K14. How Do I Configure Zywall Vpn - ZyXEL Communications ZyWALL 5 Support Notes

Hide thumbs Also See for ZyWALL 5:
Table of Contents

Advertisement

ZyWALL 5 Support Notes

K14. How do I configure ZyWALL VPN?

You can configure ZyWALL for VPN via web GUI. ZyWALL 1 supports Web only.
K15. What VPN protocols are supported by ZyWALL?
All ZyWALL series support ESP (protocol number 50) and AH (protocol number 51).
K16. What types of encryption does ZyWALL VPN support?
ZyWALL supports 56-bit DES and 168-bit 3DES.
K17. What types of authentication does ZyWALL VPN support?
VPN vendors support a number of different authentication methods. ZyWALL VPN supports both SHA1
and MD5.
AH provides authentication, integrity, and replay protection (but not confidentiality). Its main difference
with ESP is that AH also secures parts of the IP header of the packet (like the source/destination
addresses), but ESP does not.
ESP can provide authentication, integrity, replay protection, and confidentiality of the data (it secures
everything in the packet that follows the header). Replay protection requires authentication and integrity
(these two go always together). Confidentiality
(encryption) can be used with or without authentication/integrity. Similarly, one could use
authentication/integrity with or without confidentiality.
K18. I am planning my ZyWALL-to-ZyWALL VPN configuration. What do I need to know?
First of all, both ZyWALL must have VPN capabilities. Please check the firmware version, V3.50 or later
has the VPN capability. If your ZyWALL is capable of VPN, you can find the VPN options in
Advanced>VPN tab.
For configuring a 'box-to-box VPN', there are some tips:
If there is a NAT router running in the front of ZyWALL, please make sure the NAT router supports to
pass through IPSec.
In NAT case (either run on the frond end router, or in ZyWALL VPN box), only IPSec ESP tunneling
mode is supported since NAT against AH mode.
Source IP/Destination IP-- Please do not number the LANs (local and remote) using the same exact
range of private IP addresses. This will make VPN destination addresses and the local LAN addresses are
292
All contents copyright (c) 2006 ZyXEL Communications Corporation.

Advertisement

Table of Contents
loading

Table of Contents