Ipsec Sa Overview; Local Network And Remote Network - ZyXEL Communications ZYWALL 2 PLUS User Manual

Internet security appliance
Hide thumbs Also See for ZYWALL 2 PLUS:
Table of Contents

Advertisement

Table 65 SECURITY > VPN > VPN Rules (IKE) > Edit Gateway Policy (continued)
LABEL
Associated
Network Policies
#
Name
Local Network
Remote Network
Apply
Cancel

14.6 IPSec SA Overview

Once the ZyWALL and remote IPSec router have established the IKE SA, they can securely
negotiate an IPSec SA through which to send data between computers on the networks.
The IPSec SA stays connected even if the underlying IKE SA is not available
anymore.
This section introduces the key components of an IPSec SA.

14.6.1 Local Network and Remote Network

In an IPSec SA, the local network consists of devices connected to the ZyWALL and may be
called the local policy. Similarly, the remote network consists of the devices connected to the
remote IPSec router and may be called the remote policy.
It is not recommended to set a VPN rule's local and remote network settings
both to 0.0.0.0 (any). This causes the ZyWALL to try to forward all access
attempts (to the local network, the Internet or even the ZyWALL) to the remote
IPSec router. In this case, you can no longer manage the ZyWALL.
If you select the VPN rules skip applying to the overlap range of local and remote IP
addresses option (see
settings are both 0.0.0.0 (any), no traffic will go through the VPN tunnel.
ZyWALL 2 Plus User's Guide
DESCRIPTION
The following table shows the policy(ies) you configure for this rule.
To add a VPN policy, click the add network policy (
(IKE) screen (see
Figure 158 on page
for more information.
This field displays the policy index number.
This field displays the policy name.
This field displays one or a range of IP address(es) of the computer(s) behind the
ZyWALL.
This field displays one or a range of IP address(es) of the remote network behind
the remote IPsec router.
Click Apply to save your changes back to the ZyWALL.
Click Cancel to exit this screen without saving.
Figure 174 on page
267) and the VPN rule's local and remote network
Chapter 14 IPSec VPN
) icon in the VPN Rules
238). Refer to
Section 14.8 on page 259
251

Advertisement

Table of Contents
loading

Table of Contents