ZyXEL Communications SBG5500-A User Manual page 173

Sbg5500 series, small business gateway
Hide thumbs Also See for SBG5500-A:
Table of Contents

Advertisement

Table 71 VPN Connection: Add/Edit
LABEL
Application Scenario
VPN Gateway
Policy
Local policy
Remote Policy
Full Tunnel
Phase 2 Settings
SA Life Time
Advanced
Encapsulation
Proposal
Add
Edit
Remove
#
Chapter 10 VPN
DESCRIPTION
Select the scenario that best describes your intended VPN connection.
Site-to-site - Choose this if the remote IPsec router has a static IP address or a
domain name. This SBG can initiate the VPN tunnel.
Site-to-site with Dynamic Peer - Choose this if the remote IPsec router has a dynamic
IP address. Only the remote IPsec router can initiate the VPN tunnel.
Remote Access (Server Role) - Choose this to allow incoming connections from IPsec
VPN clients. The clients have dynamic IP addresses and are also known as dial-in
users. Only the clients can initiate the VPN tunnel.
Remote Access (Client Role) - Choose this to connect to an IPsec server. This SBG is
the client (dial-in user) and can initiate the VPN tunnel.
Select the VPN gateway this VPN connection is to use.
Type the IP address of a computer on your network. You can also specify a subnet.
This must match the remote IP address configured on the remote IPsec device.
Type the IP address of a computer behind the remote IPsec device. You can also
specify a subnet. This must match the local IP address configured on the remote
IPsec device.
Select this check box if you need the SBG to send packets through the VPN Tunnel.
Type the maximum number of seconds the IPsec SA can last. Shorter life times
provide better security. The SBG automatically negotiates a new IPsec SA before the
current one expires, if there are users who are accessing remote resources.
Select which type of encapsulation the IPsec SA uses. Choices are:
Tunnel - this mode encrypts the IP header information and the data.
Transport - this mode only encrypts the data.
The SBG and remote IPsec router must use the same encapsulation.
Use this section to manage the encryption algorithm and authentication algorithm
pairs the SBG accepts from the remote IPsec router for negotiating the IPsec SA.
Click this to create a new entry.
Select an entry and click this to be able to modify it.
Select an entry and click this to delete it.
This field is a sequential value, and it is not associated with a specific proposal. The
sequence of proposals should not affect performance significantly.
SBG5500 Series User's Guide
173

Hide quick links:

Advertisement

Table of Contents
loading

This manual is also suitable for:

Sbg5500-b

Table of Contents