Phase 1; Phase 1 List - Fortinet FortiGate FortiGate-60M Administration Manual

Version 2.80 mr7 antivirus firewalls
Hide thumbs Also See for FortiGate FortiGate-60M:
Table of Contents

Advertisement

Phase 1

Phase 1

Phase 1 list

248
The basic phase 1 settings associate IPSec phase 1 parameters with a remote
gateway and determine:
whether the various phase 1 parameters will be exchanged in multiple rounds with
encrypted authentication information (main mode) or in a single message with
authentication information that is not encrypted (aggressive mode)
whether a preshared key or digital certificates will be used to authenticate the
identities of the two VPN peers
whether a peer identifier, certificate distinguished name, or group name will be
used to identify the remote peer or client when a connection attempt is made
In phase 1, the two VPN peers exchange keys to establish a secure communication
channel between them. The advanced P1 Proposal parameters select the encryption
and authentication algorithms that are used to generate the keys. Additional advanced
phase 1 settings can be selected to ensure the smooth operation of phase 1
negotiations.
To configure phase 1 settings
1
Go to VPN > IPSEC > Phase 1.
2
Follow the general guidelines in these sections:
"Phase 1 list" on page 248
"Phase 1 basic settings" on page 249
"Phase 1 advanced settings" on page 251
For information about how to choose the correct phase 1 settings for your particular
situation, refer to the
Note: The procedures in this section assume that you want the FortiGate unit to generate
unique IPSec encryption and authentication keys automatically. In situations where a remote
VPN peer requires a specific IPSec encryption and/or authentication key, you must configure
the FortiGate unit to use manual keys instead. For more information, see
page
255.
Figure 121:IPSec VPN Phase 1 list
Create New
Gateway Name
Gateway IP
Mode
FortiGate VPN
Guide.
Select Create New to create a new phase 1 configuration.
The names of existing phase 1 configurations.
The IP address or domain name of a remote peer, or Dialup for a dialup
client.
Main or Aggressive.
01-28007-0144-20041217
VPN
"Manual key" on
Fortinet Inc.

Advertisement

Table of Contents
loading

This manual is also suitable for:

Fortigate-60m

Table of Contents