background image

 

 
 

 

 

VPN Configuration Guide 

Zyxel  

USG Series, USG Flex Series,​

 ​

ZyWALL VPN Firewalls, ZyWALL ATP Firewalls

 

 

 

 

Summary of Contents for USG Flex Series

Page 1: ...VPN Configuration Guide Zyxel USG Series USG Flex Series ZyWALL VPN Firewalls ZyWALL ATP Firewalls ...

Page 2: ...arks of their respective companies equinux shall have absolutely no liability for any direct or indirect special or other consequential damages in connection with the use of this document or any change to the router in general including without limitation any lost profits business or data even if equinux has been advised of the possibility of such damages Every effort has been made to ensure that ...

Page 3: ...nfiguration Checklist Task 1 VPN Gateway Configuration Task 2 VPN Tracker Configuration Step 1 Add a Connection Step 2 Configure the VPN Connection Task Three Testing the VPN connection Connect to your VPN Troubleshooting Technical Support 2 ...

Page 4: ...rs to make it easier to reference it later You can print this checklist to help keep track of the various settings of your ZyWALL USG VPN gateway device IP Addresses 1 WAN IP Address or hostname 2 LAN internal IP Address Subnet Mask User Authentication XAUTH 3 Username _______________________________ 4 Password _______________________________ Pre Shared Key 5 Pre Shared Key _______________________...

Page 5: ...way through its web configuration interface Go to the CONFIGURATION tab to access the device s settings Go to Network Interface and switch to the Ethernet tab Write down the IP address of the primary WAN network interface here wan1 as 1 on your Configuration Checklist If your device has a DNS hostname fixed or DynDNS write it down instead Write down the IP address of the LAN network interface here...

Page 6: ...rd Enter a password for this new user Make sure to remember the password or write it down as 4 then click OK to add the user To add more users simply repeat this step You might want to connect the device to an existing LDAP or RADIUS authentication server later remember to select the appropriate user type for the external authentication server in the User Type pop up We recommend using a local use...

Page 7: ...ation Method Go to Object Auth Method and click the Add button Name Enter a name for the new authentication method here vpn_auth Click the Add button and choose local from the pop up Click OK to save the authentication method 6 ...

Page 8: ... Click the Add button Click the Show Advanced Settings button to be able to access all settings General Settings Select the Enable checkbox to enable the VPN gateway settings that you are about to configure VPN Gateway Name Enter a name for the phase 1 setup here vpn_tracker 7 ...

Page 9: ...hared Key here topsecret Make sure to choose a good pre shared key and remember it or write it down as 5 Local ID Type Make sure IP is selected Content Leave the default of 0 0 0 0 This means that the IP address entered for My Address will automatically be used as the device s identifier Peer ID Type Make sure Any is selected This means that connecting VPN clients can use any identifier type 8 ...

Page 10: ...ES and SHA 1 with the option of using AES 128 and SHA 1 as shown here Key Group Choose DH2 from the pop up Select the NAT Traversal checkbox Make sure the Dead Peer Detection DPD checkbox is selected It is possible to use different phase 1 settings Please note that any changes you make here must be matched in VPN Tracker Advanced Phase 1 We recommend using the settings shown here for initial setup...

Page 11: ...eckbox Server Mode Choose vpn_auth from the pop up If you do not see the vpn_auth entry here you may have skipped Step 3 Create an Authentication Method Click OK to complete the phase 1 setup The result should look similar to what is shown in the following screenshot 10 ...

Page 12: ... click the Add button Click the Show Advanced Settings button to be able to access all settings General Settings Select the Enable checkbox to enable the VPN connection settings that you are about to configure Connection Name Enter a name for the phase 2 setup here vpn_tracker 11 ...

Page 13: ... from the pop up Policy Local policy Choose the address object corresponding to the network s VPN clients are permitted to access Here LAN1_SUBNET i e the ZyWALL s LAN network 2 is being used This selection will be appropriate in most cases Select the checkbox Policy Enforcement to restrict VPN client access to the network s chosen under Local Policy 12 ...

Page 14: ...anging the default proposal settings to use at least 3DES and SHA 1 with the option of using AES 128 and SHA 1 as shown here Perfect Forward Secrecy PFS Choose DH2 from the pop up It is possible to use different phase 2 settings Please note that any changes you make here must be matched in VPN Tracker Advanced Phase 2 We recommend using the settings shown here for initial setup and testing 13 ...

Page 15: ... will apply to this VPN connection Some devices may not have this option in that case please add the connection manually to Network Zone It is not necessary to make any changes to the Connectivity Check and Inbound Outbound traffic NAT settings Click OK to complete the phase 2 setup The result should look similar to what is shown in the following screenshot 14 ...

Page 16: ...nnection there are a few settings that need to be customized to match what is configured on your VPN gateway VPN Gateway Enter the WAN IP address or hostname of your VPN gateway that you wrote down as 1 Local Address Leave empty for now Depending on your setup you may have to set a specific local address later Refer to Supporting Multiple Users on when and how to set a specific local address Remot...

Page 17: ...n IMPORTANT If you are using VPN Tracker for the first time with your current Internet connection it will test your connection Wait for the test to complete Depending on your setup You will be prompted to enter your XAUTH username 3 and password 4 and your pre shared key 5 To save time for the future check the box Store in Keychain to save the password in your keychain so you are not asked for it ...

Page 18: ...found at http www vpntracker com support Technical Support If you re stuck the technical support team at equinux is here to help Contact us via http www vpntracker com support Please include the following information with any request for support A description of the problem and any troubleshooting steps that you have already taken A VPN Tracker Technical Support Report Log Technical Support Report...

Reviews: