Step 1: Basic Connection Setup
Open FortiClient and click Configure VPN (or click the gear/edit icon next to an existing connection).
Set VPN to IPsec VPN.
Fill out the general settings:
Connection Name:
FCI IPSEC VPNRemote Gateway: fcimarilao
.fortiddns.comAuthentication Method: Select Pre-shared key and enter your pre-shared key password (P!nkpetrel!).
Authentication (EAP): Select Save login.
Username:
(VPN Account)Failover SSL VPN:
[None]
Step 2: Expand Advanced Settings Click on + Advanced Settings at the bottom of the window to reveal VPN Settings, Phase 1, and Phase 2.
Step 3: Configure VPN Settings (Advanced Settings)
IKE: Select Version 2.
Address Assignment: Select Mode Config.
Encapsulation: Select Auto (UDP fallback TCP).
IKE UDP Port:
500IKE TCP Port:
5500
Step 4: Configure Phase 1
IKE Proposal 1:
Encryption: AES256 | Authentication: SHA256
IKE Proposal 2:
Encryption: AES256 | Authentication: SHA512
DH Group: Check 20 (uncheck all other groups).
Key Life:
86400secLocal ID: Leave blank (Optional).
Check Dead Peer Detection.
Check NAT Traversal.
Uncheck Enable Local LAN.
Step 5: Configure Phase 2
IKE Proposal 1:
Encryption: AES256 | Authentication: SHA256
IKE Proposal 2:
Encryption: AES256 | Authentication: SHA512
Key Life: Check Seconds and enter
43200(uncheck KBytes).Check Enable Replay Detection.
Check Enable Perfect Forward Secrecy (PFS).
DH Group: Select 20 from the drop-down menu.
Step 6: Save and Connect
Click Save at the bottom of the window.
Enter the password for account when prompted on the main screen and click Connect.
Was this article helpful?
That’s Great!
Thank you for your feedback
Sorry! We couldn't be helpful
Thank you for your feedback
Feedback sent
We appreciate your effort and will try to fix the article