What You Need To Know; The Setup Screen - ZyXEL Communications SBG3500-N000 User Manual

Wireless n fiber wan small business gateway
Hide thumbs Also See for SBG3500-N000:
Table of Contents

Advertisement

20.3 What You Need To Know

A VPN tunnel is usually established in two phases. Each phase establishes a security association
(SA), a contract indicating what security parameters the SBG3500-N and the remote IPSec router
will use.
The first phase establishes an Internet Key Exchange (IKE) SA between the SBG3500-N and remote
IPSec router. The second phase uses the IKE SA to securely establish an IPSec SA through which
the SBG3500-N and remote IPSec router can send data between computers on the local network
and remote network. The following figure illustrates this.
Figure 116 VPN: IKE SA and IPSec SA
Network A
N
ETWORK
In this example, a computer in network A is exchanging data with a computer in network B. Inside
networks A and B, the data is transmitted the same way data is normally transmitted in the
networks. Between routers X and Y, the data is protected by tunneling, encryption, authentication,
and other security features of the IPSec SA. The IPSec SA is established securely using the IKE SA
that routers X and Y established first.

20.4 The Setup Screen

The following figure helps explain the main fields in the web configurator.
Figure 117 IPSec Fields Summary
Local Network
Local IP Address
Local and remote IP addresses must be static.
SBG3500-N000 User's Guide
IPSec SA
X
IKE SA
VPN Tunnel
Network B
Y
Remote Network
Remote
IPSec Router
Remote IP Address
Chapter 20 IPSec VPN
257

Advertisement

Table of Contents
loading

Table of Contents