ZyXEL Communications ZYWALL USG 1000 Support Notes page 21

Internet security appliance
Hide thumbs Also See for ZYWALL USG 1000:
Table of Contents

Advertisement

3) Login to ZyWALL70 and go to Security > VPN > Gateway Policy, add a new gateway
policy to connect with central office's ZyWALL USG. My Address and Remote Gateway
Address are ZyWALL70 and ZyWALL USG WAN IP addresses. The Pre-Shared Key
configured on both sides must exactly the same Local ID Type & content and Peer ID
Type & content are reverse to the Local ZyWALL USG.
4) The IKE Proposal is very important setting when configuring the VPN tunnel. The
proposal includes Negotiation Mode, Encryption and Authentication Algorithm and....
Make sure the IKE proposal parameters are must the same on both ends.
5) Switch to Configuration > Network > IPSec VPN > VPN Connection, add a new VPN
connection (IPSec phase2). Setup the Phase2 proposal and local and remote policies. The
chosen phase2 proposal chosen must be the same as on the remote site's ZyWALL70.
6) In ZyWALL70, VPN is a rule based VPN. This means that whether the traffic is going to
the tunnel or not will depend on the local and remote policies. In this example,
All contents copyright (c) 2007 ZyXEL Communications Corporation.
ZyWALL USG 1000 Support Notes
21

Advertisement

Table of Contents
loading

Table of Contents