Contents
FortiGate-4000 Installation and Configuration Guide 11
Configuring LDAP support .............................................................................................. 231
Adding LDAP servers.................................................................................................. 231
Deleting LDAP servers................................................................................................ 232
Configuring user groups.................................................................................................. 232
Adding user groups..................................................................................................... 233
Deleting user groups................................................................................................... 234
IPSec VPN........................................................................................................... 235
Key management............................................................................................................ 236
Manual Keys ............................................................................................................... 236
Automatic Internet Key Exchange (AutoIKE) with pre-shared keys or certificates ..... 236
Manual key IPSec VPNs................................................................................................. 237
General configuration steps for a manual key VPN .................................................... 237
Adding a manual key VPN tunnel ............................................................................... 237
AutoIKE IPSec VPNs...................................................................................................... 239
General configuration steps for an AutoIKE VPN ....................................................... 239
Adding a phase 1 configuration for an AutoIKE VPN.................................................. 239
Adding a phase 2 configuration for an AutoIKE VPN.................................................. 244
Managing digital certificates............................................................................................ 246
Obtaining a signed local certificate ............................................................................. 246
Obtaining CA certificates ............................................................................................ 249
Configuring encrypt policies............................................................................................ 249
Adding a source address ............................................................................................ 250
Adding a destination address...................................................................................... 251
Adding an encrypt policy............................................................................................. 251
IPSec VPN concentrators ............................................................................................... 253
VPN concentrator (hub) general configuration steps .................................................. 254
Adding a VPN concentrator ........................................................................................ 255
VPN spoke general configuration steps...................................................................... 256
Monitoring and Troubleshooting VPNs ........................................................................... 257
Viewing VPN tunnel status.......................................................................................... 257
Viewing dialup VPN connection status ....................................................................... 258
Testing a VPN............................................................................................................. 258
PPTP and L2TP VPN .......................................................................................... 259
Configuring PPTP ........................................................................................................... 259
Configuring the FortiGate unit as a PPTP gateway .................................................... 260
Configuring a Windows 98 client for PPTP ................................................................. 262
Configuring a Windows 2000 client for PPTP ............................................................. 263
Configuring a Windows XP client for PPTP ................................................................ 263
Configuring L2TP............................................................................................................ 265
Configuring the FortiGate unit as an L2TP gateway ................................................... 265
Configuring a Windows 2000 client for L2TP.............................................................. 267
Configuring a Windows XP client for L2TP ................................................................. 268