Manual Key
IPSec VPN
FortiGate Version 4.0 Administration Guide
542
01-400-89802-20090424
Figure 355: Manual Key list
Creating a new manual key configuration
If one of the VPN devices is manually keyed, the other VPN device must also be manually
keyed with the identical authentication and encryption keys. In addition, it is essential that
both VPN devices be configured with complementary Security Parameter Index (SPI)
settings. The administrators of the devices need to cooperate to achieve this.
Each SPI identifies a Security Association (SA). The value is placed in ESP datagrams to
link the datagrams to the SA. When an ESP datagram is received, the recipient refers to
the SPI to determine which SA applies to the datagram. You must manually specify an SPI
for each SA. There is an SA for each direction, so for each VPN you must specify two
SPIs, a local SPI and a remote SPI, to cover bidirectional communications between two
VPN devices.
To specify manual keys for creating a tunnel, go to
VPN > IPSEC > Manual Key
and
select
Create New
.
Figure 356: New Manual Key
Create New
Create a new manual key configuration. See
Tunnel Name
The names of existing manual key configurations.
Remote Gateway
The IP addresses of remote peers or dialup clients.
Encryption Algorithm
The names of the encryption algorithms specified in the manual key
configurations.
Authentication
Algorithm
The names of the authentication algorithms specified in the manual key
configurations.
Delete and Edit icons
Delete or edit a manual key configuration.
Edit
Delete
Caution:
If you are not familiar with the security policies, SAs, selectors, and SA databases
for your particular installation, do not attempt the following procedure without qualified
assistance.
Summary of Contents for Gate 60D
Page 705: ...www fortinet com...
Page 706: ...www fortinet com...