VPN

ipsec phase2

 

 

ipsec phase2

Use the config vpn ipsec phase2 CLI command to add or edit an IPSec VPN phase 2 configuration.

Command syntax pattern

config vpn ipsec phase2 edit <name_str>

set <keyword> <variable>

end

config vpn ipsec phase2 edit <name_str>

unset <keyword>

end

config vpn ipsec phase2 delete <name_str> end

get vpn ipsec phase2 [<name_str>]

show vpn ipsec phase2 [<name_str>]

ipsec phase2 command keywords and variables

Keywords and variables

Description

Default

Availability

bindtoif

Bind the tunnel to the specified

No

All models.

<interface-name_str>

network interface. Type the name of

default.

 

 

the local FortiGate interface.

 

 

dstaddr <name_str>

Enter the name of the firewall

No

All models.

 

destination IP address that

default.

selector

 

corresponds to the recipient or

 

must be set

 

network behind the remote VPN

 

to

 

peer. You must create the firewall

 

specify.

 

address before you can select it here.

 

 

For more information, see “Adding

 

 

 

firewall policies for IPSec VPN

 

 

 

tunnels” on page 266.

 

 

dstport

Enter the port number that the remote

No

All models.

<port_integer>

VPN peer uses to transport traffic

default.

selector

 

related to the specified service (see

 

must be set

 

protocol). The dstport range is 1

 

to

 

to 65535. To specify all ports, type 0.

 

.

 

 

 

specify

protocol

Enter the IP protocol number for the

No

All models.

<protocol_integer>

service. The protocol range is 1 to

default.

selector

 

255. To specify all services, type 0.

 

must be set

 

 

 

to

 

 

 

specify.

FortiGate-100A Administration Guide

01-28007-0068-20041203

271

Page 271
Image 271
Fortinet 100A manual Ipsec phase2 command keywords and variables, 271, Network behind the remote VPN

100A specifications

Fortinet 100A is a versatile network security device designed to provide comprehensive protection against various cyber threats while ensuring optimal network performance. As part of the FortiGate series, the 100A combines advanced security features with powerful hardware capabilities, making it suitable for small to medium-sized businesses.

One of the key features of the Fortinet 100A is its deep packet inspection technology. This capability allows the firewall to analyze both the header and payload of packets traversing the network, enabling it to detect and block malicious content effectively. The 100A can identify and mitigate a wide range of threats, including malware, intrusions, and application-layer attacks.

The FortiOS operating system powers the Fortinet 100A, offering a robust and user-friendly interface for configuration and management. With its unified security management console, administrators can efficiently monitor network traffic and enforce security policies across the organization. The system provides centralized logging and reporting features, enabling users to gain valuable insights into their security posture and respond swiftly to incidents.

The 100A supports multiple deployment modes, including transparent, NAT, and route modes. This flexibility allows organizations to integrate the device into their existing network architecture with ease. The firewall's high throughput capabilities ensure that network performance remains unaffected, even under heavy load from multiple users and devices.

Another notable aspect of the Fortinet 100A is its support for various VPN technologies, including IPsec and SSL VPN. This feature facilitates secure remote access for employees, enabling them to connect to the corporate network safely, regardless of their location. As remote work continues to be a norm in many sectors, this capability is critical for maintaining productivity and security.

In addition to these features, the Fortinet 100A provides comprehensive web filtering capabilities, protecting users from harmful websites and inappropriate content. This protection is essential for organizations looking to maintain a secure and productive environment.

With its combination of powerful security features, flexible deployment options, and robust performance, the Fortinet 100A stands out as an ideal solution for organizations seeking to bolster their cybersecurity measures while ensuring seamless connectivity for users. As cyber threats continue to evolve, investing in a capable device like the FortiGate 100A is crucial for maintaining a secure network infrastructure.