Telecommuters Sharing One Vpn Rule Example; Telecommuters Using Unique Vpn Rules Example; Figure 222 Telecommuters Sharing One Vpn Rule Example; Table 110 Telecommuters Sharing One Vpn Rule Example - ZyXEL Communications ZYWALL 35 User Manual

Internet security appliance
Hide thumbs Also See for ZYWALL 35:
Table of Contents

Advertisement

18.15.1 Telecommuters Sharing One VPN Rule Example

See the following figure and table for an example configuration that allows multiple
telecommuters (A, B and C in the figure) to use one VPN rule to simultaneously access a
ZyWALL at headquarters (HQ in the figure). The telecommuters do not have domain names
mapped to the WAN IP addresses of their IPSec routers. The telecommuters must all use the
same IPSec parameters but the local IP addresses (or ranges of addresses) should not overlap.

Figure 222 Telecommuters Sharing One VPN Rule Example

Table 110 Telecommuters Sharing One VPN Rule Example

FIELDS
My ZyWALL:
Remote Gateway
Address:
Local Network - Single
IP Address:
Remote Network -
Single IP Address:

18.15.2 Telecommuters Using Unique VPN Rules Example

In this example the telecommuters (A, B and C in the figure) use IPSec routers with domain
names that are mapped to their dynamic WAN IP addresses (use Dynamic DNS to do this).
With aggressive negotiation mode (see
the ID types and contents to distinguish between VPN rules. Telecommuters can each use a
separate VPN rule to simultaneously access a ZyWALL at headquarters. They can use
different IPSec parameters. The local IP addresses (or ranges of addresses) of the rules
configured on the ZyWALL at headquarters can overlap. The local IP addresses of the rules
configured on the telecommuters' IPSec routers should not overlap.
ZyWALL 5/35/70 Series User's Guide
TELECOMMUTERS
0.0.0.0 (dynamic IP address
assigned by the ISP)
Public static IP address
Telecommuter A: 192.168.2.12
Telecommuter B: 192.168.3.2
Telecommuter C: 192.168.4.15
192.168.1.10
Section 18.3.1.4 on page
Chapter 18 IPSec VPN
HEADQUARTERS
Public static IP address
0.0.0.0 With this setting only the
telecommuter can initiate the IPSec
tunnel.
192.168.1.10
Not Applicable
359), the ZyWALL can use
389

Hide quick links:

Advertisement

Table of Contents
loading

Table of Contents