Nat Traversal; Figure 13-3 Nat Router Between Ipsec Routers - ZyXEL Communications ZyWALL 5 User Manual

Internet security appliance
Hide thumbs Also See for ZyWALL 5:
Table of Contents

Advertisement

When there is outbound traffic with no inbound traffic, the
ZyWALL automatically drops the tunnel after two minutes.

13.7 NAT Traversal

NAT traversal allows you to set up a VPN connection when there are NAT routers between the two
IPSec routers.
Normally you cannot set up a VPN connection with a NAT router between the two IPSec routers
because the NAT router changes the header of the IPSec packet. In the previous figure, IPSec router A
sends an IPSec packet in an attempt to initiate a VPN. The NAT router changes the IPSec packet's
header so it does not match the header for which IPSec router B is checking. Therefore, IPSec router B
does not respond and the VPN connection cannot be built.
NAT traversal solves the problem by adding a UDP port 500 header to the IPSec packet. The NAT
router forwards the IPSec packet with the UDP port 500 header unchanged. IPSec router B checks the
UDP port 500 header and responds. IPSec routers A and B build a VPN connection.
13.7.1 NAT Traversal Configuration
For NAT traversal to work you must:
Use ESP security protocol (in either transport or tunnel mode).
Use IKE keying mode.
Enable NAT traversal on both IPSec endpoints.
In order for IPSec router A (see the figure) to receive an initiating IPSec packet from IPSec router B,
set the NAT router to forward UDP port 500 to IPSec router A.
13.7.2 X-Auth (Extended Authentication)
Extended authentication provides added security by allowing you to use usernames and passwords for
VPN connections. This is especially helpful when multiple ZyWALLs use one VPN rule to connect to
a single ZyWALL. An attacker cannot make a VPN connection without a valid username and
password.
The extended authentication server checks the user names and passwords of the extended
authentication clients before completing the IPSec connection (see also the Authentication Server
section).
A ZyWALL can be an extended authentication server for some VPN connections and an extended
authentication client for other VPN connections.
VPN Screens

Figure 13-3 NAT Router Between IPSec Routers

ZyWALL 5 Internet Security Appliance
13-5

Hide quick links:

Advertisement

Table of Contents
loading

Table of Contents