IPSec VPN | AutoIKE IPSec VPNs |
|
|
10Enable Autokey Keep Alive if you want to keep the VPN tunnel running even if no data is being processed.
11Select a concentrator if you want the tunnel to be part of a hub and spoke VPN configuration.
If you use the procedure, “Adding a VPN concentrator” on page 251 to add the tunnel to a concentrator, the next time you open the tunnel, the Concentrator field displays the name of the concentrator to which you added the tunnel.
12Select a Quick Mode Identity.
Use selectors from policy | Select this option for |
| VPN uses an encrypt policy to select which VPN tunnel to |
| use for the connection. In this configuration, the VPN tunnel |
| is referenced directly from the encrypt policy. |
| You must select this option if both VPN peers are FortiGate |
| units. |
Use wildcard selectors | Select this option for |
| VPN uses routing information to select which VPN tunnel to |
| use for the connection. In this configuration, the tunnel is |
| referenced indirectly by a route that points to a tunnel |
| interface. |
| You must select this option if the remote VPN peer is a non- |
| FortiGate unit that has been configured to operate in tunnel |
| interface mode. |
13Select OK to save the AutoIKE key VPN tunnel.
Figure 58: Adding a phase 2 configuration
241 |