I'm used to configuring IPSec tunnels manually, and specifying encapsulation, hash, etc. I have Fortigate 30e firewalls, and whenever you select "Create new" under "IPSec tunnels" it takes you to the Wizard. This is fine, but if I want to use an undocumented client on Linux such as Openswan or Shrewsoft, I can't find the detailed phase 1 and phase 2 configs. It appears that some configuration details are "baked in" and not displayed when you dump the configuration.
Is there some documentation as to what is used for all IPSec config attributes? For example, DES, 3DES, etc.
Thanks
Solved! Go to Solution.
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
The documentation covers a lots of it: http://help.fortinet.com/fos50hlp/56/Content/FortiOS/fortigate-ipsecvpn/IntroVPN.htm, including some of the CLI settings.
To see more of the possible settings in the GUI, you need to convert a wizard created tunnel to a custom tunnel. This is hidden in the docs - see the beginning of http://help.fortinet.com/fos50hlp/56/Content/FortiOS/fortigate-ipsecvpn/Phase_2/Config_Phase2_Parame....
To see more details than that you'll need to go to the CLI section for vpn ipsec, for example:
config vpn ipsec phase1-interface
config vpn ipsec phase2-interface
See the CLI admin guide for more details on the CLI elements:
http://help.fortinet.com/cli/fos50hlp/56/index.htm
https://docs.fortinet.com/d/fortigate-fortios-5.6.6-cli-reference
Remember that in the CLI you need to "show full" to see all options, and that some won't show up unless/until you set various modes for the object you're looking at, though "tree" will show everything.
There are also a number of cookbook articles on IPSec VPN.
The documentation covers a lots of it: http://help.fortinet.com/fos50hlp/56/Content/FortiOS/fortigate-ipsecvpn/IntroVPN.htm, including some of the CLI settings.
To see more of the possible settings in the GUI, you need to convert a wizard created tunnel to a custom tunnel. This is hidden in the docs - see the beginning of http://help.fortinet.com/fos50hlp/56/Content/FortiOS/fortigate-ipsecvpn/Phase_2/Config_Phase2_Parame....
To see more details than that you'll need to go to the CLI section for vpn ipsec, for example:
config vpn ipsec phase1-interface
config vpn ipsec phase2-interface
See the CLI admin guide for more details on the CLI elements:
http://help.fortinet.com/cli/fos50hlp/56/index.htm
https://docs.fortinet.com/d/fortigate-fortios-5.6.6-cli-reference
Remember that in the CLI you need to "show full" to see all options, and that some won't show up unless/until you set various modes for the object you're looking at, though "tree" will show everything.
There are also a number of cookbook articles on IPSec VPN.
The "convert to a custom tunnel" is exactly what I needed, thanks. I've configured all sorts of IPSec firewalls manually with clients, so I needed control (and views) of both sides. I was attempting to guess the phase 1 SA settings.
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1712 | |
1093 | |
752 | |
447 | |
231 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.