ZyXEL Communications ZyWALL 10W User Manual page 241

Internet security gateway
Hide thumbs Also See for ZyWALL 10W:
Table of Contents

Advertisement

LABEL
Content
VPN Screens
Table 15-7 VPN IKE
Peer ID
Peer ID Content when you set Authentication Method to Pre-Shared
Type
Key.
IP
Type the IP address of the computer with which you will make the VPN
connection. If you configure this field to 0.0.0.0 or leave it blank, the
ZyWALL will use the address in the Secure Gateway Address field.
DNS or
Type a domain name or e-mail address by which to identify the remote
E-Mail
IPSec router. Use up to 31 ASCII characters including spaces,
although trailing spaces are truncated. The domain name or e-mail
address is for identification purposes only and can be any string.
It is recommended that you type an IP address other than 0.0.0.0 or use the DNS or
E-mail Peer ID Type with the following situations:
There is a NAT router between the two IPSec routers.
You want the ZyWALL to distinguish between VPN connection requests
coming in from remote IPSec routers with dynamic WAN IP addresses.
Peer ID
Peer ID Content when you set Authentication Method to Certificate.
Type
IP
Type the same IP address as the subject alternative name field of the
certificate the remote IPSec router will use for this VPN connection. If
you configure this field as 0.0.0.0 or leave it blank, the ZyWALL uses
the address in the Secure Gateway Address field. The ZyWALL
checks the peer ID content against the IP address in the subject
alternative name field of the remote IPSec router's certificate that it
uses for this VPN connection.
DNS or
Type the dame domain name or e-mail address as the subject
E-Mail
alternative name field of the certificate the remote IPSec router will use
for this VPN connection.
Subject
Type the subject name of the certificate the remote IPSec router will
Name
use for this VPN connection.
Any
The peer Content field is not available.
With Pre-Shared Key or Certificate, if you use IP as the peer ID type and configure
the content as 0.0.0.0 (or blank) and the Secure Gateway Address is also
configured as 0.0.0.0, the ZyWALL does not check the peer's ID content.
Regardless of how you configure the ID Type and Content fields, active rules cannot
have overlapping local and remote IP address ranges.
ZyWALL Series Internet Security Gateway
DESCRIPTION
15-17

Advertisement

Table of Contents
loading

This manual is also suitable for:

Zywall 30wZywall 50Zywall 100

Table of Contents