Chapter 11 IPsec VPN for FortiOS 5.0 : Supporting IKE Mode config clients : Automatic configuration overview
  
Automatic configuration overview
VPN configuration for remote clients is simpler if it is automated. Several protocols support automatic configuration:
The Fortinet FortiClient Endpoint Security application can completely configure a VPN connection with a suitably configured FortiGate unit given only the FortiGate unit’s address. This protocol is exclusive to Fortinet. For more information, see the “FortiClient dialup-client configurations” chapter.
DHCP over IPsec can assign an IP address, Domain, DNS and WINS addresses. The user must first configure IPsec parameters such as gateway address, encryption and authentication algorithms.
IKE Mode Config can configure host IP address, Domain, DNS and WINS addresses. The user must first configure IPsec parameters such as gateway address, encryption and authentication algorithms. Several network equipment vendors support IKE Mode Config, which is described in the ISAKMP Configuration Method document draft‑dukes-ike-mode-cfg-02.txt.
This chapter describes how to configure a FortiGate unit as either an IKE Mode Config server or client.