Introduction 4 Features 4 Downloading FortiClient (Android) 7.2 5 Chromebook support 5 Product integration and support 7 Getting started 8 Launching FortiClient (Android) for the first time 8 Launching FortiClient (Android) from the notification bar 9 Quitting FortiClient (Android) from the app menu 9 Force stopping FortiClient (Android) from the Apps page 9 Web security 11 Web security status 12 Web security settings 12 VPN 14 SSL VPN 14创建SSL VPN连接14连接到VPN 19编辑SSL VPN设置或删除SSL VPN配置21启用/禁用自动启动22启动DTLS 22 IPSEC VPN 22 IPSEC VPN 23创建IPSEC VPN连接24连接到IPSEC VPN IPSEC VPN 2 28 EDEN 28 EDIND 2 28 EDIND 2 28 EDIND ODIND AT AT 2 28 EDIND OR EDITION ODITION ODITION ODITION ODITER ODITIND ODITION ODITION ODITIND ODITIND ODITIND ODITIND ODITIND ODITIND ODITIND ODITION ODITIS启用/禁用AutoStart 30推动VPN身份验证证书31 VPN证书路径31使用MDM推动VPN身份验证证书32独立VPN客户端33端点控制34 FortIcLient EMS 34配置Forticlient EMS EMS EMS EMS端口配置文件34 EMS连接机制36配置34 EMS INDER 36 EMS INDER 36配置36 EMPERTION 36权限39更改日志41
•隧道:站点到站点,轮毂和辐条,动态端点,AUTOVPN,ADVPN,组VPN(IPV4/ipv6/dual stack)•杜松安全连接:远程访问/ssl vpn•配置有效载荷:yes yes y yes•ike Engryption angorthms:ike Engryption algorithms:prime,prime,prime,des-cbc,3dees-cbc,aec-cb cm,aec-cb cm cb cb cb cb cb cb cb cb cb cb cb• IKE authentication algorithms: MD5, SHA-1, SHA-128, SHA-256, SHA-384 • Authentication: Pre-shared key and public key infrastructure (PKI) (X.509) • IPsec: Authentication Header (AH)/Encapsulating Security Payload (ESP) protocol • IPsec Authentication Algorithms: hmac-md5, hmac-sha-196, hmac-sha-256 • IPsec Encryption Algorithms: Prime, DES-CBC, 3DES-CBC, AEC-CBC, AES-GCM, Suite B • Perfect forward secrecy, anti-reply • Internet Key Exchange: IKEv1, IKEv2 • Monitoring: Standard-based dead peer detection (DPD) support, VPN monitoring • VPNs GRE, IP-IP和MPLS
3 安全软件标准................................................................................................7 3.1 IPsec 安全标准......................................................................................7 3.1.1 TCP/IP 协议和层..............................................................................8 3.1.2 TCP/IP 安全性................................................................................10 3.1.3 IPsec.............................................................................................11 3.1.4 IPsec 使用示例.............................................................................11 3.2 通用标准.............................................................................................12 3.2.1 通用标准概述....................................................................................12 3.2.2 通用标准评估保证级别....................................................................14 3.2.3 通用标准示例....................................................................................15 3.3 标准对美国政府的影响.....................................................................16
和 CISA 建议使用 IPsec VPN。特别是经过测试和验证并列入国家信息保障伙伴关系 (NIAP) 产品合规列表 的 IPsec VPN 产品。基于 TLS 的 VPN 缺乏标准化,无法客观衡量其保障,目前不建议用于通用 IP 流量的隧道传输。使用此选项的组织可以将其云租户配置为仅接受来自 VPN 的连接。然后,他们可以使用 VPN 集中管理访问并记录和监控网络流量,为组织提供额外的安全层和对其云租户使用情况的可见性。有关 VPN 的更多指导,请参阅 NSA 的报告:选择和强化远程访问 VPN 解决方案、网络基础设施安全指南和配置 IPsec 虚拟专用网络。[4]、[5]、[6] 组织可以使用 VPN 来保护客户端与租户的连接以及与云资源的连接。虽然它们不是执行此操作的唯一机制,但 VPN 是确保在整个组织内一致执行加密要求的不错选择。
LookAside Crypto和压缩引擎LCE为静止和运输中的数据提供了lookaside加密和压缩服务。LCE引擎通过通过压缩来减少数据来改善大数据,文件系统和数据库的吞吐量。同时支持多达100Gbps压缩加上100Gbps减压。当数据在运输中时,LCE可确保使用真实性,完整性和隐私协议(例如TLS,DTLS,QUIC,IPSEC,IPSEC,PSP)确保数据完好无损。当数据静止时,LCE会提供设备级加密,存储级加密和磁盘上的数据保护。
更改日志5简介6许可6特殊通知7启用完整磁盘访问7激活系统扩展8 VPN 8 Web过滤器和应用防火墙8代理模式扩展9启用通知9 dhcp ipsec vpn不支持IPSEC VPN 10运行多个fortiguard fortering fortering fort fort fort fort fort fort fort fort fort fort fort fort fort fort fort fort fort fort fort fort fort fort( 7.4.0 11 Installation information 12 Firmware images and tools 12 Upgrading from previous FortiClient versions 12 Downgrading to previous versions 12 Uninstalling FortiClient 13 Firmware image checksums 13 Product integration and support 14 Language support 15 Resolved issues 16 Application Firewall 16 Deployment and installers 16 GUI 16 Logs 17 Remote Access 17 Remote Access - IPsec VPN 17 Remote Access - SSL VPN 18 FSSOMA 18 Malware Protection and沙盒18零信托遥测18其他19个已知问题20申请防火墙20部署和安装程序20端点控制20 FSSOMA 20 GUI 21
Change log 5 Introduction 6 Licensing 6 Special notices 7 Enabling full disk access 7 Activating system extensions 8 VPN 8 Web Filter and Application Firewall 9 Proxy mode extension 10 Enabling notifications 10 DHCP over IPsec VPN not supported 10 IKEv2 not supported 10 Running multiple FortiClient instances 11 IPsec VPN support limitation 11 Installation information 12 Firmware images and tools 12 Upgrading from previous FortiClient versions 12 Downgrading to previous versions 12 Uninstalling FortiClient 13 Firmware image checksums 13 Product integration and support 14 Language support 15 Resolved issues 16 GUI 16 Deployment and installers 16 Remote Access 16 Remote Access - SSL VPN 16 Upgrade 17 ZTNA connection rules 17 Other 17 Known issues 18 New known issues 18 Existing known issues 18 Configuration 18 Dashboard 18 Endpoint control 19 Remote Access 19 Remote Access - IPsec VPN 19远程访问-SSL VPN 20漏洞扫描20 Web过滤器和插件20零信任标签21
Change log 5 Introduction 6 Licensing 6 Special notices 7 Enabling full disk access 7 Activating system extensions 8 VPN 8 Web Filter and Application Firewall 9 Proxy mode extension 10 Enabling notifications 10 DHCP over IPsec VPN not supported 10 IKEv2 not supported 10 Running multiple FortiClient instances 11 IPsec VPN support limitation 11 Installation information 12 Firmware images and tools 12 Upgrading from previous FortiClient versions 12 Downgrading to previous versions 12 Uninstalling FortiClient 13 Firmware image checksums 13 Product integration and support 14 Language support 15 Resolved issues 16 GUI 16 Remote Access - SSL VPN 16 Known issues 17 New known issues 17 Existing known issues 17 Configuration 17 Dashboard 17 Endpoint control 18 Remote Access 18 Remote Access - IPsec VPN 18 Remote Access - SSL VPN 19 Vulnerability Scan 19 Web Filter and plugin 19零信托标签20应用程序防火墙20头像和社交登录信息20许可证20部署和安装程序20安装和升级20
Prisma Access connects remote networks over a standard IPsec connection—using any existing router, software-defined wide area networking (SD-WAN) edge device, or firewall that supports IPsec—to secure traffic, protect confidential information, and address data privacy needs.Prisma Access使用Palo Alto Networks Prisma SD-WAN,下一代防火墙(NGFWS)和第三方供应商产品支持SD-WAN选项。Prisma SD-WAN可用的Prisma访问的ADEM附加组件将路径和性能可见性扩展到所有用户的所有分支位置,而无需其他代理。解决方案监视影响Prisma SD-WAN站点体验的条件,包括分支应用程序,设备和用户交通,并根据需要执行自动补救。