![Fortinet FortiWAN Handbook Download Page 197](http://html1.mh-extra.com/html/fortinet/fortiwan/fortiwan_handbook_2322088197.webp)
IPSec set up
IPSec
Keylife
Enter the time interval (in seconds) that the negotiated secret keys
(used for IPSec SA) are valid during. For the expiration of keys, IKE
Phase 2 is performed automatically to negotiate new keys without
interrupting normal IPSec VPN communications. Keylife of IPSec
SA's secret keys is suggested to be shorter than the keylife of
ISAKMP SA's secret keys.
Quick Mode
Configurations of Quick Mode is required only for IPSec Tunnel
Mode. A Quick Mode selector determines the acceptance or
rejection of transmission through the IPSec VPN tunnel for packets.
It usually implies the IPSec VPN communications between private
networks (hosts) behind the two FortiWANs unit (IPsec VPN
gateways). Packets coming form the networks behind the local
FortiWAN and going to another network behind the remote
FortiWAN are evaluated by Quick Mode selectors at the local
FortiWAN unit. Only packets matching the selector are allowed to
be transferred via the IPSec VPN tunnel. A Quick Mode selector
consists of the following five filters:
l
Source:
the source of a packet that is allowed to be transferred via
the IPSec VPN tunnel. It can be an IPv4 address or an IPv4 subnet
behind the local FortiWAN.
l
Source Port:
the source port of a packet that is allowed to be
transferred via the IPSec VPN tunnel.
l
Destination :
the destination of a packet that is allowed to be
transferred via the IPSec VPN tunnel. It can be an IPv4 address or an
IPv4 subnet behind the remote FortiWAN.
l
Destination Port:
the destination port of a packet that is allowed to
be transferred via the IPSec VPN tunnel.
l
Protocol:
the protocol of a packet that is allowed to be transferred
via the IPSec VPN tunnel.
Note that one pair of source and destination is not allowed to be set
to multiple Quick Mode selectors, neither a subset of the pair is.
Make sure the pair of source and destination defined in a Quick
Mode selector is absolutely incompatible to other Quick Mode
selectors (no matter which Phase 1 configuration they belong to,
current one or others).
It's necessary to have an Auto Routing (AR) filter that is
correspondent with the Quick Mode selector you made, see the
following section "
Define routing policies for an IPSec VPN
".
So far, we have introduced the concept of IPSec VPN and how to configure the settings of FortiWAN's IPSec.
However, the success of the IPSec VPN establishment and communications actually requires the cooperation between
FortiWAN' IPSec and other functions, Auto Routing, NAT and Tunnel Routing. In other words, besides the
configurations of IPSec, correspondent policies of Auto Routing, NAT or Tunnel Routing are required to set up an
IPSec VPN. See "
Define routing policies for IPSec VPN
".
FortiWAN Handbook
Fortinet Technologies Inc.
197