Fortinet Fortigate-5000 series Administration Manual page 306

Hide thumbs Also See for Fortigate-5000 series:
Table of Contents

Advertisement

Config
306
Enable SSL VPN
Login Port
Tunnel IP Range
Server Certificate
Require Client Certificate
Encryption Key Algorithm
Default - RC4(128
bits) and higher
High - AES(128/256
bits) and 3DES
Low - RC4(64 bits),
DES and higher
Idle Timeout
Portal Message
Advanced (DNS and WINS Servers)
DNS Server #1
DNS Server #2
WINS Server #1
WINS Server #2
Select to enable SSL VPN connections.
Optionally enter a different HTTPS port number for
remote client web browsers to connect to the FortiGate
unit. The default port number is 10443.
Specify the range of IP addresses reserved for tunnel-
mode SSL VPN clients. Type the starting and ending
address that defines the range of reserved IP
addresses.
Select the signed server certificate to use for
authentication purposes. If you leave the default setting
(Self-Signed), the FortiGate unit offers its factory
installed (self-signed) certificate from Fortinet to remote
clients when they connect.
If you want to enable the use of group certificates for
authenticating remote clients, select the option.
Afterward, when the remote client initiates a connection,
the FortiGate unit prompts the client for its client-side
certificate as part of the authentication process.
Select the algorithm for creating a secure SSL
connection between the remote client web browser and
the FortiGate unit.
If the web browser on the remote client is capable of
matching a 128-bit or greater cipher suite, select this
option.
If the web browser on the remote client is capable of
matching a high level of SSL encryption, select this
option to enable cipher suites that use more than 128
bits to encrypt data.
If you are not sure which level of SSL encryption the
remote client web browser supports, select this option to
enable a 64-bit or greater cipher suite.
Type the period of time (in seconds) to control how long
the connection can remain idle before the system forces
the user to log in again. The range is from 10 to 28800
seconds. This setting applies to the SSL VPN session.
The interface does not time out when web application
sessions or tunnels are up.
If you want to display a custom caption at the top of the
web portal home page, type the message.
Enter up to two DNS Servers to be provided for the use
of clients.
Enter up to two WINS Servers to be provided for the use
of clients.
FortiGate Version 3.0 MR4 Administration Guide
VPN SSL
01-30004-0203-20070102

Hide quick links:

Advertisement

Table of Contents
loading

Table of Contents