P-662HW-D Series Support Notes
Be very careful about the remote IP address in branch office B, because
systems behind branch office B want to access systems behind branch office
A and headquarter, we have to specify these two segments in
Remote
section.
However if we include these two segments in one rule, the LAN segment of
branch office B will be also included in this single rule, which means
intercommunication inside branch office B will run into VPN tunnel. To avoid
such situation, we need two separate rules to cover the LAN segment of
branch office A and headquarter.
•
The first rule in Branch_ B, Branch_B_1.
This rule is for branch office B to access headquarter.
(1)
Local Address Type
is
Range Address
and
IP Address Start
is
192.168.2.0, IP Address End
is
192.168.2.255.
This section covers the LAN
segment of branch office B.
Remote Address Type
is
Range Address
and
IP Address Start
is
192.168.1.0
, IP Address End is
192.168.1.255
. This section covers the LAN
segment of headquarter office.
(2)
My IP Address
is the
WAN IP of Prestige
in
Branch_B
,
202.2.1.1
in the
example.
Secure Gateway Address
is
IP address of Headquarter
,
202.1.1.1
in the
example.
(3) Suppose the pre-shared key is
01234567
, we should configure the same
key in the corresponding rule in Headquarter VPN Gateway.
(4) You can setup IKE phase 1 and phase 2 parameters by pressing
Advanced
button. Please make sure that parameters you set in this menu
match with all the parameters with the corresponding VPN rule in headquarter.
We don’t make any advanced setup in the example.
•
The second rule in Branch_B, Branch_B_2.
This rule is for branch office B to access branch office A.
(1)
Local Address Type
is
Range Address
and
IP Address Start
is
192.168.2.0, IP Address End
is
192.168.2.255.
This section covers the LAN
segment of branch office B.
Remote Address Type
is
Range Address
and
IP Address Start
is
192.168.3.0
, IP Address End is
192.168.3.255
. This section covers the LAN
segment of branch office A.
108
All contents copyright © 2006 ZyXEL Communications Corporation.