IPSec VPN
Auto Key
FortiGate Version 4.0 Administration Guide
01-400-89802-20090424
533
•
Redundant configurations
Route-based VPNs help to simplify the implementation of VPN tunnel redundancy. You
can configure several routes for the same IP traffic with different route metrics. You can
also configure the exchange of dynamic (RIP, OSPF, or BGP) routing information through
VPN tunnels. If the primary VPN connection fails or the priority of a route changes through
dynamic routing, an alternative route will be selected to forward traffic through the
redundant connection.
A simple way to provide failover redundancy is to create a backup IPSec interface. You
can do this in the CLI. For more information, including an example configuration, see the
monitor-phase1
keyword for the
ipsec vpn phase1-interface
command in the
.
Routing
Optionally, through the CLI, you can define a specific default route for a virtual IPSec
interface. For more information, see the
default-gw
keyword for the
vpn ipsec phase1-interface
command in the
.
Auto Key
You can configure two VPN peers (or a FortiGate dialup server and a VPN client) to
generate unique Internet Key Exchange (IKE) keys automatically during the IPSec
phase 1 and phase 2 exchanges.
When you define phase 2 parameters, you can choose any set of phase 1 parameters to
set up a secure connection for the tunnel and authenticate the remote peer.
Auto Key configuration applies to both tunnel-mode and interface-mode VPNs.
To configure an Auto Key VPN, go to
VPN > IPSEC > Auto Key (IKE)
.
Figure 350: Auto Key list
Create Phase 1
Create a new phase 1 tunnel configuration. For more information, see
“Creating a new phase 1 configuration” on page 534
Create Phase 2
Create a new phase 2 configuration. For more information, see
new phase 2 configuration” on page 538
.
Phase 1
The names of existing phase 1 tunnel configurations.
Phase 2
The names of existing phase 2 configurations.
Interface Binding
The names of the local interfaces to which IPSec tunnels are bound. These
can be physical, aggregate, VLAN, inter-VDOM link or wireless interfaces.
Delete and Edit icons
Delete or edit a phase 1 configuration.
Edit
Delete
Summary of Contents for Gate 60D
Page 705: ...www fortinet com...
Page 706: ...www fortinet com...