ZyXEL Communications ZYWALL USG 2000 Support Notes page 85

Unified security gateway
Hide thumbs Also See for ZYWALL USG 2000:
Table of Contents

Advertisement

Remote Policy: 192.168.0.0/16
ZyWALL35 WAN: 179.25.13.2
Local Policy: 192.168.11.0/24
Remote Policy: 192.168.0.0/16
Negotiation Mode : Main
Pre-share key: 123456789
Encryption :DES
Authentication :MD5
Key Group :DH1
Encapsulation: Tunnel
Active Protocol: ESP
Encryption: DES
Authentication: SHA1
Perfect Forward Secrecy (PFS): None
The next step is to configure the VPN tunnel setting. Following the ZyWALL5 VPN design
logic, we have to define the local and remote policies to force the traffic going through the
VPN tunnel to the remote site. For example, the traffic from ZyWALL5 will be sent to all the
remote sites' devices like ZyWALL35 (LAN subnet: 192.168.11.x), local center's ZyWALL
USG2000 (LAN subnet: 192.168.21.x), remote center's ZyWALL USG2000 (LAN subnet:
192.168.20.x), ZyWALL 2 Plus (LAN subnet: 192.168.21.x) and ZyWALL70 (LAN subnet:
192.168.22.x) by building one VPN tunnel with local center ZyWALL USG2000. Thus a
separate VPN tunnel to each remote site is not needed. We will use a class B subnet
(192.168.0.0/255.255.0.0) as remote policy in order to include all ranges of the remote policies
requirements.
The Local Policy is the local subnet 192.168.12.0/24 and Remote Policy is 192.168.0.0/16
for the tunnel between ZyWALL5 and local center ZyWALL USG2000. Please switch to
menu Security > VPN > Global Setting and activate the "VPN rules skip applying to the
overlap range of local and remote IP addresses" option because the local and remote policies
are in the overlap range in this application. If this feature is not activated, you will fail to
access device because of triggering VPN tunnels.
All contents copyright (c) 2008 ZyXEL Communications Corporation.
Phase 1
Phase2
ZyWALL USG 2000 Support Notes
Remote Policy: 192.168.12.0/16
Local Policy: 192.168.0.0/16
Remote Policy: 192.168.11.0/16
Phase 1
Negotiation Mode : Main
Pre-share key: 123456789
Encryption :DES
Authentication :MD5
Key Group :DH1
Phase2
Encapsulation: Tunnel
Active Protocol: ESP
Encryption: DES
Authentication: SHA1
Perfect Forward Secrecy (PFS): None
85

Advertisement

Table of Contents
loading

Table of Contents