What Are Local Id And Peer Id - ZyXEL Communications P-2608HWL-D1 Support Notes

P-2608hwl series
Hide thumbs Also See for P-2608HWL-D1:
Table of Contents

Advertisement

For IKE VPN, the key and SPIs are negotiated from one VPN gateway to the other. After that, the
two VPN gateways use this negotiated keys and SPIs to send packets between the two networks.
For manual key VPN, the encryption key, authentication key (if needed), and SPIs are
predetermined by the administrator when configuring the security association.
IKE is more secure than manual key, because IKE negotiation can generate new keys and SPIs randomly
for the VPN connection.
What is the use of a Phase 1 ID?
In IKE phase 1 negotiation, the IP address of the remote peer determines which VPN rule must be used to
serve the incoming request. However, in some applications, the remote VPN gateway or client software is
using an IP address that is dynamically assigned from an ISP, so the Prestige needs additional information
to make the decision. Such additional information is what we call phase 1 ID. In IKE payload, there are
local and peer ID fields are used for this purpose.

What are Local ID and Peer ID?

Local ID and Peer ID are used in IKE phase 1 negotiation. It's in FQDN(Fully Qualified Domain Name)
format and the IKE standard uses it as a Phase 1 ID type.
Phase 1 ID is an identification for each VPN device on both ends. The type of a Phase 1 ID may be IP,
FQDN(DNS) or Users FQDN(E-mail). The content of Phase 1 ID depends on the Phase 1 ID type. The
following is an example for how to configure a phase 1 ID.
ID type Content
------------------------------------
IP 202.132.154.1
DNS www.zyxel.com
E-mail support@zyxel.com.tw
Please note that in the Prestige, if the "DNS" or "E-mail" type is chosen, you can still enter any character
as the content, for example "this_is_Prestige". You don't have to enter the content in the exact format.
By default, the Prestige and the remote device use IP as the phase 1 ID type. However, if the remote peer
uses DNS or E-mail ID type, you must also set the Prestige to use the same ID type.
All contents copyright (c) 2005 ZyXEL Communications Corporation.
P-2608HWL Series Support Notes
171

Advertisement

Table of Contents
loading

This manual is also suitable for:

P-2608hwl-d3

Table of Contents