Chapter 9 Interfaces
ZyWALL ATP Series User’s Guide
282
9.9 VTI
IPSec VPN Tunnel Interface (VTI) encrypts or decrypts IPv4 traffic from or to the interface according to
the IP routing table.
VTI allows static routes to send traffic over the VPN. The IPSec tunnel endpoint is associated with an
actual (virtual) interface. Therefore many interface capabilities such as Policy Route, Static Route, Trunk,
and BWM can be applied to the IPSec tunnel as soon as the tunnel is active
IPSec VTI simplifies network management and load balancing. Create a trunk using VPN tunnel
interfaces for load balancing. In the following example configure VPN tunnels with static IP addresses or
DNS on both Zyxel Devices (or IPSec routers at the end of the tunnel). Also configure VTI and a trunk on
both Zyxel Devices.
Figure 194
VTI and Trunk for VPN Load Balancing
Add
Click
Add
to create an
IPv4 Address
, an
IPv4 CIDR
(for example, 192.168.1.1/24) or an
IPv4
Range
(for example, 192.168.1.2-192.168.1.100) as the target IP address. The Zyxel Device
answers external ARP requests only if they match one of these inputted target IP addresses.
For example, if the
IPv4 Address
is 192.168.1.5, then the Zyxel Device will answer ARP
requests coming from the WAN only if it contains 192.168.1.5 as the target IP address.
Select an existing entry and click
Remove
to delete that entry.
Related Setting
Configure WAN
TRUNK
Click
WAN TRUNK
to go to a screen where you can configure the interface as part of a
WAN trunk for load balancing.
Configure Policy
Route
Click
Policy Route
to go to the screen where you can manually configure a policy route to
associate traffic with this bridge interface.
OK
Click
OK
to save your changes back to the Zyxel Device.
Cancel
Click
Cancel
to exit this screen without saving.
Table 110 Configuration > Network > Interface > Bridge > Add / Edit (continued)
LABEL
DESCRIPTION