【正文】
reates temporary rules based on SSL VPN firewall policies linked to the User Group ? Local, RADIUS, LDAP present user with a login page ? On successful authentication user is connected to SSL VPN portal ? PKI allows a user to be authenticated on presentation of a valid certificate ? Users directly connected to portal, no username or password is required IPSec VPN ? Phase 1 objects authenticate remote gateways using a Peer ID, and a preshare key or certificate ? Dynamic IP remote gateways (dial up) configure a Local ID which will be sent in the clear when using aggressive mode ? Xauth is used with Dial Up remote gateways to identify the user using a username and password ? Xauth links to a User Group object type firewall PPTP and L2TP ? FortiOS terminates the PPTP/L2TP connection and assigns authenticated users an address out of the configured address pool ? On successful authentication a temporary rule matching the configured address pool is created ? Local, RADIUS and LDAP used to authenticate connecting users Admin login ? Admin account link to a profile defining the users role and VDOM membership ? Local and RADIUS ? If both are configured the RADIUS object is attempted first and then if no response the Local password is used ? RADIUS Accounting packets sent for Admin users ? PKI allows a user to be authenticated on presentation of a valid certificate ? Users directly connected to the WebUI, no username or password is required RADIUS ? FortiGate acts as a work access server (NAS) ? User information passed to the RADIUS server ? User authenticated based on the RADIUS servers re