Fortinet
v3.0 MR7
manual
Password
Default RC4128
Name field, type admin
See Configuring user groups on
Authentication Settings
Authorization
Directory Service servers
Select Enable Pptp
Using the Query icon
Page 66
www.fortinet.com
Page 65
Page 66
Image 66
Page 65
Page 66
Contents
E R G U I D E
FortiOS v3.0 MR7 User Authentication User Guide
Trademarks
Contents
Index
Configuring authenticated access
Users/peers and user groups
Creating local users Creating peer users
About authentication
Introduction
User’s view of authentication
Web-based user authentication
VPN client-based authentication
FortiGate administrator’s view of authentication
See Creating local users on See Creating peer users on
Authentication servers
See Configuring user groups on
Users
Public Key Infrastructure PKI authentication
Peers
User groups
Firewall policies
Authentication timeout
About this document
VPN tunnels
Name field, type admin
FortiGate documentation
Typographic conventions
FortiGate Administration Guide
Related documentation
FortiMail documentation
FortiManager documentation
FortiClient documentation
FortiAnalyzer documentation
Fortinet Knowledge Center
Customer service and technical support
Fortinet Tools and Documentation CD
Comments on Fortinet technical documentation
Authentication servers
Radius servers
Configuring the FortiGate unit to use a Radius server
Radius attributes sent in Radius accounting message
Primary Server Name/IP
Primary Server Secret
Edit icon Edit a Radius server configuration
Group
Ldap servers
Ldapsearch -x objectclass=
Configuring the FortiGate unit to use an Ldap server
Common Name
Password
Server Port
Identifier
Protocol
To configure the FortiGate unit for Ldap authentication CLI
Edit
Certificate
Using the Query icon
Ldap server Distinguished Name Query tree
TACACS+ servers
Ascii
Authentication Type
Server Key
Directory Service servers
Groups
Create New
Domain
Fsae Collector IP
Directory Service server configuration Name
Fsae Collector IP/Name Port
CLI
Example Directory Service server list
Directory Service servers
Users/peers and user groups
Users/peers
User type Authentication
Creating local users
To create a local user web-based manager Go to User Local
To view a list of all local users, go to User Local
Delete icon Edit icon
To create a local user CLI
To remove a user from the FortiGate unit configuration CLI
Creating peer users
Delete icon
Authenticating peer user
To view a list of PKI peer users, go to User PKI
Subject
To create a peer user for PKI authentication CLI
Remove PKI peer user
Directory Service user groups
User groups
Firewall user groups
SSL VPN user groups
Protection profiles
Configuring user groups
Select Create New and enter the following information
Firewall
Members
Configuring Directory Service user groups
To create a firewall user group CLI
FortiGuard Web
Configuring SSL VPN user groups
Available Users/Groups or Available Members
To create a peer group CLI
Configuring Peer user groups
Viewing a list of user groups
Group Name
Config user group delete groupname End
User groups
Enter the Idle Timeout value seconds Select Apply
Authentication timeout
Authentication protocols
Telnet
Firewall policy authentication
Authentication Settings
To configure authentication for a firewall policy
Configuring authentication for a firewall policy
Authentication is an Advanced firewall option
Go to Firewall Policy
Firewall policy order
Firewall Policy Move To
Configuring authenticated access to the Internet
Source Interface
Zone
Select Enable SSL-VPN and enter information as follows
VPN authentication
Configuring authentication of SSL VPN users
Go to VPN SSL
Require Client Certificate
Default RC4128
Server Certificate
Encryption Key Algorithm
To configure authentication for an SSL VPN CLI
Select Enable Pptp
Configuring authentication of VPN peers and clients
Configuring authentication of Pptp VPN users/user groups
Select Require Client Certificate, and then select Apply
To configure authentication for a Pptp VPN CLI
Configuring authentication of L2TP VPN users/user groups
Configuring authentication of remote IPSec VPN users
To configure authentication for an L2TP VPN CLI
To configure user group authentication for dialup IPSec CLI
Only users with passwords on the FortiGate unit
Remote Gateway
Configuring XAuth authentication
IPSec configuration for dialup users
XAuth
To configure authentication for a dialup IPSec VPN CLI
Remote Gateway Authentication Method
Server Type
VPN authentication
Index
01-30007-0347-20080731
MS-CHAP
VSA
Related pages
Troubleshooting Tables for Dish Network Solo 381
Specifications for Samsung LS19TWASU/CI
Flowchart 3 Configuration Test for HP PB 10
Special wireless installation instructions for Lexmark 40E
CG 60 Parts List for Magikitch'n CG-60
Paltm Bar Code List and Samples for AMT Datasouth 600
Learn how to select the network boot option on
Intel DG33BU
.
Top
Page
Image
Contents