IPSec VPN

Configuring encrypt policies

 

 

Adding a destination address

The destination address can be a VPN client address on the Internet or the address of a network behind a remote VPN gateway.

To add a destination address

1Go to Firewall > Address.

2Select an external interface.

3Select New to add an address.

4Enter the Address Name, IP Address, and NetMask for a single computer or for an entire subnetwork on an internal interface of the remote VPN peer.

5Select OK to save the destination address.

Adding an encrypt policy

To add an encrypt policy

1Go to Firewall > Policy.

2Select the policy list that you want to add the policy to (usually, Internal->External).

3Select New to add a new policy.

4Set Source to the source address.

5Set Destination to the destination address.

6Set Service to control the services allowed over the VPN connection.

You can select ANY to allow all supported services over the VPN connection or select a specific service or service group to limit the services allowed over the VPN connection.

7Set Action to ENCRYPT.

8Configure the ENCRYPT parameters.

FortiGate-800 Installation and Configuration Guide

247

Page 247
Image 247
Fortinet FortiGate-800 manual Adding a destination address, Adding an encrypt policy, 247