![Fortinet FortiWAN Скачать руководство пользователя страница 12](http://html1.mh-extra.com/html/fortinet/fortiwan/fortiwan_handbook_2322088012.webp)
Scope
What's new
What's new
The following features are new or changed since FortiWAN 4.0.0:
FortiWAN 4.2.1
Bug fixes only. Please refer to FortiWAN 4.2.1 Release Notes.
FortiWAN 4.2.0
l
IPSec VPN
- Supports standard IPSec VPN which is based on the two-phase Internet Key Exchange
(IKE) protocol. FortiWAN's IPSec VPN provides two communication modes, tunnel mode and transport
mode. Tunnel mode is a common method used to establish IPSec VPN between two network sites.
FortiWAN IPSec tunnel mode transfers data traffic within single connection (single WAN link), therefore
bandwidth aggregation and fault tolerance are not available to the VPN. On the other hand, FortiWAN's
transport mode is designed to provide protections to Tunnel Routing transmission on each of the TR
tunnels, so that the IPSec VPN with ability of bandwidth aggregation and fault tolerance can be
implemented.
FortiWAN's IPSEC tunnel mode supports single-link connectivity between FortiWAN devices, FortiWAN
and FortiGate and FortiWAN and any appliance supporting standard IPSEC. FortiWAN's IPSEC
transport mode supports multi-link Tunnel Routing between FortiWAN devices. IPSEC Aggressive Mode
is not supported in this release. See "
".
l
Tunnel Routing
- Supports IPSec encryption. With cooperation with FortiWAN's IPSec tunnel mode,
the Tunnel Routing communication can be protected by IPSec Security Association (IPSec SA), which
provides strict security negotiations, data privacy and authenticity. The VPN network implemented by
Tunnel Routing and IPSec transport mode has the advantages of high security level, bandwidth
aggregation and fault tolerance. See "
".
l
Basic subnet
- Supports DHCP Relay on every LAN port and DMZ port. FortiWAN forwards the DHCP
requests and responses between a LAN or DMZ subnet and the specified DHCP server (standalone), so
that centralized DHCP management can be implemented. With appropriate deployments of Tunnel
Routing (or Tunnel Routing over IPSec Transport mode), the DHCP server of headquarters is capable to
manage IP allocation to regional sites through DHCP relay. FortiWAN's DHCP relay is for not only a
local network but also a Tunnel Routing VPN network. See "
Automatic addressing within a basic
".
l
DHCP
- Supports static IP allocation by Client Identifier (Options code: 61).According to the client
identifier, FortiWAN's DHCP recognizes the user who asks for an IP lease, and assigns the specified IP
address to him. See "
Automatic addressing within a basic subnet
".
l
Bandwidth Management
- Supports the visibility to Tunnel Routing traffic. In the previous version,
individual application encapsulated by Tunnel Routing was invisible to FortiWAN's Bandwidth
Management. Bandwidth Management is only capable of shaping the overall tunnel (GRE) traffic. From
this release, Bandwidth Management evaluates traffic before/after Tunnel Routing
encapsulation/decapsulation, so that traffic of individual application in a Tunnel Routing transmission
can be controlled. See "
".
l
Administration
- Ability of changing their own password for Monitor accounts is added. In the previous
version, password of accounts belonging to Monitor group can be changed by only administrators. From
this release, Monitor accounts can change their own password. See "
".
FortiWAN Handbook
Fortinet Technologies Inc.
12
Содержание FortiWAN
Страница 1: ...FortiWAN Handbook VERSION 4 2 1...