Manuals
/
Fortinet
/
Computer Equipment
/
Network Card
Fortinet
v3.0 MR7
manual
Models:
v3.0 MR7
1
65
66
66
Download
66 pages
4.08 Kb
59
60
61
62
63
64
65
66
<
>
Password
Default RC4128
Name field, type admin
See Configuring user groups on
Authentication Settings
Authorization
Directory Service servers
Select Enable Pptp
Using the Query icon
Page 65
Image 65
www.fortinet.com
Page 64
Page 66
Page 65
Image 65
Page 64
Page 66
Contents
E R G U I D E
Trademarks
FortiOS v3.0 MR7 User Authentication User Guide
Contents
Users/peers and user groups
Configuring authenticated access
Index
Creating local users Creating peer users
Introduction
About authentication
VPN client-based authentication
User’s view of authentication
Web-based user authentication
See Creating local users on See Creating peer users on
FortiGate administrator’s view of authentication
See Configuring user groups on
Authentication servers
Peers
Public Key Infrastructure PKI authentication
Users
User groups
About this document
Authentication timeout
Firewall policies
VPN tunnels
Typographic conventions
Name field, type admin
FortiGate documentation
Related documentation
FortiGate Administration Guide
FortiClient documentation
FortiManager documentation
FortiMail documentation
FortiAnalyzer documentation
Fortinet Tools and Documentation CD
Customer service and technical support
Fortinet Knowledge Center
Comments on Fortinet technical documentation
Radius servers
Authentication servers
Radius attributes sent in Radius accounting message
Configuring the FortiGate unit to use a Radius server
Primary Server Secret
Primary Server Name/IP
Group
Edit icon Edit a Radius server configuration
Ldap servers
Ldapsearch -x objectclass=
Configuring the FortiGate unit to use an Ldap server
Server Port
Password
Common Name
Identifier
Edit
To configure the FortiGate unit for Ldap authentication CLI
Protocol
Certificate
Ldap server Distinguished Name Query tree
Using the Query icon
Ascii
TACACS+ servers
Server Key
Authentication Type
Directory Service servers
Domain
Create New
Groups
Fsae Collector IP
Fsae Collector IP/Name Port
Directory Service server configuration Name
CLI
Example Directory Service server list
Directory Service servers
Users/peers
Users/peers and user groups
To create a local user web-based manager Go to User Local
User type Authentication
Creating local users
To create a local user CLI
To view a list of all local users, go to User Local
Delete icon Edit icon
Delete icon
To remove a user from the FortiGate unit configuration CLI
Creating peer users
Subject
Authenticating peer user
To view a list of PKI peer users, go to User PKI
Remove PKI peer user
To create a peer user for PKI authentication CLI
Firewall user groups
Directory Service user groups
User groups
Protection profiles
SSL VPN user groups
Firewall
Configuring user groups
Select Create New and enter the following information
To create a firewall user group CLI
Configuring Directory Service user groups
Members
FortiGuard Web
Available Users/Groups or Available Members
Configuring SSL VPN user groups
Viewing a list of user groups
Configuring Peer user groups
To create a peer group CLI
Group Name
Config user group delete groupname End
User groups
Authentication protocols
Authentication timeout
Enter the Idle Timeout value seconds Select Apply
Telnet
Authentication Settings
Firewall policy authentication
Authentication is an Advanced firewall option
Configuring authentication for a firewall policy
To configure authentication for a firewall policy
Go to Firewall Policy
Firewall Policy Move To
Firewall policy order
Zone
Configuring authenticated access to the Internet
Source Interface
Configuring authentication of SSL VPN users
VPN authentication
Select Enable SSL-VPN and enter information as follows
Go to VPN SSL
Server Certificate
Default RC4128
Require Client Certificate
Encryption Key Algorithm
To configure authentication for an SSL VPN CLI
Configuring authentication of Pptp VPN users/user groups
Configuring authentication of VPN peers and clients
Select Enable Pptp
Select Require Client Certificate, and then select Apply
Configuring authentication of remote IPSec VPN users
Configuring authentication of L2TP VPN users/user groups
To configure authentication for a Pptp VPN CLI
To configure authentication for an L2TP VPN CLI
Remote Gateway
To configure user group authentication for dialup IPSec CLI
Only users with passwords on the FortiGate unit
IPSec configuration for dialup users
Configuring XAuth authentication
Remote Gateway Authentication Method
To configure authentication for a dialup IPSec VPN CLI
XAuth
Server Type
VPN authentication
Index
01-30007-0347-20080731
MS-CHAP
VSA
Top
Page
Image
Contents