
Chapter 20 IPSec VPN
ZyWALL 110/310/1100 Series User’s Guide
290
Authentication
Select which hash algorithm to use to authenticate packet data in the IPSec SA.
Choices are SHA1, SHA256, SHA512 and MD5. SHA is generally considered
stronger than MD5, but it is also slower.
The ZyWALL and the remote IPSec router must both have a proposal that uses the
same authentication algorithm.
Perfect Forward
Secrecy (PFS)
Select whether or not you want to enable Perfect Forward Secrecy (PFS) and, if you
do, which Diffie-Hellman key group to use for encryption. Choices are:
none - disable PFS
DH1 - enable PFS and use a 768-bit random number
DH2 - enable PFS and use a 1024-bit random number
DH5 - enable PFS and use a 1536-bit random number
PFS changes the root key that is used to generate encryption keys for each IPSec SA.
The longer the key, the more secure the encryption, but also the longer it takes to
encrypt and decrypt information. Both routers must use the same DH key group.
Related Settings
Zone
Select the security zone into which to add this VPN connection policy. Any security
rules or settings configured for the selected zone apply to this VPN connection policy.
Connectivity Check
The ZyWALL can regularly check the VPN connection to the gateway you specified to
make sure it is still available.
Enable
Connectivity Check
Select this to turn on the VPN connection check.
Check Method
Select how the ZyWALL checks the connection. The peer must be configured to
respond to the method you select.
Select icmp to have the ZyWALL regularly ping the address you specify to make sure
traffic can still go through the connection. You may need to configure the peer to
respond to pings.
Select tcp to have the ZyWALL regularly perform a TCP handshake with the address
you specify to make sure traffic can still go through the connection. You may need to
configure the peer to accept the TCP connection.
Check Port
This field displays when you set the Check Method to tcp. Specify the port number
to use for a TCP connectivity check.
Check Period
Enter the number of seconds between connection check attempts.
Check Timeout
Enter the number of seconds to wait for a response before the attempt is a failure.
Check Fail
Tolerance
Enter the number of consecutive failures allowed before the ZyWALL disconnects the
VPN tunnel. The ZyWALL resumes using the first peer gateway address when the VPN
connection passes the connectivity check.
Check this Address Select this to specify a domain name or IP address for the connectivity check. Enter
that domain name or IP address in the field next to it.
Check the First
and Last IP
Address in the
Remote Policy
Select this to have the ZyWALL check the connection to the first and last IP addresses
in the connection’s remote policy. Make sure one of these is the peer gateway’s LAN
IP address.
Log
Select this to have the ZyWALL generate a log every time it checks this VPN
connection.
Inbound/Outbound
traffic NAT
Outbound Traffic
Table 107
Configuration > VPN > IPSec VPN > VPN Connection > Edit (continued)
LABEL
DESCRIPTION
Summary of Contents for ZyWALL 110 Series
Page 16: ...ZyWALL 110 310 1100 Series User s Guide 16...
Page 32: ...Chapter 1 Introduction ZyWALL 110 310 1100 Series User s Guide 32...
Page 42: ...Chapter 3 Hardware Introduction ZyWALL 110 310 1100 Series User s Guide 42...
Page 68: ...Chapter 4 Quick Setup Wizards ZyWALL 110 310 1100 Series User s Guide 68...
Page 176: ...Chapter 7 Interfaces ZyWALL 110 310 1100 Series User s Guide 176...
Page 186: ...Chapter 8 Trunk ZyWALL 110 310 1100 Series User s Guide 186...
Page 210: ...Chapter 10 Routing Protocols ZyWALL 110 310 1100 Series User s Guide 210...
Page 220: ...Chapter 12 DDNS ZyWALL 110 310 1100 Series User s Guide 220...
Page 228: ...Chapter 13 NAT ZyWALL 110 310 1100 Series User s Guide 228...
Page 240: ...Chapter 15 ALG ZyWALL 110 310 1100 Series User s Guide 240...
Page 246: ...Chapter 16 IP MAC Binding ZyWALL 110 310 1100 Series User s Guide 246...
Page 263: ...Chapter 18 Authentication Policy ZyWALL 110 310 1100 Series User s Guide 263...
Page 264: ...Chapter 18 Authentication Policy ZyWALL 110 310 1100 Series User s Guide 264...
Page 316: ...Chapter 20 IPSec VPN ZyWALL 110 310 1100 Series User s Guide 316...
Page 340: ...Chapter 22 SSL User Screens ZyWALL 110 310 1100 Series User s Guide 340...
Page 442: ...Chapter 36 DHCPv6 ZyWALL 110 310 1100 Series User s Guide 442...
Page 540: ...Appendix A Legal Information ZyWALL 110 310 1100 Series User s Guide 540...
Page 558: ...Index ZyWALL 110 310 1100 Series User s Guide 558...
Page 559: ...Index ZyWALL 110 310 1100 Series User s Guide 559...
Page 560: ...Index ZyWALL 110 310 1100 Series User s Guide 560...
Page 561: ...Index ZyWALL 110 310 1100 Series User s Guide 561...
Page 562: ...Index ZyWALL 110 310 1100 Series User s Guide 562...