IPSec VPN
Manual Key
FortiGate Version 4.0 Administration Guide
01-400-89802-20090424
543
•
Name
Type a name for the VPN tunnel. The maximum name length is 15 characters
for an interface mode VPN, 35 characters for a policy-based VPN.
Local SPI
Type a hexadecimal number (up to 8 characters, 0-9, a-f) that represents the
SA that handles outbound traffic on the local FortiGate unit. The valid range is
from
0x100
to
0xffffffff
. This value must match the Remote SPI value in
the manual key configuration at the remote peer.
Remote SPI
Type a hexadecimal number (up to 8 characters, 0-9, a-f) that represents the
SA that handles inbound traffic on the local FortiGate unit. The valid range is
from
0x100
to
0xffffffff
. This value must match the Local SPI value in
the manual key configuration at the remote peer.
Remote Gateway
Type the IP address of the public interface to the remote peer. The address
identifies the recipient of ESP datagrams.
Local Interface
This option is available in NAT/Route mode only. Select the name of the
interface to which the IPSec tunnel will be bound. The FortiGate unit obtains
the IP address of the interface from the network interface settings. For more
information, see
Encryption
Algorithm
Select one of the following symmetric-key encryption algorithms:
DES
— Digital Encryption Standard, a 64-bit block algorithm that uses a 56-
bit key.
3DES
— Triple-DES, in which plain text is encrypted three times by three
keys.
AES128
— a 128-bit block Cipher Block Chaining (CBC) algorithm that uses
a 128-bit key.
AES192
— a 128-bit block Cipher Block Chaining (CBC) algorithm that uses
a 192-bit key.
AES256
— a 128-bit block Cipher Block Chaining (CBC) algorithm that uses
a 256-bit key.
Note:
The algorithms for encryption and authentication cannot both be NULL.
Encryption Key
Enter an encryption key appropriate to the encryption algorithm:
•
for DES, type a 16-character hexadecimal number (0-9, a-f).
•
for 3DES, type a 48-character hexadecimal number (0-9, a-f) separated
into three segments of 16 characters.
•
for AES128, type a 32-character hexadecimal number (0-9, a-f) separated
into two segments of 16 characters.
•
for AES192, type a 48-character hexadecimal number (0-9, a-f) separated
into three segments of 16 characters.
•
for AES256, type a 64-character hexadecimal number (0-9, a-f) separated
into four segments of 16 characters.
Authentication
Algorithm
Select one of the following message digests:
MD5
— Message Digest 5 algorithm, which produces a 128-bit message
digest.
SHA1
— Secure Hash Algorithm 1, which produces a 160-bit message digest.
Note:
The Algorithms for encryption and authentication cannot both be NULL.
Authentication
Key
Enter an authentication key appropriate to the authentication algorithm:
•
for MD5, type a 32-character hexadecimal number (0-9, a-f) separated into
two segments of 16 characters.
•
for SHA1, type 40-character hexadecimal number (0-9, a-f) separated into
one segment of 16 characters and a second segment of 24 characters.
IPSec Interface
Mode
Create a virtual interface for the local end of the VPN tunnel. Select this check
box to create a route-based VPN, clear it to create a policy-based VPN.
This is available only in NAT/Route mode.
Summary of Contents for Gate 60D
Page 705: ...www fortinet com...
Page 706: ...www fortinet com...