
IPSec VPN
Configuring encrypt policies
FortiGate-400 Installation and Configuration Guide
225
Adding a source address
The source address is located within the internal network of the local VPN peer. It can
be a single computer address or the address of a network.
1
Go to
Firewall > Address
.
2
Select an internal interface. (Methods will differ slightly between FortiGate models.)
3
Select New to add an address.
4
Enter the Address Name, IP Address, and NetMask for a single computer or for an
entire subnetwork on an internal interface of the local VPN peer.
5
Select OK to save the source address.
Adding a destination address
The destination address can be a VPN client address on the Internet or the address of
a network behind a remote VPN gateway.
1
Go to
Firewall > Address
.
2
Select an external interface. (Methods will differ slightly between FortiGate models.)
3
Select New to add an address.
4
Enter the Address Name, IP Address, and NetMask for a single computer or for an
entire subnetwork on an internal interface of the remote VPN peer.
5
Select OK to save the source address.
Adding an encrypt policy
1
Go to
Firewall > Policy
.
2
Use the policy grid to choose the policy list to which to add the policy.
For example, port1
->
port2 or port3
->
port2.
3
Select New to add a new policy.
4
Set Source to the source address.
5
Set Destination to the destination address.
6
Set Service to control the services allowed over the VPN connection.
You can select ANY to allow all supported services over the VPN connection or select
a specific service or service group to limit the services allowed over the VPN
connection.
7
Set Action to ENCRYPT.
8
Configure the ENCRYPT parameters.
VPN Tunnel
Select an Auto Key tunnel for this encrypt policy.
Allow inbound
Select Allow inbound to enable inbound users to connect to the source
address.
Allow outbound
Select Allow outbound to enable outbound users to connect to the
destination address.
Содержание FortiGate 400
Страница 13: ...Contents FortiGate 400 Installation and Configuration Guide 13 Glossary 295 Index 299 ...
Страница 14: ...Contents 14 Fortinet Inc ...
Страница 44: ...44 Fortinet Inc Next steps Getting started ...
Страница 60: ...60 Fortinet Inc Configuration example Multiple connections to the Internet NAT Route mode installation ...
Страница 74: ...74 Fortinet Inc Transparent mode configuration examples Transparent mode installation ...
Страница 132: ...132 Fortinet Inc Registering a FortiGate unit after an RMA Virus and attack definitions updates and registration ...
Страница 148: ...148 Fortinet Inc Providing DHCP services to your internal network Network configuration ...
Страница 168: ...168 Fortinet Inc Customizing replacement messages System configuration ...
Страница 200: ...200 Fortinet Inc Content profiles Firewall configuration ...
Страница 258: ...258 Fortinet Inc Logging attacks Network Intrusion Detection System NIDS ...
Страница 294: ...294 Fortinet Inc Configuring alert email Logging and reporting ...
Страница 298: ...298 Fortinet Inc Glossary ...
Страница 308: ...308 Fortinet Inc Index ...