Id Type And Content - ZyXEL Communications SBG3500-N000 User Manual

Wireless n fiber wan small business gateway
Hide thumbs Also See for SBG3500-N000:
Table of Contents

Advertisement

Table 94 VPN and NAT
SECURITY PROTOCOL
ESP
ESP
Y* - This is supported in the SBG3500-N if you enable NAT traversal.

20.7.7 ID Type and Content

With aggressive negotiation mode (see
incoming SAs by ID type and content since this identifying information is not encrypted. This
enables the SBG3500-N to distinguish between multiple rules for SAs that connect from remote
IPSec routers that have dynamic WAN IP addresses.
Regardless of the ID type and content configuration, the SBG3500-N does not allow you to save
multiple active rules with overlapping local and remote IP addresses.
With main mode (see
provide identity protection. In this case the SBG3500-N can only distinguish between different
incoming SAs that connect from remote IPSec routers that have dynamic WAN IP addresses. The
SBG3500-N can distinguish incoming SAs because you can select between three encryption
algorithms (DES, 3DES and AES), two authentication algorithms (MD5 and SHA1) and eight key
groups when you configure a VPN rule (see
as an extra level of identification for incoming SAs.
The type of ID can be a domain name, an IP address or an e-mail address. The content is the IP
address, domain name, or e-mail address.
Table 95 Local ID Type and Content Fields
LOCAL ID TYPE= CONTENT=
IP
FQDN
User-FQDN
20.7.7.1 ID Type and Content Examples
Two IPSec routers must have matching ID type and content configuration in order to set up a VPN
tunnel.
The two SBG3500-Ns in this example can complete negotiation and establish a VPN tunnel.
Table 96 Matching ID Type and Content Configuration Example
SBG3500-N A
Local ID type: User-FQDN
Local ID content: tom@yourcompany.com
Remote ID type: IP
Remote ID content: 1.1.1.2
SBG3500-N000 User's Guide
MODE
NAT
Transport
Y*
Tunnel
Y
Section 20.7.4 on page
Section 20.7.4 on page
Type the IP address of your computer.
Type a domain name (up to 31 characters) by which to identify this SBG3500-N.
Type an e-mail address (up to 31 characters) by which to identify this SBG3500-
N.
The domain name or e-mail address that you use in the Local ID Content field
is used for identification purposes only and does not need to be a real domain
name or e-mail address.
271), the SBG3500-N identifies
271), the ID type and content are encrypted to
Section 20.4 on page
257). The ID type and content act
SBG3500-N B
Local ID type: IP
Local ID content: 1.1.1.2
Remote ID type: E-mail
Remote ID content: tom@yourcompany.com
Chapter 20 IPSec VPN
273

Advertisement

Table of Contents
loading

Table of Contents