
IPSec VPN
Configuring encrypt policies
FortiGate-400 Installation and Configuration Guide
225
Adding a source address
The source address is located within the internal network of the local VPN peer. It can
be a single computer address or the address of a network.
1
Go to
Firewall > Address
.
2
Select an internal interface. (Methods will differ slightly between FortiGate models.)
3
Select New to add an address.
4
Enter the Address Name, IP Address, and NetMask for a single computer or for an
entire subnetwork on an internal interface of the local VPN peer.
5
Select OK to save the source address.
Adding a destination address
The destination address can be a VPN client address on the Internet or the address of
a network behind a remote VPN gateway.
1
Go to
Firewall > Address
.
2
Select an external interface. (Methods will differ slightly between FortiGate models.)
3
Select New to add an address.
4
Enter the Address Name, IP Address, and NetMask for a single computer or for an
entire subnetwork on an internal interface of the remote VPN peer.
5
Select OK to save the source address.
Adding an encrypt policy
1
Go to
Firewall > Policy
.
2
Use the policy grid to choose the policy list to which to add the policy.
For example, port1
->
port2 or port3
->
port2.
3
Select New to add a new policy.
4
Set Source to the source address.
5
Set Destination to the destination address.
6
Set Service to control the services allowed over the VPN connection.
You can select ANY to allow all supported services over the VPN connection or select
a specific service or service group to limit the services allowed over the VPN
connection.
7
Set Action to ENCRYPT.
8
Configure the ENCRYPT parameters.
VPN Tunnel
Select an Auto Key tunnel for this encrypt policy.
Allow inbound
Select Allow inbound to enable inbound users to connect to the source
address.
Allow outbound
Select Allow outbound to enable outbound users to connect to the
destination address.
Summary of Contents for FortiGate 400
Page 13: ...Contents FortiGate 400 Installation and Configuration Guide 13 Glossary 295 Index 299 ...
Page 14: ...Contents 14 Fortinet Inc ...
Page 44: ...44 Fortinet Inc Next steps Getting started ...
Page 74: ...74 Fortinet Inc Transparent mode configuration examples Transparent mode installation ...
Page 148: ...148 Fortinet Inc Providing DHCP services to your internal network Network configuration ...
Page 168: ...168 Fortinet Inc Customizing replacement messages System configuration ...
Page 200: ...200 Fortinet Inc Content profiles Firewall configuration ...
Page 258: ...258 Fortinet Inc Logging attacks Network Intrusion Detection System NIDS ...
Page 294: ...294 Fortinet Inc Configuring alert email Logging and reporting ...
Page 298: ...298 Fortinet Inc Glossary ...
Page 308: ...308 Fortinet Inc Index ...