Figure 363 Menu 27.1.1: Ipsec Setup; Table 208 Menu 27.1.1: Ipsec Setup - ZyXEL Communications ZyWall 35 User Manual

Internet security appliance
Hide thumbs Also See for ZyWall 35:
Table of Contents

Advertisement

Figure 363 Menu 27.1.1: IPSec Setup

Index= 1
Active= Yes
Local ID type = IP
My Addr Type= IP
Peer ID type= IP
Secure Gateway Address= zwtest.zyxel.com.tw
Protocol= 0
Local:
Remote:
Enable Replay Detection = No
Key Management= IKE
Edit Key Management Setup= No
The following table describes the fields in this screen.

Table 208 Menu 27.1.1: IPSec Setup

FIELD
Index
Name
Active
Keep Alive
NAT
Traversal
Chapter 44 VPN/IPSec Setup
Menu 27.1.1 - IPSec Setup
Name= Taiwan
Keep Alive= No
DNS Server= 0.0.0.0
Addr Type= RANGE
IP Addr Start= 192.168.1.35
Port Start= 0
Addr Type= SUBNET
IP Addr Start= 4.4.4.4
Port Start= 0
Press ENTER to Confirm or ESC to Cancel:
Note: You must also configure menu 27.1.1.1 or menu 27.1.1.2
to fully configure and use a VPN.
DESCRIPTION
This is the VPN rule index number you selected in the previous menu.
Enter a unique identification name for this VPN rule. The name may be up to 32
characters long but only 10 characters will be displayed in Menu 27.1 - IPSec
Summary.
Press [SPACE BAR] to choose either Yes or No. Choose Yes and press [ENTER] to
activate the VPN tunnel. This field determines whether a VPN rule is applied before a
packet leaves the firewall.
Press [SPACE BAR] to choose either Yes or No. Choose Yes and press [ENTER] to
have the ZyWALL automatically re-initiate the SA after the SA lifetime times out, even if
there is no traffic. The remote IPSec router must also have keep alive enabled in order
for this feature to work.
Choose Yes and press [ENTER] to enable NAT traversal. NAT traversal allows you to
set up a VPN connection when there are NAT routers between the two IPSec routers.
The remote IPSec router must also have NAT traversal enabled. You can use NAT
traversal with ESP protocol using Transport or Tunnel mode, but not with AH protocol
nor with Manual key management.
In order for an IPSec router behind a NAT router to receive an initiating IPSec packet,
set the NAT router to forward UDP port 500 to the IPSec router behind the NAT router.
NAT Traversal= No
Content:
Address= 0.0.0.0
Content:
192.168.1.38
255.255.0.0
ZyWALL 35 User's Guide
End/Subnet Mask=
End= N/A
End/Subnet Mask=
End= N/A
563

Advertisement

Table of Contents
loading

This manual is also suitable for:

Zywall 70

Table of Contents