VPN

Phase 2 advanced options

 

 

Enable replay detection

You can select either of the following message digests to check the authenticity of messages during an encrypted session:

NULL-Do not use a message digest.

MD5-Message Digest 5, the hash algorithm developed by RSA Data Security.

SHA1-Secure Hash Algorithm 1, which produces a 160-bit message digest.

To specify one combination only, set the Encryption and Authentication options of the second combination to NULL. To specify a third combination, use the add button beside the fields for the second combination.

Optionally enable or disable replay detection. Replay attacks occur when an unauthorized party intercepts a series of IPSec packets and replays them back into the tunnel.

Enable perfect forward secrecy (PFS)

DH Group

Enable or disable PFS. Perfect forward secrecy (PFS) improves security by forcing a new Diffie-Hellman exchange whenever keylife expires.

Select one Diffie-Hellman group (1, 2, or 5). The remote peer or client must be configured to use the same group.

Keylife

Select the method for determining when the phase 2 key expires: Seconds,

 

KBytes, or Both. If you select both, the key expires when either the time has

 

passed or the number of KB have been processed. The range is from 120 to

 

172800 seconds, or from 5120 to 2147483648 KB.

Autokey Keep

Alive

DHCP-IPSec

Internet browsing

Quick Mode Identities

Enable the option if you want the tunnel to remain active when no data is being processed.

If the FortiGate unit will relay DHCP requests from dialup clients to an external DHCP server, you can select DHCP-IPsec Enable to enable DHCP over IPSec services. The DHCP relay parameters must be configured separately. For more information, see “System DHCP” on page 73.

If the tunnel will support an Internet-browsing configuration, select the browsing interface from the list.

Enter the method for choosing selectors for IKE negotiations:

To choose a selector from a firewall encryption policy, select Use selectors from policy.

To disable selector negotiation, select Use wildcard selectors.

To specify the firewall encryption policy source and destination IP addresses, select Specify a selector and then select the names of the source and destination addresses from the Source address and Dest address lists. You may optionally specify source and destination port numbers and/or a protocol number.

Manual key

If required, you can manually define cryptographic keys for establishing an IPSec VPN tunnel. You would define manual keys in situations where:

Prior knowledge of the encryption and/or authentication key is required (that is, one of the VPN peers requires a specific IPSec encryption and/or authentication key).

Encryption and authentication needs to be disabled.

FortiGate-100A Administration Guide

01-28007-0068-20041203

253

Page 253
Image 253
Fortinet 100A manual Manual key, 253, Enable replay detection, Enable perfect forward secrecy PFS DH Group, Keylife

100A specifications

Fortinet 100A is a versatile network security device designed to provide comprehensive protection against various cyber threats while ensuring optimal network performance. As part of the FortiGate series, the 100A combines advanced security features with powerful hardware capabilities, making it suitable for small to medium-sized businesses.

One of the key features of the Fortinet 100A is its deep packet inspection technology. This capability allows the firewall to analyze both the header and payload of packets traversing the network, enabling it to detect and block malicious content effectively. The 100A can identify and mitigate a wide range of threats, including malware, intrusions, and application-layer attacks.

The FortiOS operating system powers the Fortinet 100A, offering a robust and user-friendly interface for configuration and management. With its unified security management console, administrators can efficiently monitor network traffic and enforce security policies across the organization. The system provides centralized logging and reporting features, enabling users to gain valuable insights into their security posture and respond swiftly to incidents.

The 100A supports multiple deployment modes, including transparent, NAT, and route modes. This flexibility allows organizations to integrate the device into their existing network architecture with ease. The firewall's high throughput capabilities ensure that network performance remains unaffected, even under heavy load from multiple users and devices.

Another notable aspect of the Fortinet 100A is its support for various VPN technologies, including IPsec and SSL VPN. This feature facilitates secure remote access for employees, enabling them to connect to the corporate network safely, regardless of their location. As remote work continues to be a norm in many sectors, this capability is critical for maintaining productivity and security.

In addition to these features, the Fortinet 100A provides comprehensive web filtering capabilities, protecting users from harmful websites and inappropriate content. This protection is essential for organizations looking to maintain a secure and productive environment.

With its combination of powerful security features, flexible deployment options, and robust performance, the Fortinet 100A stands out as an ideal solution for organizations seeking to bolster their cybersecurity measures while ensuring seamless connectivity for users. As cyber threats continue to evolve, investing in a capable device like the FortiGate 100A is crucial for maintaining a secure network infrastructure.