| Configuration Item (Fortinet) |
Description |
| Template type: site-to-site, hub-and-spoke, and remote access |
- This is a proprietary feature. We recommend that you customize settings as needed. - The site-to-site and remote access types are available only for Fortinet and Cisco. - The hub-and-spoke type is available only for Fortinet. |
| Forward Error Correction |
- This is a proprietary feature, which is disabled by default. Fortinet incorporates FEC into its IPsec VPN service to enhance data transmission reliability and efficiency. FEC can detect and correct data errors during data transmission, and therefore reduces the data loss and retransmission rate. - We recommend that you disable it. Otherwise, IPsec VPN tunnel establishment may be affected. |
| Device creation Aggregate member |
- These are proprietary features, which are disabled by default. Ignore them. - We recommend that you disable them. Otherwise, IPsec VPN tunnel establishment may be affected. |
| XAUTH |
- Athena NGFW does not support this feature. This is an additional feature for identity authentication during the IPsec VPN tunnel establishment, which can enhance security. It is supported only for IKEv1. By default, it is disabled in Fortinet. - We recommend that you disable it. Otherwise, IPsec VPN tunnel establishment may be affected. |
| Selector |
- This is equivalent to an encrypted traffic entry in Athena NGFW in policy mode. We recommend that you configure a single selector using an all-0 address. - This is equivalent to the traffic of interest in Athena NGFW in route mode. If IPv4 is enabled in Athena NGFW, it is equivalent to a Fortinet selector using an all-0 IPv4 address. If IPV6 is enabled in Athena NGFW, it is equivalent to a Fortinet selector using an all-0 IPv6 address. |
| Local Address: IP address ranges, IPv6 address ranges, named addresses, and IPv6 named addresses Remote Address: IP address ranges, IPv6 address ranges, named addresses, and IPv6 named addresses |
- These are proprietary features. By contrast, Athena NGFW supports only subnets, IPv6 subnets, IP addresses, and IPv6 addresses. - We recommend that you do not use IP address ranges, because Athena NGFW does not support IP address ranges. Otherwise, IPsec VPN tunnel establishment may fail. - When a named address (address group) is used in policy mode, we recommend that you use IKEv2. Otherwise, IPsec VPN tunnel establishment may fail in phase 2. |
| Diffie-Hellman Group: group31 and group32 |
Athena NGFW does not support these DH groups. Use other DH groups as needed, which do not affect IPsec VPN tunnel establishment. |
| Encryption: CHACHA20POLY1305 |
Athena NGFW does not support this encryption algorithm. Use other algorithms as needed, which do not affect IPsec VPN tunnel establishment. |
| Enable Replay Detection |
- Athena NGFW does not support customizing reply detection settings, and disables replay detection by default. - By default, replay detection is enabled in Fortinet. If the peer end has two Fortinet firewalls deployed in active/standby mode, disable this feature. Otherwise, business may be interrupted during an active/standby switchover. |
| Local Port Remote Port Protocol |
- These are proprietary features, which are used to configure the phase-2 local port, peer port, and protocol. By default, all local and remote ports and all protocols are selected. - We recommend that you select all local and remote ports and all protocols. Otherwise, IPsec VPN tunnel establishment may be affected. |
| Other |
Use the default settings, which do not affect IPsec VPN tunnel establishment. |