Chapter 14 IPSec VPN
ZyWALL 2 Plus User’s Guide
273
In transport mode, the encapsulation depends on the active protocol. With AH, the ZyWALL
includes part of the original IP header when it encapsulates the packet. With ESP, however,
the ZyWALL does not include the IP header when it encapsulates the packet, so it is not
possible to verify the integrity of the source IP address.
14.6.5 IPSec SA Proposal and Perfect Forward Secrecy
An IPSec SA proposal is similar to an IKE SA proposal (see
),
except that you also have the choice whether or not the ZyWALL and remote IPSec router
perform a new DH key exchange every time an IPSec SA is established. This is called Perfect
Forward Secrecy (PFS).
If you enable PFS, the ZyWALL and remote IPSec router perform a DH key exchange every
time an IPSec SA is established, changing the root key from which encryption keys are
generated. As a result, if one encryption key is compromised, other encryption keys remain
secure.
If you do not enable PFS, the ZyWALL and remote IPSec router use the same root key that
was generated when the IKE SA was established to generate encryption keys.
The DH key exchange is time-consuming and may be unnecessary for data that does not
require such security.
14.7 VPN Rules (IKE) Network Policy Edit
Click
SECURITY > VPN
and the add network policy (
) icon or a network policy’s edit
icon in the
VPN Rules (IKE)
screen to display the
VPN-Network Policy -Edit
screen. Use
this screen to configure a network policy. A network policy identifies the devices behind the
IPSec routers at either end of a VPN tunnel and specifies the authentication, encryption and
other settings needed to negotiate a phase 2 IPSec SA.
Summary of Contents for ADSL 2+ Security Gateway
Page 2: ......
Page 25: ...Table of Contents ZyWALL 2 Plus User s Guide 25 Index 679 ...
Page 26: ...Table of Contents ZyWALL 2 Plus User s Guide 26 ...
Page 46: ...46 ...
Page 88: ...Chapter 3 Wizard Setup ZyWALL 2 Plus User s Guide 88 ...
Page 132: ...132 ...
Page 144: ...Chapter 6 LAN Screens ZyWALL 2 Plus User s Guide 144 ...
Page 180: ...Chapter 9 DMZ Screens ZyWALL 2 Plus User s Guide 180 ...
Page 190: ...190 ...
Page 222: ...Chapter 11 Firewall ZyWALL 2 Plus User s Guide 222 ...
Page 252: ...Chapter 13 Content Filtering Reports ZyWALL 2 Plus User s Guide 252 ...
Page 328: ...Chapter 16 Authentication Server ZyWALL 2 Plus User s Guide 328 ...
Page 330: ...330 ...
Page 346: ...Chapter 17 Network Address Translation NAT ZyWALL 2 Plus User s Guide 346 ...
Page 350: ...Chapter 18 Static Route ZyWALL 2 Plus User s Guide 350 ...
Page 398: ...Chapter 21 Remote Management ZyWALL 2 Plus User s Guide 398 ...
Page 416: ...Chapter 24 ALG Screen ZyWALL 2 Plus User s Guide 416 ...
Page 417: ...417 PART V Logs and Maintenance Logs Screens 419 Maintenance 447 ...
Page 418: ...418 ...
Page 423: ...Chapter 25 Logs Screens ZyWALL 2 Plus User s Guide 423 Figure 274 LOGS Log Settings ...
Page 466: ...466 ...
Page 474: ...Chapter 27 Introducing the SMT ZyWALL 2 Plus User s Guide 474 ...
Page 496: ...Chapter 30 LAN Setup ZyWALL 2 Plus User s Guide 496 ...
Page 504: ...Chapter 32 DMZ Setup ZyWALL 2 Plus User s Guide 504 ...
Page 508: ...Chapter 33 Wireless Setup ZyWALL 2 Plus User s Guide 508 ...
Page 556: ...Chapter 38 Filter Configuration ZyWALL 2 Plus User s Guide 556 ...
Page 570: ...Chapter 40 System Information Diagnosis ZyWALL 2 Plus User s Guide 570 ...
Page 586: ...Chapter 41 Firmware and Configuration File Maintenance ZyWALL 2 Plus User s Guide 586 ...
Page 594: ...Chapter 42 System Maintenance Menus 8 to 10 ZyWALL 2 Plus User s Guide 594 ...
Page 598: ...Chapter 43 Remote Management ZyWALL 2 Plus User s Guide 598 ...
Page 604: ...604 ...
Page 612: ...Chapter 45 Troubleshooting ZyWALL 2 Plus User s Guide 612 ...
Page 620: ...620 ...
Page 644: ...Appendix B Pop up Windows JavaScripts and Java Permissions ZyWALL 2 Plus User s Guide 644 ...
Page 668: ...Appendix E Importing Certificates ZyWALL 2 Plus User s Guide 668 ...
Page 672: ...Appendix F Legal Information ZyWALL 2 Plus User s Guide 672 ...
Page 678: ...Appendix G Customer Support ZyWALL 2 Plus User s Guide 678 ...