FortiGate Version 3.0 MR4 Administration Guide
298 01-30004-0203-20070102
Manual Key VPN IPSEC
Remote Gateway Type the IP address of the public interface to the remote peer. The
address identifies the recipient of ESP datagrams.
Local Interface This option is available in NAT/Route mode only. Select the name of
the physical, aggregate, or VLAN interface to which the IPSec tunnel
will be bound. The FortiGate unit obtains the IP address of the
interface from System > Network > Interface settings (see
“Interface” on page 69).
Encryption
Algorithm
Select one of the following symmetric-key encryption algorithms:
• DES-Digital Encryption Standard, a 64-bit block algorithm that
uses a 56-bit key.
• 3DES-Triple-DES, in which plain text is encrypted three times by
three keys.
• AES128-A 128-bit block algorithm that uses a 128-bit key.
• AES192-A 128-bit block algorithm that uses a 192-bit key.
• AES256-A 128-bit block algorithm that uses a 256-bit key.
Encryption Key If you selected:
• DES, type a 16-character hexadecimal number (0-9, a-f).
• 3DES, type a 48-character hexadecimal number (0-9, a-f)
separated into three segments of 16 characters.
• AES128, type a 32-character hexadecimal number (0-9, a-f)
separated into two segments of 16 characters.
• AES192, type a 48-character hexadecimal number (0-9, a-f)
separated into three segments of 16 characters.
• AES256, type a 64-character hexadecimal number (0-9, a-f)
separated into four segments of 16 characters.
Authentication
Algorithm
Select one of the following message digests:
• MD5-Message Digest 5 algorithm, which produces a 128-bit
message digest.
• SHA1-Secure Hash Algorithm 1, which produces a 160-bit
message digest.
Authentication Key If you selected:
• MD5, type a 32-character hexadecimal number (0-9, a-f)
separated into two segments of 16 characters.
• SHA1, type 40-character hexadecimal number (0-9, a-f)
separated into one segment of 16 characters and a second
segment of 24 characters.
IPSec Interface
Mode
Create a virtual interface for the local end of the VPN tunnel.
This command is available only in NAT/Route mode.