ZyXEL Communications ZYWALL USG 1000 Support Notes page 98

Internet security appliance
Hide thumbs Also See for ZYWALL USG 1000:
Table of Contents

Advertisement

Remote Policy: 192.168.0.0/16
ZyWALL35 WAN: 179.25.13.2
Local Policy: 192.168.11.0/24
Remote Policy: 192.168.0.0/16
Negotiation Mode : Main
Pre-share key: 123456789
Encryption :DES
Authentication :MD5
Key Group :DH1
Encapsulation: Tunnel
Active Protocol: ESP
Encryption: DES
Authentication: SHA1
Perfect Forward Secrecy (PFS): None
The next step is to configure the VPN tunnel setting. Following the ZyWALL5 VPN design
logic, we have to define the local and remote policies to force the traffic going through the
VPN tunnel to the remote site. For example, the traffic from ZyWALL5 will be sent to all the
remote sites' devices like ZyWALL35 (LAN subnet: 192.168.11.x), local center's ZyWALL
USG (LAN subnet: 192.168.21.x), remote center's ZyWALL USG (LAN subnet:
192.168.20.x), ZyWALL 2 Plus (LAN subnet: 192.168.21.x) and ZyWALL70 (LAN subnet:
192.168.22.x) by building one VPN tunnel with local center ZyWALL USG. Thus a separate
VPN tunnel to each remote site is not needed. We will use a class B subnet
(192.168.0.0/255.255.0.0) as remote policy in order to include all ranges of the remote policies
requirements.
The Local Policy is the local subnet 192.168.12.0/24 and Remote Policy is 192.168.0.0/16
for the tunnel between ZyWALL5 and local center ZyWALL USG. Please switch to menu
Security > VPN > Global Setting and activate the "VPN rules skip applying to the overlap
range of local and remote IP addresses" option because the local and remote policies are in the
overlap range in this application. If this feature is not activated, you will fail to access device
because of triggering VPN tunnels.
All contents copyright (c) 2007 ZyXEL Communications Corporation.
Phase 1
Phase2
ZyWALL USG 1000 Support Notes
Remote Policy: 192.168.12.0/16
Local Policy: 192.168.0.0/16
Remote Policy: 192.168.11.0/16
Phase 1
Negotiation Mode : Main
Pre-share key: 123456789
Encryption :DES
Authentication :MD5
Key Group :DH1
Phase2
Encapsulation: Tunnel
Active Protocol: ESP
Encryption: DES
Authentication: SHA1
Perfect Forward Secrecy (PFS): None
98

Advertisement

Table of Contents
loading

Table of Contents