Manual Key List - Fortinet FortiGate FortiGate-60M Administration Manual

Version 2.80 mr7 antivirus firewalls
Hide thumbs Also See for FortiGate FortiGate-60M:
Table of Contents

Advertisement

Manual key

Manual key list

256
In both cases, you do not specify IPSec phase 1 and phase 2 parameters; you define
manual keys on the VPN > IPSEC > Manual Key tab instead.
If one of the VPN peers uses specific authentication and encryption keys to establish
a tunnel, both VPN peers must be configured to use the same encryption and
authentication algorithms and keys.
Note: It may not be safe or practical to define manual keys because network administrators
must be trusted to keep the keys confidential, and propagating changes to remote VPN peers in
a secure manner may be difficult.
It is essential that both VPN peers be configured with matching encryption and
authentication algorithms, matching authentication and encryption keys, and
complementary Security Parameter Index (SPI) settings.
Each SPI identifies a Security Association (SA). The value is placed in ESP
datagrams to link the datagrams to the SA. When an ESP datagram is received, the
recipient refers to the SPI to determine which SA applies to the datagram. An SPI
must be specified manually for each SA. Because an SA applies to communication in
one direction only, you must specify two SPIs per configuration (a local SPI and a
remote SPI) to cover bidirectional communications between two VPN peers.
Caution: If you are not familiar with the security policies, SAs, selectors, and SA databases for
your particular installation, do not attempt the following procedure without qualified assistance.
To specify manual keys for creating a tunnel
1
Go to VPN > IPSEC > Manual Key and select Create New.
2
Follow the guidelines in these sections:
"Manual key list" on page 256
"Manual key options" on page 257
Figure 127:IPSec VPN Manual Key list
Create New
Remote Gateway
Encryption
Algorithm
Authentication
Algorithm
Select Create New to create a new manual key configuration.
The IP address of the remote peer or client.
The names of the encryption algorithms used in the configuration.
The names of the authentication algorithms used in the configuration.
Edit, view, or delete manual key configurations.
01-28007-0144-20041217
VPN
Fortinet Inc.

Advertisement

Table of Contents
loading

This manual is also suitable for:

Fortigate-60m

Table of Contents