Nat Traversal Configuration; X-Auth (Extended Authentication); Authentication Server; Figure 51 Nat Router Between Ipsec Routers - ZyXEL Communications ZyWall P1 User Manual

Hide thumbs Also See for ZyWall P1:
Table of Contents

Advertisement

ZyWALL P1 User's Guide

Figure 51 NAT Router Between IPSec Routers

Normally you cannot set up a VPN connection with a NAT router between the two IPSec
routers because the NAT router changes the header of the IPSec packet. In the previous figure,
IPSec router A sends an IPSec packet in an attempt to initiate a VPN. The NAT router changes
the IPSec packet's header so it does not match the header for which IPSec router B is
checking. Therefore, IPSec router B does not respond and the VPN connection cannot be built.
NAT traversal solves the problem by adding a UDP port 500 header to the IPSec packet. The
NAT router forwards the IPSec packet with the UDP port 500 header unchanged. IPSec router
B checks the UDP port 500 header and responds. IPSec routers A and B build a VPN
connection.

9.5.1 NAT Traversal Configuration

For NAT traversal to work you must:
• Use ESP security protocol (in either transport or tunnel mode).
• Use IKE keying mode.
• Enable NAT traversal on both IPSec endpoints.
In order for IPSec router A (see
from IPSec router B, set the NAT router to forward UDP port 500 to IPSec router A.

9.5.2 X-Auth (Extended Authentication)

With the Extended authentication feature on a remote IPSec router, added security is provided
allowing you to use usernames and passwords for VPN connections. This is especially helpful
when multiple ZyWALLs use one VPN rule to connect to a single remote IPSec router. An
attacker cannot make a VPN connection without a valid username and password.
The extended authentication server checks the user names and passwords of the extended
authentication clients before completing the IPSec connection .
A remote IPSec router can be an extended authentication server for some VPN connections
and an extended authentication client for other VPN connections.

9.5.3 Authentication Server

A ZyWALL set to be a VPN extended authentication server can use either the username-
password pair to the ZyWALL or an external RADIUS server for VPN authentication.
132
Figure 51 on page
132) to receive an initiating IPSec packet
Chapter 9 VPN Screens

Advertisement

Table of Contents
loading

Table of Contents