Pre-Shared Key; Diffie-Hellman (Dh) Key Groups; Telecommuter Vpn/Ipsec Examples - ZyXEL Communications P-2612HW-F1 User Manual

802.11g wireless adsl voip iad
Hide thumbs Also See for P-2612HW-F1:
Table of Contents

Advertisement

Chapter 14 VPN
The two ZyXEL Devices in this example can complete negotiation and establish a
VPN tunnel.
Table 86 Matching ID Type and Content Configuration Example
ZYXEL DEVICE A
Local ID type: E-mail
Local ID content:
tom@yourcompany.com
Peer ID type: IP
Peer ID content: 1.1.1.2
The two ZyXEL Devices in this example cannot complete their negotiation because
ZyXEL Device B's Local ID type is IP, but ZyXEL Device A's Peer ID type is set
to E-mail. An "ID mismatched" message displays in the IPSEC LOG.
Table 87 Mismatching ID Type and Content Configuration Example
ZYXEL DEVICE A
Local ID type: IP
Local ID content: 1.1.1.10
Peer ID type: E-mail
Peer ID content: aa@yahoo.com

14.9.10 Pre-Shared Key

A pre-shared key identifies a communicating party during a phase 1 IKE
negotiation (see
"pre-shared" because you have to share it with another party before you can
communicate with them over a secure connection.

14.9.11 Diffie-Hellman (DH) Key Groups

Diffie-Hellman (DH) is a public-key cryptography protocol that allows two parties
to establish a shared secret over an unsecured communications channel. Diffie-
Hellman is used within IKE SA setup to establish session keys. 768-bit (Group 1 -
DH1) and 1024-bit (Group 2 – DH2) Diffie-Hellman groups are supported. Upon
completion of the Diffie-Hellman exchange, the two peers have a shared secret,
but the IKE SA is not authenticated. For authentication, use pre-shared keys.

14.9.12 Telecommuter VPN/IPSec Examples

The following examples show how multiple telecommuters can make VPN
connections to a single ZyXEL Device at headquarters. The telecommuters use
IPSec routers with dynamic WAN IP addresses. The ZyXEL Device at headquarters
has a static public IP address.
288
ZYXEL DEVICE B
Local ID type: IP
Local ID content: 1.1.1.10
Peer ID type: IP
Peer ID content: N/A
Section 14.9.5 on page 284
ZYXEL DEVICE B
Local ID type: IP
Local ID content: 1.1.1.2
Peer ID type: E-mail
Peer ID content: tom@yourcompany.com
for more on IKE phases). It is called
P-2612HW-F1 User's Guide

Advertisement

Table of Contents
loading

Table of Contents