Chapter 4 Wizard Setup
There are two phases to every IKE (Internet Key Exchange) negotiation – phase 1
(Authentication) and phase 2 (Key Exchange). A phase 1 exchange establishes an IKE SA
(Security Association).
Figure 39 VPN Advanced Wizard: Step 3
The following table describes the labels in this screen.
Table 19 VPN Advanced Wizard: Step 3
LABEL
Phase 1
Setting
Secure
Gateway
My Address
(interface)
Negotiation
Mode
100
DESCRIPTION
If Any displays in this field, it is not configurable for the chosen scenario.
If this field is configurable, enter the WAN IP address or domain name of the remote
IPSec router (secure gateway) in the field below to identify the remote IPSec router
by its IP address or a domain name. Set this field to 0.0.0.0 if the remote IPSec
router has a dynamic WAN IP address.
Select an interface from the drop-down list box to use on your ZyWALL.
Select Main for identity protection. Select Aggressive to allow more incoming
connections from dynamic IP addresses to use separate passwords.
Note: Multiple SAs (security associations) connecting through a
secure gateway must have the same negotiation mode.
ZyWALL USG 300 User's Guide