Virtual Address Mapping; Figure 165 Local And Remote Network Ip Address Overlap - ZyXEL Communications ZYWALL 2 PLUS User Manual

Internet security appliance
Hide thumbs Also See for ZYWALL 2 PLUS:
Table of Contents

Advertisement

Chapter 14 IPSec VPN
14.6.1.1 Overlapping Local And Remote Network IP Addresses
Devices behind the ZyWALL (local devices) and the devices behind the remote IPSec router
(remote devices) may use private IP addresses. Therefore it is possible that local devices and
remote devices may have the same IP addresses. This is known as overlapping local and
remote IP addresses.
For example, local network X uses IP addresses 192.168.1.2 to 192.168.1.4. Remote network
Y uses IP addresses 192.168.1.2 to 192.168.1.27.
If you select the VPN rules skip applying to the overlap range of local and remote IP
addresses option (see
access a network X computer with an IP address from 192.168.1.2 to 192.168.1.4, the
ZyWALL sends the traffic through the VPN tunnel to network Y.
If you clear the VPN rules skip applying to the overlap range of local and remote IP
addresses option (see
access a network X computer with an IP address from 192.168.1.2 to 192.168.1.4, the
ZyWALL sends the traffic to the local network.

Figure 165 Local and Remote Network IP Address Overlap

14.6.2 Virtual Address Mapping

Virtual address mapping (NAT over IPSec) changes the source IP addresses of packets from
your local devices to virtual IP addresses before sending them through the VPN tunnel.
14.6.2.1 Avoiding Overlapping Local And Remote Network IP Addresses
If both IPSec routers support virtual address mapping, you can access devices on both
networks, even if their IP addresses overlap. You map the ZyWALL's local network addresses
to virtual IP addresses and map the remote IPSec router's local IP addresses to other (non-
overlapping) virtual IP addresses.
Take
Section 14.6.1.1 on page 252
addresses. You can set up virtual address mapping on both IPSec routers to allow computers
on network X to access network X and network Y computers with the same IP address.
• You set ZyWALL A to change the source IP addresses of packets from local network X
(192.168.1.2 to 192.168.1.4) to virtual IP addresses 10.0.0.2 to 10.0.0.4 before sending
them through the VPN tunnel.
• You set ZyWALL B to change the source IP addresses of packets from the remote
network Y (192.168.1.2 to 192.168.1.27) to virtual IP addresses 172.21.2.2 to 172.21.2.27
before sending them through the VPN tunnel.
252
Figure 174 on page
267), every time a computer on network X tries to
Figure 174 on page
267), every time a computer on network X tries to
as an example of overlapping local and remote IP
ZyWALL 2 Plus User's Guide

Advertisement

Table of Contents
loading

Table of Contents