Chapter 14 IPSec VPN
ZyWALL 2 Plus User’s Guide
261
Step 2: The remote IPSec router selects an acceptable proposal and sends it back to the
ZyWALL. It also finishes the Diffie-Hellman key exchange, authenticates the ZyWALL, and
sends its (unencrypted) identity to the ZyWALL for authentication.
Step 3: The ZyWALL authenticates the remote IPSec router and confirms that the IKE SA is
established.
Aggressive mode does not provide as much security as main mode because the identity of the
ZyWALL and the identity of the remote IPSec router are not encrypted. It is usually used
when the address of the initiator is not known by the responder and both parties want to use
pre-shared keys for authentication (for example, telecommuters).
14.3.1.5 VPN, NAT, and NAT Traversal
In the following example, there is another router (
A
) between router
X
and router
Y
.
Figure 176
VPN/NAT Example
If router
A
does NAT, it might change the IP addresses, port numbers, or both. If router
X
and
router
Y
try to establish a VPN tunnel, the authentication fails because it depends on this
information. The routers cannot establish a VPN tunnel.
Most routers like router
A
now have an IPSec pass-through feature. This feature helps router
A
recognize VPN packets and route them appropriately. If router
A
has this feature, router
X
and
router
Y
can establish a VPN tunnel as long as the active protocol is ESP. (See
for more information about active protocols.)
If router A does not have an IPSec pass-through or if the active protocol is AH, you can solve
this problem by enabling NAT traversal. In NAT traversal, router
X
and router
Y
add an extra
header to the IKE SA and IPSec SA packets. If you configure router
A
to forward these
packets unchanged, router
X
and router
Y
can establish a VPN tunnel.
You have to do the following things to set up NAT traversal.
• Enable NAT traversal on the ZyWALL and remote IPSec router.
• Configure the NAT router to forward packets with the extra header unchanged. (See the
field description for detailed information about the extra header.)
The extra header may be UDP port 500 or UDP port 4500, depending on the standard(s) the
ZyWALL and remote IPSec router support.
14.4 Additional IPSec VPN Topics
This section discusses other IPSec VPN topics that apply to either IKE SAs or IPSec SAs or
both. Relationships between the topics are also highlighted.
Summary of Contents for ADSL 2+ Security Gateway
Page 2: ......
Page 25: ...Table of Contents ZyWALL 2 Plus User s Guide 25 Index 679 ...
Page 26: ...Table of Contents ZyWALL 2 Plus User s Guide 26 ...
Page 46: ...46 ...
Page 88: ...Chapter 3 Wizard Setup ZyWALL 2 Plus User s Guide 88 ...
Page 132: ...132 ...
Page 144: ...Chapter 6 LAN Screens ZyWALL 2 Plus User s Guide 144 ...
Page 180: ...Chapter 9 DMZ Screens ZyWALL 2 Plus User s Guide 180 ...
Page 190: ...190 ...
Page 222: ...Chapter 11 Firewall ZyWALL 2 Plus User s Guide 222 ...
Page 252: ...Chapter 13 Content Filtering Reports ZyWALL 2 Plus User s Guide 252 ...
Page 328: ...Chapter 16 Authentication Server ZyWALL 2 Plus User s Guide 328 ...
Page 330: ...330 ...
Page 346: ...Chapter 17 Network Address Translation NAT ZyWALL 2 Plus User s Guide 346 ...
Page 350: ...Chapter 18 Static Route ZyWALL 2 Plus User s Guide 350 ...
Page 398: ...Chapter 21 Remote Management ZyWALL 2 Plus User s Guide 398 ...
Page 416: ...Chapter 24 ALG Screen ZyWALL 2 Plus User s Guide 416 ...
Page 417: ...417 PART V Logs and Maintenance Logs Screens 419 Maintenance 447 ...
Page 418: ...418 ...
Page 423: ...Chapter 25 Logs Screens ZyWALL 2 Plus User s Guide 423 Figure 274 LOGS Log Settings ...
Page 466: ...466 ...
Page 474: ...Chapter 27 Introducing the SMT ZyWALL 2 Plus User s Guide 474 ...
Page 496: ...Chapter 30 LAN Setup ZyWALL 2 Plus User s Guide 496 ...
Page 504: ...Chapter 32 DMZ Setup ZyWALL 2 Plus User s Guide 504 ...
Page 508: ...Chapter 33 Wireless Setup ZyWALL 2 Plus User s Guide 508 ...
Page 556: ...Chapter 38 Filter Configuration ZyWALL 2 Plus User s Guide 556 ...
Page 570: ...Chapter 40 System Information Diagnosis ZyWALL 2 Plus User s Guide 570 ...
Page 586: ...Chapter 41 Firmware and Configuration File Maintenance ZyWALL 2 Plus User s Guide 586 ...
Page 594: ...Chapter 42 System Maintenance Menus 8 to 10 ZyWALL 2 Plus User s Guide 594 ...
Page 598: ...Chapter 43 Remote Management ZyWALL 2 Plus User s Guide 598 ...
Page 604: ...604 ...
Page 612: ...Chapter 45 Troubleshooting ZyWALL 2 Plus User s Guide 612 ...
Page 620: ...620 ...
Page 644: ...Appendix B Pop up Windows JavaScripts and Java Permissions ZyWALL 2 Plus User s Guide 644 ...
Page 668: ...Appendix E Importing Certificates ZyWALL 2 Plus User s Guide 668 ...
Page 672: ...Appendix F Legal Information ZyWALL 2 Plus User s Guide 672 ...
Page 678: ...Appendix G Customer Support ZyWALL 2 Plus User s Guide 678 ...