![Fortinet FortiWAN Скачать руководство пользователя страница 191](http://html1.mh-extra.com/html/fortinet/fortiwan/fortiwan_handbook_2322088191.webp)
IPSec set up
IPSec
(TR) traffic to be transferred through IPSec VPN in Transport Mode, therefore, the quick mode selector is not required
for Phase 2 configurations of Transport Mode.
IKE Phase 2 Web UI fields:
IKE Phase 1 and Phase 2 are both the necessaries to establish an IPSec VPN, thus configurations of an IPSec VPN
must contains configurations of the two Phases. Choosing a set of Phase 1 parameters that you would like to define
the correspondent Phase 2 parameters for. The Phase 2 configuration panel is below the Phase 1 panel on the Web
UI. Click the add button on the header of Phase 2 or the add button of an existing Phase 2 configuration to add a new
Phase 2 configuration panel.
For IPSec Tunnel mode, you can define multiple sets of Phase 2 parameters within one Phase 1 configuration for
different Phase 2 Quick Mode selectors. A Phase 2 configuration contains only one quick mode selector used to filter
packets matching the only one pair of packet source, destination and protocol. To allow different traffic (for example,
traffic of different protocol) to be transferred through the same IPSec VPN tunnel (through the same Local and Remote
IPs), it requires multiple Phase 2 configurations (different quick mode selectors) to associate with the same Phase 1.
Moreover, you can deliver different IKE Phase 2 proposals (different encryption, authentication algorithms and DH
groups) to the multiple quick mode selectors, if multiple security levels are necessary.
For IPSec Transport mode, the Phase 2 configuration does not require a Quick Mode selector. FortiWAN's IPSec
Transport mode is designed to protect only communications of Tunnel Routing. Tunnel Routing takes the part to
evaluate packets for TR transmission (TR rules) and distributes packets over TR tunnels (TR algorithms), then IPSec
Transport mode established on a TR tunnel (Local IP and Remote IP) protects all the passing TR packets. Therefore,
multiple Phase 2 sets within a Phase 1 is not required for Transport mode. Remember that FortiWAN supports only
two kinds of site-to-site IPSec VPN, "IPSec Tunnel mode" and "Tunnel Routing over IPSec Transport mode".
Add / Delete / Move-Up /
Move-Down
The buttons for:
l
Adding a new configuration panel below current Phase 2
configuration
l
Deleting the current Phase 2 configuration
l
Moving the current Phase 2 configuration up a row
l
Moving the current Phase 2 configuration down a row
The buttons for Phase 2 configurations are only available for IPSec
Tunnel mode. Each Phase 1 configuration of Transport mode
contains one and only one Phase 2 configuration.
Packets that matching a Quick Mode selector are allowed to pass
through the correspondent IPSec VPN. However, each Quick Mode
selector is required to be incompatible with the others, Phase 2
configurations moving-up or moving-down is nothing about rule first-
match.
FortiWAN Handbook
Fortinet Technologies Inc.
191
Содержание FortiWAN
Страница 1: ...FortiWAN Handbook VERSION 4 2 1...