![Fortinet FortiWAN Скачать руководство пользователя страница 178](http://html1.mh-extra.com/html/fortinet/fortiwan/fortiwan_handbook_2322088178.webp)
IPSec
IPSec set up
Tunnel mode
IPSec Tunnel mode is commonly used for site-to-site communications by tunneling through incompatible networks.
For example, it delivers protected communications between two private networks through Internet, which is a typical
IPSec VPN. In IPSec tunnel mode, the original IP packet is entirely encrypted (not only the payload data but also the
routing information are encrypted), and is encapsulated with a new IP header. With the new IP header encapsulation
and decapsulation, two incompatible networks deliver encrypted packets to each other by tunneling through Internet.
Transport mode
IPSec Transport mode is used for communications between two end-stations (host-to-host). An end-station can be a
IPSec gateway or just a host running IPSec server/client. Both are actually the destination to each other while
communicating. The basic concept of IPsec Transport mode is that the original IP header is intact; the routing is
neither modified nor encrypted. Transport mode only provides protection of the payload of the original IP packet by
encryption. The two endpoints are supposed to be accessible to each other originally. Usually, Transport mode is
applied to other tunneling protocols to provide protection of GRE/L2TP encapsulated IP data packets ( GRE/L2TP
transmission over IPSec protection). FortiWAN IPSec Transport mode is only available for Tunnel Routing.
IPSec set up
After basic concept of IPSec introduced previously, this section focus on the introduction of FortiWAN's IPSec and the
configurations to set up FortiWAN's IPSec. FortiWAN provides a complete VPN solution through the cooperation of
Tunnel Routing and IPSec. FortiWAN's Tunnel Routing is used to build a site-to-site VPN with bandwidth aggregation
and fault tolerance over multiple WAN links. Moreover, with FortiWAN's IPSec protection, Tunnel Routing delivers
packets over secure channels.
About FortiWAN IPSec VPN
Specifications of FortiWAN's IPsec VPN
Since FortiWAN's IPSec is designed for applications of site-to-site VPN, it is functionally-limited comparing with
standard IPSec protocol suite. However, FortiWAN's IPsec still provides basic protections for tunneling
communications. The specifications is listed as following:
IKE
Support IKE v1 only
Authentication method
Support pre-shared key only
IKE Phase 1 modes
Support Main mode only
Encryption algorithm
DES, 3DES, AES128, AES192, AES256
Authentication algorithm
MD5, SHA1, SHA256, SHA384, SHA512
178
FortiWAN Handbook
Fortinet Technologies Inc.
Содержание FortiWAN
Страница 1: ...FortiWAN Handbook VERSION 4 2 1...