Nat Traversal; Nat Traversal Configuration; Id Type And Content - ZyXEL Communications VANTAGE CNM User Manual

Centralized network management
Hide thumbs Also See for VANTAGE CNM:
Table of Contents

Advertisement

If the ZyXEL device has its maximum number of simultaneous IPSec tunnels connected to it
and they all have keep alive enabled, then no other tunnels can take a turn connecting to the
ZyXEL device because the ZyXEL device never drops the tunnels that are already connected.

11.1.12 NAT Traversal

NAT traversal allows you to set up a VPN connection when there are NAT routers between
end IPSec VPN tunnel devices.
Normally you cannot set up a VPN connection with a NAT router between the two IPSec
routers because the NAT router changes the header of the IPSec packet. In the previous figure,
IPSec router A sends an IPSec packet in an attempt to initiate a VPN. The NAT router changes
the IPSec packet's header so it does not match the header for which IPSec router B is
checking. Therefore, IPSec router B does not respond and the VPN connection cannot be built.
NAT traversal solves the problem by adding a UDP port 500 header to the IPSec packet. The
NAT router forwards the IPSec packet with the UDP port 500 header unchanged. IPSec router
B checks the UDP port 500 header and responds. IPSec routers A and B build a VPN
connection.

11.1.12.1 NAT Traversal Configuration

For NAT traversal to work you must:
• Use ESP security protocol (in either transport or tunnel mode).
• Use IKE keying mode.
• Enable NAT traversal on both IPSec endpoints.

11.1.13 ID Type and Content

With aggressive negotiation mode, the ZyXEL device identifies incoming SAs by ID type and
content since this identifying information is not encrypted. This enables the ZyXEL device to
distinguish between multiple rules for SAs that connect from remote IPSec routers that have
dynamic WAN IP addresses. Telecommuters can use separate passwords to simultaneously
connect to the ZyXEL device from IPSec routers with dynamic IP addresses.
Chapter 11 Configuration > VPN
Note: When there is outbound traffic with no inbound traffic, the
ZyXEL device automatically drops the tunnel after two minutes.
Note: Regardless of the ID type and content configuration, the
ZyXEL device does not allow you to save multiple active rules
with overlapping local and remote IP addresses.
Vantage CNM User's Guide
156

Advertisement

Table of Contents
loading

Table of Contents