【正文】
sed authentication Authentication – Services ? Firewall Policies (Firewall User Authentication) ? SSL VPN ? IPSec VPN ? PPTP and L2TP ? Admin login ? FortiGuard Web Filtering Override Firewall Policies ? User Groups linked to Accept Firewall Policies ? On successful authentication a temporary rule is created ? If no traffic present rule remove after the ‘a(chǎn)uthtimeout’ ? Local, RADIUS, LDAP authentication presents user with a login page ? On successful authentication the user is redirected to requested site ? Windows AD (FSAE and NTLM) ? Authentication based on AD Group membership ? PKI user authenticated on presentation of a valid certificate ? HTTPS (and HTTP with redirect to HTTPS) SSL VPN ? User Groups are linked to SSL VPN policies ? Allows users access to the SSL VPN portal ? Creates temporary rules based on SSL VPN firewall policies linked to the User Group ? Local, RADIUS, LDAP present user with a login page ? On successful authentication user is connected to SSL VPN portal ? PKI allows a user to be authenticated on presentation of a valid certificate ? Users directly connected to portal, no username or password is required IPSec VPN ? Phase 1 objects authenticate remote gateways using a Peer ID, and a preshare key or certificate ? Dynamic IP remote gateways (dial up) configure a Local ID which will be sent in the clear when using aggressive mode ? Xauth is used with Dial Up remote gateways to identify the user using a username and password ? Xauth links to a User Group object type firewall PPTP and L2TP ? FortiOS terminates the PPTP/L2TP connection and assigns authentic