ZyXEL Communications ZYWALL USG 1000 Support Notes page 144

Internet security appliance
Hide thumbs Also See for ZYWALL USG 1000:
Table of Contents

Advertisement

[2] encapsulation tunnel
[3] transform-set esp-des-sha
[4] set security-association lifetime seconds 86400
[5] set pfs none
[6] no policy-enforcement
[7] local-policy Local_192_168_1
[8] remote-policy Remote_ANY
[9] no nail-up
[10] no replay-detection
[11] no netbios-broadcast
[12] no out-snat activate
[13] in-snat activate
[14] in-snat source Remote_192_168_3 destination Local_192_168_1
snat Local_192_168_31
[15] no in-dnat activate
(3) Add a policy route
1.
Go to GUI menu Configuration > Policy > Route > Policy Route tab
2.
By default, there is one policy route already to indicate all packets which is sent from
LAN to any network will be passed through WAN_TRUNK. This is also to direct IKE
packet to WAN and trigger the VPN tunnel then.
3.
Click the '+' icon to add another policy route which indicates where all the traffic which
wants to go to the ZyWALL USG-A's LAN network will be routed to.
4.
Define that all the traffic that wants to go to 192.168.1.0 network will be routed by the
gateway, the host of 192.168.2.254. The configuration is as shown below.
All contents copyright (c) 2007 ZyXEL Communications Corporation.
ZyWALL USG 1000 Support Notes
144

Advertisement

Table of Contents
loading

Table of Contents