Table 20 Vpn Advanced Wizard: Step 4 - ZyXEL Communications ZyWALL USG 300 User Manual

Unified security gateway
Hide thumbs Also See for ZyWALL USG 300:
Table of Contents

Advertisement

Table 20 VPN Advanced Wizard: Step 4 (continued)
LABEL
SA Life Time
(Seconds)
Perfect Forward
Secret (PFS)
Policy Setting
Local Policy (IP/
Mask)
Incoming Interface
Remote Policy (IP/
Mask)
Property
Nailed-Up
Back
Next
This read-only screen shows the status of the current VPN setting. Use the summary table to
check whether what you have configured is correct.
ZyWALL USG 300 User's Guide
DESCRIPTION
Define the length of time before an IKE SA automatically renegotiates in this
field. The minimum value is 60 seconds.
A short SA Life Time increases security by forcing the two VPN gateways to
update the encryption and authentication keys. However, every time the VPN
tunnel renegotiates, all users accessing remote resources are temporarily
disconnected.
Perfect Forward Secret (PFS) is disabled (None) by default in phase 2 IPSec
SA setup. This allows faster IPSec setup, but is not so secure.
Select DH1, DH2 or DH5 to enable PFS. DH1 refers to Diffie-Hellman Group 1 a
768 bit random number. DH2 refers to Diffie-Hellman Group 2 a 1024 bit (1Kb)
random number. DH5 refers to Diffie-Hellman Group 5 a 1536 bit random
number (more secure, yet slower).
Type a static local IP address that corresponds to the remote IPSec router's
configured remote IP address.
To specify IP addresses on a network by their subnet mask, type the subnet
mask of the LAN behind your ZyWALL.
Select an interface from the drop-down list box to have packets encrypted by
the remote IPSec router to enter the ZyWALL via this interface.
If Any displays in this field, it is not configurable for the chosen scenario.
If this field is configurable, type a static local IP address that corresponds to the
remote IPSec router's configured local IP address.
To specify IP addresses on a network by their subnet mask, type the subnet
mask of the LAN behind the remote gateway.
This displays for the site-to-site and remote access client role scenarios. Select
this to have the ZyWALL automatically renegotiate the IPSec SA when the SA
life time expires.
Click Back to return to the previous screen.
Click Next to continue.
Chapter 4 Wizard Setup
103

Advertisement

Table of Contents
loading

Table of Contents