Fortinet
v3.0 MR7
manual
E R G U I D E
Password
Default RC4128
Name field, type admin
See Configuring user groups on
Authentication Settings
Authorization
Directory Service servers
Select Enable Pptp
Using the Query icon
Page 1
U S E R G U I D E
FortiOS v3.0 MR7
User Authentication User Guide
www.fortinet.com
Page 1
Page 2
Image 1
Page 1
Page 2
Contents
E R G U I D E
Trademarks
FortiOS v3.0 MR7 User Authentication User Guide
Contents
Users/peers and user groups
Configuring authenticated access
Index
Creating local users Creating peer users
Introduction
About authentication
Web-based user authentication
User’s view of authentication
VPN client-based authentication
See Creating local users on See Creating peer users on
FortiGate administrator’s view of authentication
See Configuring user groups on
Authentication servers
Peers
Public Key Infrastructure PKI authentication
Users
User groups
About this document
Authentication timeout
Firewall policies
VPN tunnels
FortiGate documentation
Name field, type admin
Typographic conventions
Related documentation
FortiGate Administration Guide
FortiClient documentation
FortiManager documentation
FortiMail documentation
FortiAnalyzer documentation
Fortinet Tools and Documentation CD
Customer service and technical support
Fortinet Knowledge Center
Comments on Fortinet technical documentation
Radius servers
Authentication servers
Radius attributes sent in Radius accounting message
Configuring the FortiGate unit to use a Radius server
Primary Server Secret
Primary Server Name/IP
Group
Edit icon Edit a Radius server configuration
Ldap servers
Ldapsearch -x objectclass=
Configuring the FortiGate unit to use an Ldap server
Server Port
Password
Common Name
Identifier
Edit
To configure the FortiGate unit for Ldap authentication CLI
Protocol
Certificate
Ldap server Distinguished Name Query tree
Using the Query icon
Ascii
TACACS+ servers
Server Key
Authentication Type
Directory Service servers
Domain
Create New
Groups
Fsae Collector IP
Fsae Collector IP/Name Port
Directory Service server configuration Name
CLI
Example Directory Service server list
Directory Service servers
Users/peers
Users/peers and user groups
Creating local users
User type Authentication
To create a local user web-based manager Go to User Local
Delete icon Edit icon
To view a list of all local users, go to User Local
To create a local user CLI
Creating peer users
To remove a user from the FortiGate unit configuration CLI
Delete icon
To view a list of PKI peer users, go to User PKI
Authenticating peer user
Subject
Remove PKI peer user
To create a peer user for PKI authentication CLI
User groups
Directory Service user groups
Firewall user groups
Protection profiles
SSL VPN user groups
Select Create New and enter the following information
Configuring user groups
Firewall
To create a firewall user group CLI
Configuring Directory Service user groups
Members
FortiGuard Web
Available Users/Groups or Available Members
Configuring SSL VPN user groups
Viewing a list of user groups
Configuring Peer user groups
To create a peer group CLI
Group Name
Config user group delete groupname End
User groups
Authentication protocols
Authentication timeout
Enter the Idle Timeout value seconds Select Apply
Telnet
Authentication Settings
Firewall policy authentication
Authentication is an Advanced firewall option
Configuring authentication for a firewall policy
To configure authentication for a firewall policy
Go to Firewall Policy
Firewall Policy Move To
Firewall policy order
Source Interface
Configuring authenticated access to the Internet
Zone
Configuring authentication of SSL VPN users
VPN authentication
Select Enable SSL-VPN and enter information as follows
Go to VPN SSL
Server Certificate
Default RC4128
Require Client Certificate
Encryption Key Algorithm
To configure authentication for an SSL VPN CLI
Configuring authentication of Pptp VPN users/user groups
Configuring authentication of VPN peers and clients
Select Enable Pptp
Select Require Client Certificate, and then select Apply
Configuring authentication of remote IPSec VPN users
Configuring authentication of L2TP VPN users/user groups
To configure authentication for a Pptp VPN CLI
To configure authentication for an L2TP VPN CLI
Only users with passwords on the FortiGate unit
To configure user group authentication for dialup IPSec CLI
Remote Gateway
IPSec configuration for dialup users
Configuring XAuth authentication
Remote Gateway Authentication Method
To configure authentication for a dialup IPSec VPN CLI
XAuth
Server Type
VPN authentication
Index
01-30007-0347-20080731
MS-CHAP
VSA
Related pages
Troubleshooting for Poulan 401214
Physical Specifications for IBM 600
Memory Error Message for Casio EM-500
Part Identification Chart for Weider WESY5983.5
Cover the receptacle when not in use for LG Electronics MULTIMEDIA PHONE
Separately sold products for installation for Samsung SCC-C7435P
How to use the parts lists and diagrams for HP 4101mfp
Language code list for Denon DVD-800
How do I follow the
generator service schedule
for optimal use?
Top
Page
Image
Contents