ZyWALL 10/10 II/50 Internet Security Gateway
VPN/IPSec Setup
26-7
Table 26-3 Menu 27.1 — IPSec Summary
FIELD DESCRIPTION EXAMPLE
Local Addr
End
When the
Addr Type
field in
Menu 27.1.1 IPSec Setup
is configured to
Single
, this is the same (static) IP address as in the
Local Addr Start
field.
When the
Addr Type
field in
Menu 27.1.1 IPSec Setup
is configured to
Range
, this is the end (static) IP address, in a range of computers on the
LAN behind your ZyWALL.
When the
Addr Type
field in
Menu 27.1.1 IPSec Setup
is configured to
SUBNET
, this is a subnet mask on the LAN behind your ZyWALL.
192.168.1.38
Encap
This field displays
Tunnel
mode
or
Transport
mode. See earlier for a
discussion of these. You need to finish configuring the VPN policy in menu
27.1.1.1 or 27.1.1.2 if
???
is displayed.
Tunnel
IPSec
ALgorithm
This field displays the security protocols used for an SA.
ESP
provides
confidentiality and integrity of data by encrypting the data and
encapsulating it into IP packets. Encryption methods include 56-bit
DES
and 168-bit
3DES
.
NULL
denotes a tunnel without encryption.
AH
(Authentication Header) provides strong integrity and authentication
by adding authentication information to IP packets. This authentication
information is calculated using header and payload data in the IP packet.
This provides an additional level of security.
AH
choices are
MD5
(default
- 128 bits) and
SHA -1
(160 bits)
.
Both
AH
and
ESP
increase the ZyWALL’s processing requirements and
communications latency (delay).
You need to finish configuring the VPN policy in menu 27.1.1.1 or 27.1.1.2
if
???
is displayed.
ESP DES MD5
Key Mgt
This field displays the SA’s type of key management, (
IKE
or
Manual
).
IKE
Remote
Addr Start
When the
Addr Type
field in
Menu 27.1.1 IPSec Setup
is configured to
Single
, this is a (static) IP address on the network behind the remote
IPSec router.
When the
Addr Type
field in
Menu 27.1.1 IPSec Setup
is configured to
Range
, this is the beginning (static) IP address, in a range of computers
on the network behind the remote IPSec router.
When the
Addr Type
field in
Menu 27.1.1 IPSec Setup
is configured to
SUBNET
, this is a (static) IP address on the network behind the remote
IPSec router.
This field displays
N/A
when you configure the
Secure Gateway Addr
172.16.2.40
Summary of Contents for ZyWALL 10/10
Page 1: ...ZyWALL 10 10 II 50 Internet Security Gateway User s Guide Version 3 50 June 2002...
Page 32: ......
Page 36: ......
Page 42: ......
Page 58: ......
Page 78: ......
Page 80: ......
Page 92: ......
Page 96: ......
Page 122: ......
Page 140: ......
Page 166: ......
Page 186: ......
Page 206: ......
Page 212: ......
Page 226: ......
Page 244: ......
Page 252: ......
Page 258: ......
Page 260: ......
Page 290: ......
Page 294: ......
Page 300: ......
Page 302: ......
Page 308: ......
Page 314: ......
Page 316: ......
Page 318: ......
Page 322: ......
Page 334: ......
Page 342: ...ZyWALL 10 10 II 50 Internet Security Gateway JJ Index Introduction 10 2...