/or authentication key, you must configure
the FortiGate unit to use manual keys instead. For more information, see
“Manual key” on
page 270
.
Create New
Select Create New to create a new phase 2 tunnel configuration.
Tunnel Name
The names of existing tunnel configurations.
Remote Gateway
The names of the phase 1 configurations that are associated with the
tunnel configurations.
Lifetime (sec/kb)
The tunnel key lifetime.
Status
The current status of the tunnel. If Down, the tunnel is not processing
traffic. If Up, the tunnel is currently processing traffic. Unknown is
displayed for dialup tunnels.
Timeout
If the tunnel is processing VPN traffic, the Timeout value specifies
amount of time left before the next phase 2 key exchange. When the
phase 2 key expires, a new key is generated without interrupting service.
Delete and Edit
icons
Delete or edit a phase 2 configuration.
Summary of Contents for FortiGate 1000A
Page 80: ...80 01 28011 0254 20051115 Fortinet Inc FortiGate IPv6 support System Network ...
Page 88: ...88 01 28011 0254 20051115 Fortinet Inc Dynamic IP System DHCP ...
Page 122: ...122 01 28011 0254 20051115 Fortinet Inc FortiManager System Config ...
Page 248: ...248 01 28011 0254 20051115 Fortinet Inc Protection profile Firewall ...
Page 260: ...260 01 28011 0254 20051115 Fortinet Inc CLI configuration User ...
Page 380: ...380 01 28011 0254 20051115 Fortinet Inc CLI configuration Log Report ...
Page 392: ...392 01 28011 0254 20051115 Fortinet Inc Glossary ...