![ZyXEL Communications P-661H-D Series Support Notes Download Page 36](http://html1.mh-extra.com/html/zyxel-communications/p-661h-d-series/p-661h-d-series_support-notes_944131036.webp)
P-661H-D Series Support Notes
NAT
*
NAT in Transport mode
None
* The NAT router must support IPSec pass through. For example, for
P-661H-D SUA/NAT routers, the default port and the client IP have to be
specified in Web Configurator,
Network -> NAT ->SUA Server Setup.
11. How do I configure P-661H-D with NAT for internal servers?
Generally, without IPSec, to configure an internal server for outside access, we
need to configure the server private IP and its service port in SUA/NAT Server
Table.
However, if both NAT and IPSec is enabled in P-661H-D, the edit of the table
is necessary only if the connection is a non-secure connection. For secure
connections, none SUA server settings are required since private IP is
reachable in the VPN case.
12. I am planning my P-661H-D behind a NAT router. What do I need to
know?
Suppose: host----P-661H-D----NAT Router----Internet----Secure host
Some tips for the configuration:
(1) The NAT router must support to pass through IPSec protocol. Only ESP
tunnel mode is possible to work in NAT case. Default port (UDP Port 500) and
the P-661H-D’s WAN IP must be configured in NAT Router’s SUA/NAT Server
Table.
(2) On the Secure host side, WAN IP of the NAT router is the tunneling
endpoint for this case, not the WAN IP of P-661H-D.
For example:
On P-661H-D: My IP Address= P-661H-D’s WAN IP
Secure Gateway IP Address= Secure host’s IP
On Secure host: My IP Address= Secure host’s IP
Secure Gateway IP Address= NAT Router’s WAN IP
13. How can I keep a tunnel alive?
To keep a tunnel alive, you can check "
keep alive
" option when configuring
your VPN tunnel. With this option, whenever phase 2 SA lifetime is due, IKE
negotiation procedure will be invoked automatically even without traffic to
make the connection stay.
But to reduce the consumption of system resource, if VPN tunnels get
35
All contents copyright © 2006 ZyXEL Communications Corporation.