How To Configure A Hub-And-Spoke Ipsec Vpn Without A Vpn Concentrator - ZyXEL Communications ZYWALL USG 1000 - EDITION 2 Manual

Unified security gateway
Hide thumbs Also See for ZYWALL USG 1000 - EDITION 2:
Table of Contents

Advertisement

7.5 How to Configure a Hub-and-spoke IPSec
VPN Without a VPN Concentrator
A hub-and-spoke IPSec VPN connects IPSec VPN tunnels to form one secure
network. This reduces the number of VPN connections that you have to set up and
maintain in the network. Here is an example of a hub-and-spoke VPN that does
not use the ZyWALL's VPN concentrator feature. Here branch office A has a
ZyNOS-based ZyWALL and headquarters (HQ) and branch office B have USG
ZyWALLs or ZyWALL 1050s.
• Branch office A's ZyWALL uses one VPN rule to access both the headquarters
(HQ) network and branch office B's network.
• Branch office B's ZyWALL uses one VPN rule to access both the headquarters
and branch office A's networks.
Figure 76 Hub-and-spoke VPN Example
This hub-and-spoke VPN example uses the following settings.
Branch Office A (ZyNOS-based ZyWALL):
Gateway Policy (Phase 1)
• My Address: 10.0.0.2
• Primary Remote Gateway: 10.0.0.1
Network Policy (Phase 2)
• Local Network: 192.168.167.0/255.255.255.0
• Remote Network: 192.168.168.0~192.168.169.255
Headquarters (USG ZyWALL or ZyWALL 1050):
VPN Gateway (VPN Tunnel 1):
ZyWALL USG 1000 User's Guide
Chapter 7 Tutorials
129

Advertisement

Table of Contents
loading

This manual is also suitable for:

Zywall 1050

Table of Contents