Vpn Connection Screens; Vpn Connection Summary - ZyXEL Communications ZyWALL 1050 User Manual

Hide thumbs Also See for ZyWALL 1050:
Table of Contents

Advertisement

• In a VPN gateway, you can select an Ethernet interface, virtual Ethernet interface, VLAN
interface, or virtual VLAN interface to specify what address the ZyWALL uses IP
address when it establishes the IKE SA. You should set up the interface first. See
10 on page
• In a VPN gateway, you can enable extended authentication. If the ZyWALL runs in
server mode, you should set up the authentication method (AAA server) first. The
authentication method specifies how the ZyWALL authenticates the remote IPSec router.
See
Chapter 32 on page
• In a VPN gateway, the ZyWALL and remote IPSec router can use certificates to
authenticate each other. You should import the certificate first. See
469.
You should set up the following features before the network can use the VPN tunnel.
• The ZyWALL does not put IPSec SA in the routing table. You must create a policy route
for the VPN tunnel. See
• Make sure the to-ZyWALL firewall rules allow IPSec VPN traffic to the ZyWALL. IKE
uses UDP port 500, AH uses IP protocol 51, and ESP uses IP protocol 50.
• The ZyWALL supports UDP port 500 and UDP port 4500 for NAT traversal. If you
enable this, make sure the to-ZyWALL firewall rules allow UDP port 4500 too.
• Make sure regular firewall rules allow traffic between the VPN tunnel and the rest of the
network. Regular firewall rules check packets the ZyWALL sends before the ZyWALL
encrypts them and check packets the ZyWALL receives after the ZyWALL decrypts
them. This depends on the zone to which you assign the VPN tunnel and the zone from
which and to which traffic may be routed.
• If you set up a VPN tunnel across the Internet, make sure your ISP supports AH or ESP.
If there are problems setting up a VPN tunnel, make sure both the ZyWALL and remote IPSec
router have the same settings for the VPN tunnel. It is also helpful to have a way to look at the
packets that are being sent and received by the ZyWALL and remote IPSec router (for
example, packet sniffers).

12.3 VPN Connection Screens

You use the VPN Connection summary screen to look at the VPN connections you have set
up, and you use the VPN Connection Add/Edit Manual Key and VPN Connection Add/
Edit Gateway screens to create or to edit VPN connections.

12.3.1 VPN Connection Summary

The VPN Connection summary screen displays the list of VPN connections, the associated
VPN gateway(s), and various settings. In addition, it also lets you activate / deactivate and
connect / disconnect each VPN connection (each IPSec SA).
To access this screen, click Configuration > Network > IPSec VPN. The following screen
appears.
Chapter 12 IPSec VPN
177.
465.
Chapter 18 on page
ZyWALL 1050 User's Guide
Chapter 33 on page
291.
Chapter
229

Advertisement

Table of Contents
loading

Table of Contents