
Chapter 14 VPN Screens
P-2802H(W)(L)-I Series User’s Guide
190
NAT is not normally compatible with ESP in transport mode either, but the ZyXEL Device’s
NAT Traversal
feature provides a way to handle this. NAT traversal allows you to set up an
IKE SA when there are NAT routers between the two IPSec routers.
Figure 108
NAT Router Between IPSec Routers
Normally you cannot set up an IKE SA with a NAT router between the two IPSec routers
because the NAT router changes the header of the IPSec packet. NAT traversal solves the
problem by adding a UDP port 500 header to the IPSec packet. The NAT router forwards the
IPSec packet with the UDP port 500 header unchanged. In
, when
IPSec router A tries to establish an IKE SA, IPSec router B checks the UDP port 500 header,
and IPSec routers A and B build the IKE SA.
For NAT traversal to work, you must:
• Use ESP security protocol (in either transport or tunnel mode).
• Use IKE keying mode.
• Enable NAT traversal on both IPSec endpoints.
• Set the NAT router to forward UDP port 500 to IPSec router A.
Finally, NAT is compatible with ESP in tunnel mode because integrity checks are performed
over the combination of the "original header plus original payload," which is unchanged by a
NAT device. The compatibility of AH and ESP with NAT in tunnel and transport modes is
summarized in the following table.
Y* - This is supported in the ZyXEL Device if you enable NAT traversal.
14.8 Remote DNS Server
In cases where you want to use domain names to access Intranet servers on a remote network
that has a DNS server, you must identify that DNS server. You cannot use DNS servers on the
LAN or from the ISP since these DNS servers cannot resolve domain names to private IP
addresses on the remote network
Table 72
VPN and NAT
SECURITY PROTOCOL
MODE
NAT
AH
Transport
N
AH
Tunnel
N
ESP
Transport
Y*
ESP
Tunnel
Y
Summary of Contents for P-2802H-I Series
Page 1: ...www zyxel com P 2802H W L I Series VDSL VoIP IAD User s Guide Version 3 70 6 2007 Edition 1...
Page 2: ......
Page 7: ...Safety Warnings P 2802H W L I Series User s Guide 7...
Page 8: ...Safety Warnings P 2802H W L I Series User s Guide 8...
Page 10: ...Contents Overview P 2802H W L I Series User s Guide 10...
Page 32: ...List of Tables P 2802H W L I Series User s Guide 32...
Page 33: ...33 PART I Introduction Introducing the ZyXEL Device 35 Introducing the Web Configurator 43...
Page 34: ...34...
Page 50: ...Chapter 2 Introducing the Web Configurator P 2802H W L I Series User s Guide 50...
Page 51: ...51 PART II Wizard Internet and Wireless Setup Wizard 53 VoIP Wizard And Example 65...
Page 52: ...52...
Page 64: ...Chapter 3 Internet and Wireless Setup Wizard P 2802H W L I Series User s Guide 64...
Page 70: ...Chapter 4 VoIP Wizard And Example P 2802H W L I Series User s Guide 70...
Page 72: ...72...
Page 82: ...Chapter 5 Status Screens P 2802H W L I Series User s Guide 82...
Page 88: ...Chapter 6 WAN Setup P 2802H W L I Series User s Guide 88...
Page 116: ...Chapter 8 Wireless LAN P 2802H W L I Series User s Guide 116...
Page 154: ...Chapter 10 Voice P 2802H W L I Series User s Guide 154...
Page 174: ...Chapter 11 Firewalls P 2802H W L I Series User s Guide 174...
Page 178: ...Chapter 12 Content Filtering P 2802H W L I Series User s Guide 178...
Page 184: ...Chapter 13 Introduction to IPSec P 2802H W L I Series User s Guide 184...
Page 238: ...Chapter 16 Static Route P 2802H W L I Series User s Guide 238...
Page 250: ...Chapter 17 Quality of Service QoS P 2802H W L I Series User s Guide 250...
Page 254: ...Chapter 18 Dynamic DNS Setup P 2802H W L I Series User s Guide 254...
Page 282: ...Chapter 20 Universal Plug and Play UPnP P 2802H W L I Series User s Guide 282...
Page 284: ...284...
Page 324: ...Chapter 25 Troubleshooting P 2802H W L I Series User s Guide 324...
Page 334: ...Chapter 26 Product Specifications P 2802H W L I Series User s Guide 334...
Page 336: ...336...
Page 348: ...Appendix A Setting up Your Computer s IP Address P 2802H W L I Series User s Guide 348...
Page 404: ...Appendix G Legal Information P 2802H W L I Series User s Guide 404...
Page 410: ...Appendix H Customer Support P 2802H W L I Series User s Guide 410...