Chapter 14 IPSec VPN
ZyWALL 2 Plus User’s Guide
254
A VPN tunnel is usually established in two phases. Each phase establishes a security
association (SA), a contract indicating what security parameters the ZyWALL and the remote
IPSec router will use. The first phase establishes an Internet Key Exchange (IKE) SA between
the ZyWALL and remote IPSec router. The second phase uses the IKE SA to securely
establish an IPSec SA through which the ZyWALL and remote IPSec router can send data
between computers on the local network and remote network. The following figure illustrates
this.
Figure 169
VPN: IKE SA and IPSec SA
In this example, a computer in network
A
is exchanging data with a computer in network
B
.
Inside networks
A
and
B
, the data is transmitted the same way data is normally transmitted in
the networks. Between routers
X
and
Y
, the data is protected by tunneling, encryption,
authentication, and other security features of the IPSec SA. The IPSec SA is established
securely using the IKE SA that routers
X
and
Y
established first.
The rest of this section discusses IKE SA and IPSec SA in more detail.
14.1.1 IKE SA Overview
The IKE SA provides a secure connection between the ZyWALL and remote IPSec router.
It takes several steps to establish an IKE SA. The negotiation mode determines the number of
steps to use. There are two negotiation modes--main mode and aggressive mode. Main mode
provides better security, while aggressive mode is faster.
"
Both routers must use the same negotiation mode.
These modes are discussed in more detail in
. Main mode is used
in various examples in the rest of this section.
14.1.1.1 IP Addresses of the ZyWALL and Remote IPSec Router
In the ZyWALL, you have to specify the IP addresses of the ZyWALL and the remote IPSec
router to establish an IKE SA.
Содержание ADSL 2+ Security Gateway
Страница 1: ...www zyxel com ZyWALL 2 Plus Internet Security Appliance User s Guide Version 4 03 12 2007 Edition 1 ...
Страница 2: ......
Страница 25: ...Table of Contents ZyWALL 2 Plus User s Guide 25 Index 679 ...
Страница 26: ...Table of Contents ZyWALL 2 Plus User s Guide 26 ...
Страница 46: ...46 ...
Страница 88: ...Chapter 3 Wizard Setup ZyWALL 2 Plus User s Guide 88 ...
Страница 131: ...131 PART II Network LAN Screens 133 Bridge Screens 145 WAN Screens 151 DMZ Screens 171 Wireless LAN 181 ...
Страница 132: ...132 ...
Страница 144: ...Chapter 6 LAN Screens ZyWALL 2 Plus User s Guide 144 ...
Страница 180: ...Chapter 9 DMZ Screens ZyWALL 2 Plus User s Guide 180 ...
Страница 190: ...190 ...
Страница 209: ...Chapter 11 Firewall ZyWALL 2 Plus User s Guide 209 Figure 138 SECURITY FIREWALL Rule Summary Edit ...
Страница 221: ...Chapter 11 Firewall ZyWALL 2 Plus User s Guide 221 Figure 149 My Service Firewall Rule Example Rule Summary Completed ...
Страница 222: ...Chapter 11 Firewall ZyWALL 2 Plus User s Guide 222 ...
Страница 252: ...Chapter 13 Content Filtering Reports ZyWALL 2 Plus User s Guide 252 ...
Страница 265: ...Chapter 14 IPSec VPN ZyWALL 2 Plus User s Guide 265 Figure 178 SECURITY VPN VPN Rules IKE Edit Gateway Policy ...
Страница 274: ...Chapter 14 IPSec VPN ZyWALL 2 Plus User s Guide 274 Figure 181 SECURITY VPN VPN Rules IKE Edit Network Policy ...
Страница 306: ...Chapter 15 Certificates ZyWALL 2 Plus User s Guide 306 Figure 203 SECURITY CERTIFICATES My Certificates Create Basic ...
Страница 328: ...Chapter 16 Authentication Server ZyWALL 2 Plus User s Guide 328 ...
Страница 330: ...330 ...
Страница 346: ...Chapter 17 Network Address Translation NAT ZyWALL 2 Plus User s Guide 346 ...
Страница 350: ...Chapter 18 Static Route ZyWALL 2 Plus User s Guide 350 ...
Страница 398: ...Chapter 21 Remote Management ZyWALL 2 Plus User s Guide 398 ...
Страница 416: ...Chapter 24 ALG Screen ZyWALL 2 Plus User s Guide 416 ...
Страница 417: ...417 PART V Logs and Maintenance Logs Screens 419 Maintenance 447 ...
Страница 418: ...418 ...
Страница 423: ...Chapter 25 Logs Screens ZyWALL 2 Plus User s Guide 423 Figure 274 LOGS Log Settings ...
Страница 466: ...466 ...
Страница 474: ...Chapter 27 Introducing the SMT ZyWALL 2 Plus User s Guide 474 ...
Страница 496: ...Chapter 30 LAN Setup ZyWALL 2 Plus User s Guide 496 ...
Страница 504: ...Chapter 32 DMZ Setup ZyWALL 2 Plus User s Guide 504 ...
Страница 508: ...Chapter 33 Wireless Setup ZyWALL 2 Plus User s Guide 508 ...
Страница 556: ...Chapter 38 Filter Configuration ZyWALL 2 Plus User s Guide 556 ...
Страница 570: ...Chapter 40 System Information Diagnosis ZyWALL 2 Plus User s Guide 570 ...
Страница 586: ...Chapter 41 Firmware and Configuration File Maintenance ZyWALL 2 Plus User s Guide 586 ...
Страница 594: ...Chapter 42 System Maintenance Menus 8 to 10 ZyWALL 2 Plus User s Guide 594 ...
Страница 598: ...Chapter 43 Remote Management ZyWALL 2 Plus User s Guide 598 ...
Страница 603: ...603 PART VII Troubleshooting and Specifications Troubleshooting 605 Product Specifications 613 ...
Страница 604: ...604 ...
Страница 612: ...Chapter 45 Troubleshooting ZyWALL 2 Plus User s Guide 612 ...
Страница 620: ...620 ...
Страница 644: ...Appendix B Pop up Windows JavaScripts and Java Permissions ZyWALL 2 Plus User s Guide 644 ...
Страница 668: ...Appendix E Importing Certificates ZyWALL 2 Plus User s Guide 668 ...
Страница 672: ...Appendix F Legal Information ZyWALL 2 Plus User s Guide 672 ...
Страница 678: ...Appendix G Customer Support ZyWALL 2 Plus User s Guide 678 ...