Virtual Address Mapping; Figure 136 Local And Remote Network Ip Address Overlap - ZyXEL Communications ZYWALL P1 User Manual

Internet security appliance
Hide thumbs Also See for ZYWALL P1:
Table of Contents

Advertisement

It is not recommended to set a VPN rule's local and remote network settings
both to 0.0.0.0 (any). This causes the ZyWALL to try to forward all access
attempts (to the local network, the Internet or even the ZyWALL) to the remote
IPSec router. In this case, you can no longer manage the ZyWALL.
If you select the VPN rules skip applying to the overlap range of local and remote IP
addresses option (see
network settings are both 0.0.0.0 (any), no traffic will go through the VPN tunnel.
13.6.1.1 Overlapping Local And Remote Network IP Addresses
Devices behind the ZyWALL (local devices) and the devices behind the remote IPSec router
(remote devices) may use private IP addresses. Therefore it is possible that local devices and
remote devices may have the same IP addresses. This is known as overlapping local and
remote IP addresses.
For example, local network X uses IP addresses 192.168.1.2 to 192.168.1.4. Remote network
Y uses IP addresses 192.168.1.2 to 192.168.1.27.
If you select the VPN rules skip applying to the overlap range of local and remote IP
addresses option (see
to access a network X computer with an IP address from 192.168.1.2 to 192.168.1.4, the
ZyWALL sends the traffic through the VPN tunnel to network Y.
If you clear the VPN rules skip applying to the overlap range of local and remote IP
addresses option (see
to access a network X computer with an IP address from 192.168.1.2 to 192.168.1.4, the
ZyWALL sends the traffic to the local network.

Figure 136 Local and Remote Network IP Address Overlap

13.6.2 Virtual Address Mapping

Virtual address mapping (NAT over IPSec) changes the source IP addresses of packets from
your local devices to virtual IP addresses before sending them through the VPN tunnel.
ZyWALL P1 User's Guide
Section 13.13 on page
234) and the VPN rule's local and remote
Section 13.13 on page
234), every time a computer on network X tries
Section 13.13 on page
234), every time a computer on network X tries
Chapter 13 IPSec VPN
219

Hide quick links:

Advertisement

Table of Contents
loading

Table of Contents