Chapter 16 VPN
P-661HNU-Fx User’s Guide
237
The two ZyXEL Devices in this example can complete negotiation and establish a
VPN tunnel.
The two ZyXEL Devices in this example cannot complete their negotiation because
ZyXEL Device B’s Local ID type is IP, but ZyXEL Device A’s Peer ID type is set
to E-mail. An “ID mismatched” message displays in the IPSEC LOG.
16.6.9 Pre-Shared Key
A pre-shared key identifies a communicating party during a phase 1 IKE
negotiation (see
for more on IKE phases). It is called
“pre-shared” because you have to share it with another party before you can
communicate with them over a secure connection.
16.6.10 Diffie-Hellman (DH) Key Groups
Diffie-Hellman (DH) is a public-key cryptography protocol that allows two parties
to establish a shared secret over an unsecured communications channel. Diffie-
Hellman is used within IKE SA setup to establish session keys. 768-bit (Group 1 -
DH1) and 1024-bit (Group 2 – DH2) Diffie-Hellman groups are supported. Upon
completion of the Diffie-Hellman exchange, the two peers have a shared secret,
but the IKE SA is not authenticated. For authentication, use pre-shared keys.
16.6.11 Telecommuter VPN/IPSec Examples
The following examples show how multiple telecommuters can make VPN
connections to a single ZyXEL Device at headquarters. The telecommuters use
IPSec routers with dynamic WAN IP addresses. The ZyXEL Device at headquarters
has a static public IP address.
Table 65
Matching ID Type and Content Configuration Example
ZYXEL DEVICE A
ZYXEL DEVICE B
Local ID type: E-mail
Local ID type: IP
Local ID content:
[email protected]
Local ID content: 1.1.1.2
Peer ID type: IP
Peer ID type: E-mail
Peer ID content: 1.1.1.2
Peer ID content: [email protected]
Table 66
Mismatching ID Type and Content Configuration Example
ZYXEL DEVICE A
ZYXEL DEVICE B
Local ID type: IP
Local ID type: IP
Local ID content: 1.1.1.10
Local ID content: 1.1.1.10
Peer ID type: E-mail
Peer ID type: IP
Peer ID content: [email protected]
Peer ID content: N/A
Summary of Contents for P-661H-61
Page 2: ......
Page 8: ...Safety Warnings P 661HNU Fx User s Guide 8...
Page 10: ...Contents Overview P 661HNU Fx User s Guide 10...
Page 18: ...Table of Contents P 661HNU Fx User s Guide 18 Appendix G Legal Information 393 Index 1...
Page 19: ...19 PART I User s Guide...
Page 20: ...20...
Page 28: ...Chapter 1 Introduction P 661HNU Fx User s Guide 28...
Page 36: ...Chapter 2 Introducing the Web Configurator P 661HNU Fx User s Guide 36...
Page 79: ...79 PART II Technical Reference...
Page 80: ...80...
Page 86: ...Chapter 4 Connection Status and System Info Screens P 661HNU Fx User s Guide 86...
Page 140: ...Chapter 6 Wireless P 661HNU Fx User s Guide 140...
Page 172: ...Chapter 8 Routing P 661HNU Fx User s Guide 172...
Page 176: ...Chapter 9 DNS Route P 661HNU Fx User s Guide 176...
Page 260: ...Chapter 24 Backup Restore P 661HNU Fx User s Guide 260...
Page 281: ...Chapter 27 Product Specifications P 661HNU Fx User s Guide 281...
Page 282: ...Chapter 27 Product Specifications P 661HNU Fx User s Guide 282...
Page 334: ...Appendix C Pop up Windows Java Script and Java Permissions P 661HNU Fx User s Guide 334...
Page 358: ...Appendix D Wireless LANs P 661HNU Fx User s Guide 358...
Page 392: ...Appendix F Open Software Announcements P 661HNU Fx User s Guide 392...
Page 403: ...Index P 661HNU Fx User s Guide 403...
Page 404: ...Index P 661HNU Fx User s Guide 404...