IPSec VPN
Auto Key
FortiGate Version 4.0 Administration Guide
01-400-89802-20090424
537
•
Figure 352: Phase 1 advanced settings
Enable IPSec Interface
Mode
This is available in NAT/Route mode only.
Create a virtual interface for the local end of the VPN tunnel. Select this
option to create a route-based VPN, clear it to create a policy-based
VPN.
IPv6 Version
Select if you want to use IPv6 addresses for the remote gateway and
interface IP addresses. This is available only when Enable IPSec
Interface Mode is enabled.
Local Gateway IP
If you selected Enable IPSec Interface Mode, specify an IP address for
the local end of the VPN tunnel. Select one of the following:
Main Interface IP
— The FortiGate unit obtains the IP address of the
interface from the network interface settings. For more information, see
.
Specify
— You can specify a secondary address of the interface
selected in the phase 1
Local Interface
field. For more information, see
“Local Interface” on page 535
.
You cannot configure Interface mode in a Transparent mode VDOM.
P1 Proposal
Select the encryption and authentication algorithms used to generate
keys for protecting negotiations.
Add or delete encryption and authentication algorithms as required.
Select a minimum of one and a maximum of three combinations. The
remote peer or client must be configured to use at least one of the
proposals that you define.
Select one of the following symmetric-key algorithms:
DES
— Digital Encryption Standard, a 64-bit block algorithm that uses a
56-bit key.
3DES
— Triple-DES, in which plain text is encrypted three times by three
keys.
AES128
— a 128-bit block Cipher Block Chaining (CBC) algorithm that
uses a 128-bit key.
AES192
— a 128-bit block Cipher Block Chaining (CBC) algorithm that
uses a 192-bit key.
AES256
— a 128-bit block Cipher Block Chaining (CBC) algorithm that
uses a 256-bit key.
Select either of the following message digests to check the authenticity
of messages during phase 1 negotiations:
MD5
— Message Digest 5, the hash algorithm developed by RSA Data
Security.
SHA1
— Secure Hash Algorithm 1, which produces a 160-bit message
digest.
To specify a third combination, use the
Add
button beside the fields for
the second combination.
Add
Delete
Summary of Contents for Gate 60D
Page 705: ...www fortinet com...
Page 706: ...www fortinet com...