K12. What Are Local Id And Peer Id - ZyXEL Communications ZyWall 35 Support Notes

Zyxel zywall 35: user guide
Hide thumbs Also See for ZyWall 35:
Table of Contents

Advertisement

ZyWALL 35 Support Notes
What are the differences between IKE and manual key VPN?
The only difference between IKE and manual key is how the encryption keys and SPIs are determined.
For IKE VPN, the key and SPIs are negotiated from one VPN gateway to the other. Afterward, two VPN
gateways use this negotiated keys and SPIs to send packets between two networks.
For manual key VPN, the encryption key, authentication key (if needed), and SPIs are predetermined by
the administrator when configuring the security association.
IKE is more secure than manual key, because IKE negotiation can generate new keys and SPIs randomly
for the VPN connection.
K11. What is Phase 1 ID for?
In IKE phase 1 negotiation, IP address of remote peer is treated as an indicator to decide which VPN rule
must be used to serve the incoming request. However, in some application, remote VPN box or client
software is using an IP address dynamically assigned from ISP, so ZyWALL needs additional information
to make the decision. Such additional information is what we call phase 1 ID. In the IKE payload, there
are local and peer ID field to achieve this.

K12. What are Local ID and Peer ID?

Local ID and Peer ID are used in IKE phase 1 negotiation. It's in FQDN(Fully Qualified Domain Name)
format, IKE standard takes it as one type of Phase 1 ID.
Phase 1 ID is identification for each VPN peer. The type of Phase 1 ID may be IP/FQDN (DNS)/User
FQDN (E-mail). The content of Phase 1 ID depends on the Phase 1 ID type. The following is an example
for how to configure phase 1 ID.
ID type Content
------------------------------------
IP 202.132.154.1
DNS www.zyxel.com
E-mail support@zyxel.com.tw
Please note that, in ZyWALL, if "DNS" or "E-mail" type is chosen, you can still use a random string as
the content, such as "this_is_zywall". It's not neccessary to follow the format exactly.
By default, ZyWALL takes IP as phase 1 ID type for itself and it's remote peer. But if its remote peer is
using DNS or E-mail, you have to adjust the settings to pass phase 1 ID checking.
When should I use FQDN?
If your VPN connection is ZyWALL to ZyWALL, and both of them have static IP address, and there is no
321
All contents copyright (c) 2006 ZyXEL Communications Corporation.

Advertisement

Table of Contents
loading

Table of Contents