Results 1 to 3 of 3

Thread: Configure SSL-VPN on FortiGate 60

  1. #1
    Join Date
    Dec 2008
    Posts
    68

    idea Configure SSL-VPN on FortiGate 60

    Hello Everybody,

    I would like to know that how do i configure SSL-VPN on my FortiGate 60. I would like to create a username for my we browser. Can any body provide me the correct logical steps for doing it? Would be grateful to you if any body helps me out to resolve the above issue.

    Thanks.

  2. #2
    Join Date
    Apr 2008
    Posts
    2,277

    Re: Configure SSL-VPN on FortiGate 60

    The Fortigate can be used to create an encrypted tunnel between hosts. CRYPTO-MAS works in conjunction with the Fortigate to replace static passwords with strong two-factor authentication that prevents the use of lost, stolen, shared, or easily guessed passwords when establishing a connection to gain access to protected resources. With CRYPTO-MAS acting as the authentication server for a VPN enabled resource, an authenticated connection sequence would be as follows:
    1. The administrator configures the Fortinet Fortigate 60 to use RADIUS Authentication.
    2. The incoming RADIUS authentication request is relayed over to the CRYPTO-MAS Server.
    3. The CRYPTO-MAS Server examines the incoming packet. If the user exists, it then checks the token associated with the user for the expected PIN + One-time password.
    4. Once the PIN + One-time password is verified against the user’s token and it is valid, it will then send an access accepted.
    If the user does not exist, or the PIN + One-time password is incorrect it will send the user an access reject message.

  3. #3
    Join Date
    May 2008
    Posts
    2,134

    Re: Configure SSL-VPN on FortiGate 60

    Here's a best practice or simple configuration on setting this up:

    set zone name VPN
    set int tun.1 zone VPN
    set int tun.1 ip unnumbered interface <untrust port; ie...eth1>
    <bind vpn to tunnel.1 here and setup proxy-id>
    set pol from trust to vpn any any any per log
    set pol from vpn to trust any any any per log
    Now, if the tunnel doesn't come up , stay up, even after triple checking the proxy-id matches the Fortinet, then move it to a policy based tunnel from untrust to trust with a matching policy.

Similar Threads

  1. Replies: 5
    Last Post: 29-01-2012, 08:37 PM
  2. How to configure RIS
    By Anuraag in forum Networking & Security
    Replies: 3
    Last Post: 10-10-2009, 02:21 PM
  3. Unable to configure SSL-VPN with FortiGate 60B
    By Mahendra varma in forum Technology & Internet
    Replies: 3
    Last Post: 27-04-2009, 08:13 PM
  4. How to Configure a VPN
    By SpearMan in forum Networking & Security
    Replies: 6
    Last Post: 04-02-2009, 02:47 PM
  5. How to configure the UPS
    By Godley in forum Windows XP Support
    Replies: 3
    Last Post: 02-04-2008, 09:20 PM

Tags for this Thread

Bookmarks

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •  
Page generated in 1,713,489,276.65043 seconds with 17 queries