How Do I Configure P-662Hw-D With Nat For Internal Servers; I Am Planning My P-662Hw-D Behind A Nat Router. What Do I Need To Know; How Can I Keep A Tunnel Alive - ZyXEL Communications P-662HW-D Series Support Notes

802.11g wireless adsl2+ 4-port security gateway
Hide thumbs Also See for P-662HW-D Series:
Table of Contents

Advertisement

VPN client/gateway behind
*
NAT
NAT in Transport mode
* The NAT router must support IPSec pass through. For example, for
P-662HW-D SUA/NAT routers, the default port and the client IP have to be
specified in Web Configurator, Network -> NAT ->SUA Server Setup.

11. How do I configure P-662HW-D with NAT for internal servers?

Generally, without IPSec, to configure an internal server for outside access, we
need to configure the server private IP and its service port in SUA/NAT Server
Table.
However, if both NAT and IPSec is enabled in P-662HW-D, the edit of the
table is necessary only if the connection is a non-secure connection. For
secure connections, none SUA server settings are required since private IP is
reachable in the VPN case.
12. I am planning my P-662HW-D behind a NAT router. What do I need to
know?
Suppose: host----P-662HW-D----NAT Router----Internet----Secure host
Some tips for the configuration:
(1) The NAT router must support to pass through IPSec protocol. Only ESP
tunnel mode is possible to work in NAT case. Default port (UDP Port 500) and
the P-662HW-D's WAN IP must be configured in NAT Router's SUA/NAT
Server Table.
(2) On the Secure host side, WAN IP of the NAT router is the tunneling
endpoint for this case, not the WAN IP of P-662HW-D.
For example:
On P-662HW-D: My IP Address= P-662HW-D's WAN IP
Secure Gateway IP Address= Secure host's IP
On Secure host: My IP Address= Secure host's IP
Secure Gateway IP Address= NAT Router's WAN IP

13. How can I keep a tunnel alive?

To keep a tunnel alive, you can check "keep alive" option when configuring
your VPN tunnel. With this option, whenever phase 2 SA lifetime is due, IKE
negotiation procedure will be invoked automatically even without traffic to
make the connection stay.
But to reduce the consumption of system resource, if VPN tunnels get
All contents copyright © 2006 ZyXEL Communications Corporation.
P-662HW-D Series Support Notes
ESP tunnel mode
None
37

Advertisement

Table of Contents
loading

Table of Contents