Chapter 11 IPsec VPN for FortiOS 5.0 : IPsec VPN in the web-based manager : Auto Key (IKE) : FortiClient VPN
  
FortiClient VPN
Use the FortiClient VPN configuration settings when configuring an IPsec VPN for remote users to connect to the VPN tunnel using FortiClient.
To create a FortiClient VPN tunnel, go to VPN > IPsec > Auto Key (IKE) and select Create FortiClient VPN at the top of the screen.
When configuring a FortiClient VPN connection, the settings for phase 1 and phase 2 settings are automatically configured by the FortiGate unit. They are set to:
Remote Gateway — Dialup User
Mode — Aggressive
IPSec Interface Mode — Enabled
Default settings for P1 and P2 Proposal
XAUTH Enable as Server (Auto)
IKE mode-config will be enabled
Peer Option — “Accept any peer ID”
The remainder of the settings use the current FortiGate defaults. Note that FortiClient settings need to match these FortiGate defaults. If you need to configure advanced settings for the FortiClient VPN, select Edit on the Auto Key (IKE) page (Go to VPN > IPsec > Auto Key (IKE)) and configure the peer options or advanced options.
Name
Enter a name for the FortiClient VPN.
Local Outgoing Interface
Select the local outgoing interface for the VPN.
Authentication Method
Select the type of authentication used when logging in to the VPN.
Preshared Key
If Pre-shared Key was selected in Authentication Method, enter the pre-shared key in the field provided.
User Group
Select a user group. You can also create a user group from the drop-down list by selecting Create New.
Address Range Start IP
Enter the start IP address for the DHCP address range for the client.
Address Range End IP
Enter the end IP address for the address range.
Subnet Mask
Enter the subnet mask.
Enable IPv4 Split Tunnel
Enabled by default, this option enables the FortiClient user to use the VPN to access internal resources while other Internet access is not sent over the VPN, alleviating potential traffic bottlenecks in the VPN connection. Disable this option to have all traffic sent through the VPN tunnel.
Accessible Networks
Select from a list of internal networks that the FortiClient user can access.
Client Options
These options affect how the FortiClient application behaves when connected to the FortiGate VPN tunnel. When enabled, a check box for the corresponding option appears on the VPN login screen in FortiClient, and is not enabled by default.
Save Password - When enabled, if the user selects this option, their password is stored on the user’s computer and will automatically populate each time they connect to the VPN.
Auto Connect - When enabled, if the user selects this option, when the FortiClient application is launched, for example after a reboot or system startup, FortiClient will automatically attempt to connect to the VPN tunnel.
Always Up (Keep Alive) - When enabled, if the user selects this option, the FortiClient connection will not shut down. When not selected, during periods of inactivity, FortiClient will attempt to stay connected every three minutes for a maximum of 10 minutes.
Endpoint Registration
When selected, the FortiGate unit requests a registration key from FortiClient before a connection can be established. A registration key is defined by going to System > Config > Advanced.
For more information on FortiClient VPN connections to a FortiGate unit, see the FortiClient Administration Guide.
DNS Server
Select which DNS server to use for this VPN:
Use System DNS — Use the same DNS servers as the FortiGate unit. These are configured at System > Interface > DNS. This is the default option.
Specify — Specify the IP address of a different DNS server.