Chapter 10 IPsec VPN : Phase 1 parameters : Using XAuth authentication : Using the FortiGate unit as an XAuth client
  
Using the FortiGate unit as an XAuth client
If the FortiGate unit acts as a dialup client, the remote peer, acting as an XAuth server, might require a username and password. You can configure the FortiGate unit as an XAuth client, with its own username and password, which it provides when challenged.
To configure the FortiGate dialup client as an XAuth client
1. At the FortiGate dialup client, go to VPN > IPsec > Tunnels and create the new custom tunnel or edit an existing tunnel.
2. Edit the Phase 1 Proposal (if it is not available, you may need to click the Convert to Custom Tunnel button).
3. Under XAuth, select Enable as Client.
4. In the Username field, type the FortiGate PAP, CHAP, RADIUS, or LDAP user name that the FortiGate XAuth server will compare to its records when the FortiGate XAuth client attempts to connect.
5. In the Password field, type the password to associate with the user name.
6. Select OK.