ZyWALL Series Internet Security Gateway
15-14
VPN
Screens
Table 15-7 VPN IKE
LABEL DESCRIPTION
Remote
Remote IP addresses must be static and correspond to the remote IPSec router's
configured local IP addresses. The remote fields do not apply when the
Secure
Gateway Address
field is configured to
0.0.0.0
. In this case only the remote IPSec
router can initiate the VPN.
Two active SAs can have the same configured local or remote IP address, but not
both. You can configure multiple SAs between the same local and remote IP
addresses, as long as only one is active at any time.
Address Type
Use the drop-down menu to choose
Single Address
,
Range Address
, or
Subnet
Address
. Select
Single Address
with a single IP address. Select
Range Address
for a specific range of IP addresses. Select
Subnet Address
to specify IP addresses
on a network by their subnet mask.
Starting IP
Address
When the
Address Type
field is configured to
Single Address
, enter a (static) IP
address on the network behind the remote IPSec router. When the
Address Type
field is configured to
Range Address
, enter the beginning (static) IP address, in a
range of computers on the network behind the remote IPSec router. When the
Address Type
field is configured to
Subnet Address
, enter a (static) IP address on
the network behind the remote IPSec router.
Ending IP
Address / Subnet
Mask
When the
Address Type
field is configured to
Single Address
, this field is N/A.
When the
Address Type
field is configured to
Range Address
, enter the end (static)
IP address, in a range of computers on the network behind the remote IPSec router.
When the
Address Type
field is configured to
Subnet Address
, enter a subnet
mask on the network behind the remote IPSec router.
DNS Server (for
IPSec VPN)
If there is a private DNS server that services the VPN, type its IP address here. The
ZyWALL assigns this additional DNS server to the ZyWALL's DHCP clients that have
IP addresses in this IPSec rule's range of local addresses.
A DNS server allows clients on the VPN to find other computers and servers on the
VPN by their (private) domain names.
Authentication
Method
Select
Pre-Shared Key
to use a pre-shared key to identify the ZyWALL and the
remote IPSec router. A pre-shared key identifies a communicating party during a
phase 1 IKE negotiation. It is called "pre-shared" because you have to share it with
another party before you can communicate with them over a secure connection.
Select
Certificate
to identify the ZyWALL and the remote IPSec router by
certificates.
Содержание Internet Security Gateway ZyWALL 100
Страница 1: ...ZyWALL 10W 30W 50 100 Internet Security Gateway User s Guide Version 3 62 February 2004 ...
Страница 8: ......
Страница 32: ......
Страница 42: ......
Страница 52: ...ZyWALL Series Internet Security Gateway 1 10 Getting to Know Your ZyWALL Figure 1 2 VPN Application ...
Страница 60: ......
Страница 74: ......
Страница 92: ......
Страница 102: ......
Страница 103: ...DMZ and WAN III Part III DMZ and WAN This part covers configuration of the DMZ and WAN screens ...
Страница 104: ......
Страница 108: ......
Страница 124: ...ZyWALL Series Internet Security Gateway 8 16 WAN Screens Figure 8 10 Dial Backup Setup ...
Страница 132: ......
Страница 134: ......
Страница 156: ......
Страница 170: ......
Страница 217: ...VPN IPSec VI Part VI VPN IPSec This part provides information on how to configure Virtual Private Networks ...
Страница 218: ......
Страница 224: ......
Страница 235: ...ZyWALL Series Internet Security Gateway VPN Screens 15 11 Figure 15 5 VPN IKE ...
Страница 260: ......
Страница 262: ......
Страница 282: ...ZyWALL Series Internet Security Gateway 16 20 Certificates Figure 16 9 Trusted CA Details ...
Страница 291: ...ZyWALL Series Internet Security Gateway Certificates 16 29 Figure 16 14 Trusted Remote Host Details ...
Страница 298: ......
Страница 300: ......
Страница 302: ...ZyWALL Series Internet Security Gateway 17 2 Authentication Server Figure 17 1 Local User Database ...
Страница 308: ......
Страница 350: ......
Страница 351: ...Logs IX Part IX Logs This part provides information and instructions for the logs and reports ...
Страница 352: ......
Страница 356: ...ZyWALL Series Internet Security Gateway 20 4 Log Screens Figure 20 2 Log Settings ...
Страница 364: ......
Страница 365: ...Maintenance X Part X Maintenance This part covers the maintenance screens ...
Страница 366: ......
Страница 378: ......
Страница 380: ......
Страница 386: ...ZyWALL Series Internet Security Gateway 22 6 Introducing the SMT Figure 22 5 Advanced Management SMT Menus ...
Страница 406: ......
Страница 420: ......
Страница 428: ......
Страница 446: ......
Страница 466: ......
Страница 490: ......
Страница 504: ......
Страница 524: ......
Страница 536: ......
Страница 538: ......
Страница 554: ......
Страница 574: ......
Страница 580: ......
Страница 586: ......
Страница 588: ......
Страница 590: ......
Страница 592: ......
Страница 604: ......
Страница 608: ......
Страница 610: ......
Страница 614: ......
Страница 624: ......
Страница 634: ......
Страница 636: ......
Страница 648: ......
Страница 654: ......
Страница 680: ......
Страница 682: ......