ZyXEL Communications Vantage CNM 2.0 User Manual page 129

Centralized network management
Hide thumbs Also See for Vantage CNM 2.0:
Table of Contents

Advertisement

FIELD
Active Protocol
Enable Replay Detection
Keep Alive
A-End/Z-End
NAT Traversal (Only
Available in ZyWALL)
A-End/Z-End Device
My IP
Peer IP
ID Type
Configuration > VPN
Table 11-6 Configuration > VPN > Tunnel IPSec Detail
The ESP and AH protocols are necessary to create a Security Association (SA), the
foundation of an IPSec VPN.
AH protocol (RFC 2402) was designed for integrity, authentication, sequence
integrity (replay resistance), and non-repudiation but not for confidentiality, for which
the ESP was designed.
The ESP protocol (RFC 2406) provides encryption as well as some of the services
offered by AH. ESP authenticating properties are limited compared to the AH due to
the non-inclusion of the IP header information during the authentication process.
When you initiate an IPSec tunnel with keep alive enabled, the ZyXEL device
automatically renegotiates the tunnel when the IPSec SA lifetime period expires. In
effect, the IPSec tunnel becomes an "always on" connection after you initiate it. Both
IPSec routers must have a ZyXEL device-compatible keep alive feature enabled in
order for this feature to work.
If the ZyXEL device has its maximum number of simultaneous IPSec tunnels
connected to it and they all have keep alive enabled, then no other tunnels can take
a turn connecting to the ZyXEL device because the ZyXEL
Select this check box to enable NAT traversal. NAT traversal allows you to set up a
VPN connection when there are NAT routers between the two IPSec routers.
The remote IPSec router must also have NAT traversal enabled.
You can use NAT traversal with ESP protocol using Transport or Tunnel mode, but
not with AH protocol nor with manual key management. In order for an IPSec router
behind a NAT router to receive an initiating IPSec packet, set the NAT router to
forward UDP port 500 to the IPSec router behind the NAT router.
Select the name of the ZyXEL device from the pull-down list.
This is the IP address of the local and remote computer(s) of the VPN tunnel.
Type the IP address of the computer with which you will make the VPN connection
or leave the field blank to have the ZyXEL device automatically use the address in
the Secure Gateway field.
Select IP to identify this ZyXEL device by its IP address.
Select DNS to identify this ZyXEL device by a domain name.
Select E-mail to identify this ZyXEL device by an e-mail address.
You do not configure the local ID type and content when you set Authentication
Method to Certificate. The ZyXEL device takes them from the certificate you select.
DESCRIPTION
Vantage CNM 2.0
11-9

Advertisement

Table of Contents
loading

Table of Contents