ZyXEL Communications ZYWALL USG 1000 Support Notes page 58

Internet security appliance
Hide thumbs Also See for ZYWALL USG 1000:
Table of Contents

Advertisement

ZyWALL USG 1000 Support Notes
VPN Connection:
[0] crypto map remoteaccess
[1] ipsec-isakmp remoteaccess
[2] encapsulation tunnel
[3] transform-set esp-des-md5
[4] set security-association lifetime seconds 86400
[5] set pfs none
[6] no policy-enforcement
[7] local-policy subnet2
[8] remote-policy VPNclient
[9] no nail-up
[10] no replay-detection
[11] no netbios-broadcast
[12] no out-snat activate
[13] no in-snat activate
[14] no in-dnat activate
Tips for application:
1. Make sure both pre-shared key settings are the same in local and remote gateway.
2. Make sure both IKE proposal settings are the same in local and remote gateway.
3. Select the correct interface for the VPN connection.
4. The Local and Peer ID type and content must the opposite and not of the same content.
5. The Local Policy of ZyWALL USG should be 'dynamic single host with the value 0.0.0.0'.
The VPN tunnel should be initialed from the remote host site.
58
All contents copyright (c) 2007 ZyXEL Communications Corporation.

Advertisement

Table of Contents
loading

Table of Contents