|
- Timestamp:
-
04/05/09 17:18:36 (17 months ago)
- Author:
-
admin
- Comment:
-
--
Legend:
- Unmodified
- Added
- Removed
- Modified
-
|
v6
|
v7
|
|
| 25 | 25 | Several address definitions must be created. These will be used later in other parts of the gateway configuration. Navigate to the following screen using the pane on the left hand side of the browser interface. |
| 26 | 26 | |
| 27 | | [[Image(http://www.shrew.net/vpn/howto/Fortigate/nav-1a.jpg)]] |
| | 27 | [[Image(http://www.shrew.net/static/howto/Fortigate/nav-1a.jpg)]] |
| 28 | 28 | |
| 29 | 29 | To create a new address definition, click on the ''Create New'' button at the top of the page. |
| 30 | 30 | |
| 31 | | [[Image(http://www.shrew.net/vpn/howto/Fortigate/nav-1b.jpg)]] |
| | 31 | [[Image(http://www.shrew.net/static/howto/Fortigate/nav-1b.jpg)]] |
| 32 | 32 | |
| 33 | 33 | ==== Wan Interface Entry ==== |
| … |
… |
|
| 44 | 44 | When finished click OK. |
| 45 | 45 | |
| 46 | | [[Image(http://www.shrew.net/vpn/howto/Fortigate/pic-1a.jpg)]] |
| | 46 | [[Image(http://www.shrew.net/static/howto/Fortigate/pic-1a.jpg)]] |
| 47 | 47 | |
| 48 | 48 | ==== Private Network Entry ==== |
| … |
… |
|
| 59 | 59 | When finished click OK. |
| 60 | 60 | |
| 61 | | [[Image(http://www.shrew.net/vpn/howto/Fortigate/pic-1b.jpg)]] |
| | 61 | [[Image(http://www.shrew.net/static/howto/Fortigate/pic-1b.jpg)]] |
| 62 | 62 | |
| 63 | 63 | === DHCP Server Parameters === |
| … |
… |
|
| 65 | 65 | An IPsec over DHCP server must be created. This will define the parameters to be assigned to clients when they connect. Navigate to the following screen using the pane on the left hand side of the browser interface. |
| 66 | 66 | |
| 67 | | [[Image(http://www.shrew.net/vpn/howto/Fortigate/nav-2a.jpg)]] |
| | 67 | [[Image(http://www.shrew.net/static/howto/Fortigate/nav-2a.jpg)]] |
| 68 | 68 | |
| 69 | 69 | To create a new DHCP server definition, click on the arrow next to your external interface name to expand the options. Then click on the plus icon to the right of the ''Servers'' option. |
| 70 | 70 | |
| 71 | | [[Image(http://www.shrew.net/vpn/howto/Fortigate/nav-2b.jpg)]] |
| | 71 | [[Image(http://www.shrew.net/static/howto/Fortigate/nav-2b.jpg)]] |
| 72 | 72 | |
| 73 | 73 | When defining your DHCP parameters, make sure you select an address range that does not overlap with any private network protected by the Fortigate unit. |
| … |
… |
|
| 86 | 86 | When finished click OK. |
| 87 | 87 | |
| 88 | | [[Image(http://www.shrew.net/vpn/howto/Fortigate/pic-2.jpg)]] |
| | 88 | [[Image(http://www.shrew.net/static/howto/Fortigate/pic-2.jpg)]] |
| 89 | 89 | |
| 90 | 90 | === Dialup Users === |
| … |
… |
|
| 92 | 92 | Dialup user accounts must be created. These will be the user name and passwords a remote access users will use to authenticate with the gateway. Navigate to the following screen using the pane on the left hand side of the browser interface. |
| 93 | 93 | |
| 94 | | [[Image(http://www.shrew.net/vpn/howto/Fortigate/nav-3a.jpg)]] |
| | 94 | [[Image(http://www.shrew.net/static/howto/Fortigate/nav-3a.jpg)]] |
| 95 | 95 | |
| 96 | 96 | To create a new user, click on the ''Create New'' button at the top of the page. |
| 97 | 97 | |
| 98 | | [[Image(http://www.shrew.net/vpn/howto/Fortigate/nav-3b.jpg)]] |
| | 98 | [[Image(http://www.shrew.net/static/howto/Fortigate/nav-3b.jpg)]] |
| 99 | 99 | |
| 100 | 100 | Define the following parameters for each user account. |
| … |
… |
|
| 105 | 105 | When finished click OK. |
| 106 | 106 | |
| 107 | | [[Image(http://www.shrew.net/vpn/howto/Fortigate/pic-3.jpg)]] |
| | 107 | [[Image(http://www.shrew.net/static/howto/Fortigate/pic-3.jpg)]] |
| 108 | 108 | |
| 109 | 109 | === Dialup User Group === |
| … |
… |
|
| 111 | 111 | A dialup user group must be created. By placing a user account in this group, it will allow them to access the gateway using the client software. Navigate to the following screen using the pane on the left hand side of the browser interface. |
| 112 | 112 | |
| 113 | | [[Image(http://www.shrew.net/vpn/howto/Fortigate/nav-4a.jpg)]] |
| | 113 | [[Image(http://www.shrew.net/static/howto/Fortigate/nav-4a.jpg)]] |
| 114 | 114 | |
| 115 | 115 | To create a new user group, click on the ''Create New'' button at the top of the page. |
| 116 | 116 | |
| 117 | | [[Image(http://www.shrew.net/vpn/howto/Fortigate/nav-4b.jpg)]] |
| | 117 | [[Image(http://www.shrew.net/static/howto/Fortigate/nav-4b.jpg)]] |
| 118 | 118 | |
| 119 | 119 | Define the following parameters for each user account. |
| … |
… |
|
| 127 | 127 | When finished click OK. |
| 128 | 128 | |
| 129 | | [[Image(http://www.shrew.net/vpn/howto/Fortigate/pic-4.jpg)]] |
| | 129 | [[Image(http://www.shrew.net/static/howto/Fortigate/pic-4.jpg)]] |
| 130 | 130 | |
| 131 | 131 | === Phase 1 Parameters === |
| … |
… |
|
| 133 | 133 | The IKE phase 1 parameters must be configured for our remote access connections. Navigate to the following screen using the pane on the left hand side of the browser interface. |
| 134 | 134 | |
| 135 | | [[Image(http://www.shrew.net/vpn/howto/Fortigate/nav-5a.jpg)]] |
| | 135 | [[Image(http://www.shrew.net/static/howto/Fortigate/nav-5a.jpg)]] |
| 136 | 136 | |
| 137 | 137 | To create a new Phase 1 definition, click on the ''Create Phase 1'' button at the top of the screen. |
| 138 | 138 | |
| 139 | | [[Image(http://www.shrew.net/vpn/howto/Fortigate/nav-5b.jpg)]] |
| | 139 | [[Image(http://www.shrew.net/static/howto/Fortigate/nav-5b.jpg)]] |
| 140 | 140 | |
| 141 | 141 | Define the following parameters. |
| … |
… |
|
| 168 | 168 | When finished click OK. |
| 169 | 169 | |
| 170 | | [[Image(http://www.shrew.net/vpn/howto/Fortigate/pic-5a.jpg)]] |
| | 170 | [[Image(http://www.shrew.net/static/howto/Fortigate/pic-5a.jpg)]] |
| 171 | 171 | |
| 172 | 172 | === Phase 2 Parameters === |
| … |
… |
|
| 174 | 174 | The IKE phase 2 parameters must be configured for our remote access connections. Navigate to the following screen using the pane on the left hand side of the browser interface. |
| 175 | 175 | |
| 176 | | [[Image(http://www.shrew.net/vpn/howto/Fortigate/nav-5a.jpg)]] |
| | 176 | [[Image(http://www.shrew.net/static/howto/Fortigate/nav-5a.jpg)]] |
| 177 | 177 | |
| 178 | 178 | To create a new Phase 2 definition, click on the ''Create Phase 1'' button at the top of the screen. |
| 179 | 179 | |
| 180 | | [[Image(http://www.shrew.net/vpn/howto/Fortigate/nav-5c.jpg)]] |
| | 180 | [[Image(http://www.shrew.net/static/howto/Fortigate/nav-5c.jpg)]] |
| 181 | 181 | |
| 182 | 182 | Define the following parameters. |
| … |
… |
|
| 204 | 204 | When finished click OK. |
| 205 | 205 | |
| 206 | | [[Image(http://www.shrew.net/vpn/howto/Fortigate/pic-5b.jpg)]] |
| | 206 | [[Image(http://www.shrew.net/static/howto/Fortigate/pic-5b.jpg)]] |
| 207 | 207 | |
| 208 | 208 | === Firewall Policies === |
| … |
… |
|
| 210 | 210 | Firewall policies must be created to define the resources remote access clients will have access to. Navigate to the following screen using the pane on the left hand side of the browser interface. |
| 211 | 211 | |
| 212 | | [[Image(http://www.shrew.net/vpn/howto/Fortigate/nav-6a.jpg)]] |
| | 212 | [[Image(http://www.shrew.net/static/howto/Fortigate/nav-6a.jpg)]] |
| 213 | 213 | |
| 214 | 214 | To create a new policy, click the ''Create New'' button at the top of the screen. |
| 215 | 215 | |
| 216 | | [[Image(http://www.shrew.net/vpn/howto/Fortigate/nav-6b.jpg)]] |
| | 216 | [[Image(http://www.shrew.net/static/howto/Fortigate/nav-6b.jpg)]] |
| 217 | 217 | |
| 218 | 218 | The first policy will allow clients to communicate with the external interface DHCP server. |
| … |
… |
|
| 238 | 238 | When finished click OK. |
| 239 | 239 | |
| 240 | | [[Image(http://www.shrew.net/vpn/howto/Fortigate/pic-6a.jpg)]] |
| | 240 | [[Image(http://www.shrew.net/static/howto/Fortigate/pic-6a.jpg)]] |
| 241 | 241 | |
| 242 | 242 | The second policy will allow clients to communicate with the private network protected by the Fortigate. A seperate policy needs to be created for each private network that should be accessible to remote access clients. |
| … |
… |
|
| 262 | 262 | When finished click OK. |
| 263 | 263 | |
| 264 | | [[Image(http://www.shrew.net/vpn/howto/Fortigate/pic-6b.jpg)]] |
| | 264 | [[Image(http://www.shrew.net/static/howto/Fortigate/pic-6b.jpg)]] |
| 265 | 265 | |
| 266 | 266 | == Client Configuration == |
| … |
… |
|
| 302 | 302 | == Resources == |
| 303 | 303 | |
| 304 | | * [http://www.shrew.net/vpn/howto/Fortigate/fortigate.vpn Example Client configuration] |
| | 304 | * [http://www.shrew.net/static/howto/Fortigate/fortigate.vpn Example Client configuration] |
|
|