Manuals
/
Fortinet
/
Computer Equipment
/
Network Card
Fortinet
v3.0 MR7
manual
Directory Service servers
Models:
v3.0 MR7
1
32
66
66
Download
66 pages
4.08 Kb
29
30
31
32
33
34
35
36
Password
Default RC4128
Name field, type admin
See Configuring user groups on
Authentication Settings
Authorization
Directory Service servers
Select Enable Pptp
Using the Query icon
Page 32
Image 32
Directory Service servers
Authentication servers
FortiOS v3.0 MR7 User Authentication User Guide
32
01-30007-0347-20080828
Page 31
Page 33
Page 32
Image 32
Page 31
Page 33
Contents
E R G U I D E
FortiOS v3.0 MR7 User Authentication User Guide
Trademarks
Contents
Configuring authenticated access
Users/peers and user groups
Index
Creating local users Creating peer users
About authentication
Introduction
VPN client-based authentication
User’s view of authentication
Web-based user authentication
FortiGate administrator’s view of authentication
See Creating local users on See Creating peer users on
Authentication servers
See Configuring user groups on
Public Key Infrastructure PKI authentication
Peers
Users
User groups
Authentication timeout
About this document
Firewall policies
VPN tunnels
Typographic conventions
Name field, type admin
FortiGate documentation
FortiGate Administration Guide
Related documentation
FortiManager documentation
FortiClient documentation
FortiMail documentation
FortiAnalyzer documentation
Customer service and technical support
Fortinet Tools and Documentation CD
Fortinet Knowledge Center
Comments on Fortinet technical documentation
Authentication servers
Radius servers
Configuring the FortiGate unit to use a Radius server
Radius attributes sent in Radius accounting message
Primary Server Name/IP
Primary Server Secret
Edit icon Edit a Radius server configuration
Group
Ldap servers
Ldapsearch -x objectclass=
Configuring the FortiGate unit to use an Ldap server
Password
Server Port
Common Name
Identifier
To configure the FortiGate unit for Ldap authentication CLI
Edit
Protocol
Certificate
Using the Query icon
Ldap server Distinguished Name Query tree
TACACS+ servers
Ascii
Authentication Type
Server Key
Directory Service servers
Create New
Domain
Groups
Fsae Collector IP
Directory Service server configuration Name
Fsae Collector IP/Name Port
CLI
Example Directory Service server list
Directory Service servers
Users/peers and user groups
Users/peers
To create a local user web-based manager Go to User Local
User type Authentication
Creating local users
To create a local user CLI
To view a list of all local users, go to User Local
Delete icon Edit icon
Delete icon
To remove a user from the FortiGate unit configuration CLI
Creating peer users
Subject
Authenticating peer user
To view a list of PKI peer users, go to User PKI
To create a peer user for PKI authentication CLI
Remove PKI peer user
Firewall user groups
Directory Service user groups
User groups
SSL VPN user groups
Protection profiles
Firewall
Configuring user groups
Select Create New and enter the following information
Configuring Directory Service user groups
To create a firewall user group CLI
Members
FortiGuard Web
Configuring SSL VPN user groups
Available Users/Groups or Available Members
Configuring Peer user groups
Viewing a list of user groups
To create a peer group CLI
Group Name
Config user group delete groupname End
User groups
Authentication timeout
Authentication protocols
Enter the Idle Timeout value seconds Select Apply
Telnet
Firewall policy authentication
Authentication Settings
Configuring authentication for a firewall policy
Authentication is an Advanced firewall option
To configure authentication for a firewall policy
Go to Firewall Policy
Firewall policy order
Firewall Policy Move To
Zone
Configuring authenticated access to the Internet
Source Interface
VPN authentication
Configuring authentication of SSL VPN users
Select Enable SSL-VPN and enter information as follows
Go to VPN SSL
Default RC4128
Server Certificate
Require Client Certificate
Encryption Key Algorithm
To configure authentication for an SSL VPN CLI
Configuring authentication of VPN peers and clients
Configuring authentication of Pptp VPN users/user groups
Select Enable Pptp
Select Require Client Certificate, and then select Apply
Configuring authentication of L2TP VPN users/user groups
Configuring authentication of remote IPSec VPN users
To configure authentication for a Pptp VPN CLI
To configure authentication for an L2TP VPN CLI
Remote Gateway
To configure user group authentication for dialup IPSec CLI
Only users with passwords on the FortiGate unit
Configuring XAuth authentication
IPSec configuration for dialup users
To configure authentication for a dialup IPSec VPN CLI
Remote Gateway Authentication Method
XAuth
Server Type
VPN authentication
Index
01-30007-0347-20080731
MS-CHAP
VSA
Top
Page
Image
Contents