
P-661H/HW Series User’s Guide
Chapter 13 VPN Screens
213
NAT Traversal This function is available if the
VPN protocol
is
ESP
.
Select this check box if you want to set up a VPN tunnel when there are NAT
routers between the ZyXEL Device and remote IPSec router. The remote IPSec
router must also enable NAT traversal, and the NAT routers have to forward UDP
port 500 packets to the remote IPSec router behind the NAT router.
Name Type up to 32 characters to identify this VPN policy. You may use any character,
including spaces, but the ZyXEL Device drops trailing spaces.
IPSec Key Mode Select
IKE
or
Manual
from the drop-down list box.
IKE
provides more protection
so it is generally recommended.
Manual
is a useful option for troubleshooting if
you have problems using
IKE
key management.
Negotiation Mode Select
Main
or
Aggressive
from the drop-down list box. Multiple SAs connecting
through a secure gateway must have the same negotiation mode.
Encapsulation
Mode
Select
Tunnel
mode or
Transport
mode from the drop-down list box.
DNS Server (for
IPSec VPN)
If there is a private DNS server that services the VPN, type its IP address here.
The ZyXEL Device assigns this additional DNS server to the ZyXEL Device's
DHCP clients that have IP addresses in this IPSec rule's range of local addresses.
A DNS server allows clients on the VPN to find other computers and servers on
the VPN by their (private) domain names.
Local
Local IP addresses must be static and correspond to the remote IPSec router's
configured remote IP addresses.
Two active SAs can have the same configured local or remote IP address, but not
both. You can configure multiple SAs between the same local and remote IP
addresses, as long as only one is active at any time.
In order to have more than one active rule with the
Secure Gateway Address
field set to
0.0.0.0
, the ranges of the local IP addresses cannot overlap between
rules.
If you configure an active rule with
0.0.0.0
in the
Secure Gateway Address
field
and the LAN’s full IP address range as the local IP address, then you cannot
configure any other active rules with the
Secure Gateway Address
field set to
0.0.0.0
.
Local Address Type Use the drop-down menu to choose
Single
,
Range
, or
Subnet
. Select
Single
for
a single IP address. Select
Range
for a specific range of IP addresses. Select
Subnet
to specify IP addresses on a network by their subnet mask.
IP Address Start When the
Local Address Type
field is configured to
Single
, enter a (static) IP
address on the LAN behind your ZyXEL Device. When the
Local Address Type
field is configured to
Range
, enter the beginning (static) IP address, in a range of
computers on your LAN behind your ZyXEL Device. When the
Local Address
Type
field is configured to
Subnet
, this is a (static) IP address on the LAN behind
your ZyXEL Device.
End / Subnet Mask When the
Local Address Type
field is configured to
Single
, this field is N/A.
When the
Local Address Type
field is configured to
Range
, enter the end (static)
IP address, in a range of computers on the LAN behind your ZyXEL Device. When
the
Local Address Type
field is configured to
Subnet
, this is a subnet mask on
the LAN behind your ZyXEL Device.
Table 84
Edit VPN Policies
LABEL
DESCRIPTION
Summary of Contents for P-661H Series
Page 2: ......
Page 5: ...P 661H HW Series User s Guide Certifications 5...
Page 10: ...P 661H HW Series User s Guide 10 Customer Support...
Page 44: ...P 661H HW Series User s Guide 44 Chapter 1 Getting To Know Your ZyXEL Device...
Page 76: ...P 661H HW Series User s Guide 76 Chapter 3 Wizards...
Page 108: ...P 661H HW Series User s Guide 108 Chapter 5 LAN Setup...
Page 132: ...P 661H HW Series User s Guide 132 Chapter 6 Wireless LAN...
Page 192: ...P 661H HW Series User s Guide 192 Chapter 10 Trend Micro Security Services...
Page 196: ...P 661H HW Series User s Guide 196 Chapter 11 Content Filtering...
Page 202: ...P 661H HW Series User s Guide 202 Chapter 12 Introduction to IPSec...
Page 230: ...P 661H HW Series User s Guide 230 Chapter 13 VPN Screens...
Page 234: ...P 661H HW Series User s Guide 234 Chapter 14 Static Route...
Page 246: ...P 661H HW Series User s Guide 246 Chapter 15 Bandwidth Management...
Page 250: ...P 661H HW Series User s Guide 250 Chapter 16 Dynamic DNS Setup...
Page 280: ...P 661H HW Series User s Guide 280 Chapter 19 System...
Page 290: ...P 661H HW Series User s Guide 290 Chapter 21 Tools...
Page 296: ...P 661H HW Series User s Guide 296 Chapter 23 Troubleshooting...
Page 300: ...P 661H HW Series User s Guide 300 Appendix A...
Page 304: ...P 661H HW Series User s Guide 304 Appendix C...
Page 326: ...P 661H HW Series User s Guide 326 Appendix E...
Page 328: ...P 661H HW Series User s Guide 328 Appendix F...
Page 334: ...P 661H HW Series User s Guide 334 Appendix G...
Page 368: ...P 661H HW Series User s Guide 368 Appendix K...
Page 376: ...P 661H HW Series User s Guide 376 Figure 219 Java Sun...