ZyWALL Series Internet Security Gateway
VPN/IPSec Setup
40-3
Table 40-1 Menu 27.1: IPSec Summary
FIELD DESCRIPTION EXAMPLE
Name
This field displays the unique identification name for this VPN rule. The
name may be up to 32 characters long but only 10 characters will be
displayed here.
Taiwan
A
Y
signifies that this VPN rule is active.
Y
Local Addr
Start
When the
Addr Type
field in
Menu 27.1.1 IPSec Setup
is configured to
Single
, this is a static IP address on the LAN behind your ZyWALL.
When the
Addr Type
field in
Menu 27.1.1 IPSec Setup
is configured to
Range
, this is the beginning (static) IP address, in a range of computers
on the LAN behind your ZyWALL.
When the
Addr Type
field in
Menu 27.1.1 IPSec Setup
is configured to
SUBNET
, this is a static IP address on the LAN behind your ZyWALL.
192.168.1.35
Addr End /
Mask
When the
Addr Type
field in
Menu 27.1.1 IPSec Setup
is configured to
Single
, this is the same (static) IP address as in the
Local Addr Start
field.
When the
Addr Type
field in
Menu 27.1.1 IPSec Setup
is configured to
Range
, this is the end (static) IP address, in a range of computers on the
LAN behind your ZyWALL.
When the
Addr Type
field in
Menu 27.1.1 IPSec Setup
is configured to
SUBNET
, this is a subnet mask on the LAN behind your ZyWALL.
192.168.1.38
Encap
This field displays
Tunnel
mode
or
Transport
mode. See earlier for a
discussion of these. You need to finish configuring the VPN policy in menu
27.1.1.1 or 27.1.1.2 if
???
is displayed.
Tunnel
IPSec
Algorithm
This field displays the security protocols used for an SA.
ESP
provides
confidentiality and integrity of data by encrypting the data and
encapsulating it into IP packets. Encryption methods include 56-bit
DES
,
168-bit
3DES
and 128-bit
AES
.
NULL
denotes a tunnel without
encryption.
AH
(Authentication Header) provides strong integrity and authentication
by adding authentication information to IP packets. This authentication
information is calculated using header and payload data in the IP packet.
This provides an additional level of security.
AH
choices are
MD5
(default
- 128 bits) and
SHA -1
(160 bits)
.
Both
AH
and
ESP
increase the ZyWALL’s processing requirements and
communications latency (delay).
You need to finish configuring the VPN policy in menu 27.1.1.1 or 27.1.1.2
if
???
is displayed.
ESP DES MD5
Содержание Internet Security Gateway ZyWALL 100
Страница 1: ...ZyWALL 10W 30W 50 100 Internet Security Gateway User s Guide Version 3 62 February 2004 ...
Страница 8: ......
Страница 32: ......
Страница 42: ......
Страница 52: ...ZyWALL Series Internet Security Gateway 1 10 Getting to Know Your ZyWALL Figure 1 2 VPN Application ...
Страница 60: ......
Страница 74: ......
Страница 92: ......
Страница 102: ......
Страница 103: ...DMZ and WAN III Part III DMZ and WAN This part covers configuration of the DMZ and WAN screens ...
Страница 104: ......
Страница 108: ......
Страница 124: ...ZyWALL Series Internet Security Gateway 8 16 WAN Screens Figure 8 10 Dial Backup Setup ...
Страница 132: ......
Страница 134: ......
Страница 156: ......
Страница 170: ......
Страница 217: ...VPN IPSec VI Part VI VPN IPSec This part provides information on how to configure Virtual Private Networks ...
Страница 218: ......
Страница 224: ......
Страница 235: ...ZyWALL Series Internet Security Gateway VPN Screens 15 11 Figure 15 5 VPN IKE ...
Страница 260: ......
Страница 262: ......
Страница 282: ...ZyWALL Series Internet Security Gateway 16 20 Certificates Figure 16 9 Trusted CA Details ...
Страница 291: ...ZyWALL Series Internet Security Gateway Certificates 16 29 Figure 16 14 Trusted Remote Host Details ...
Страница 298: ......
Страница 300: ......
Страница 302: ...ZyWALL Series Internet Security Gateway 17 2 Authentication Server Figure 17 1 Local User Database ...
Страница 308: ......
Страница 350: ......
Страница 351: ...Logs IX Part IX Logs This part provides information and instructions for the logs and reports ...
Страница 352: ......
Страница 356: ...ZyWALL Series Internet Security Gateway 20 4 Log Screens Figure 20 2 Log Settings ...
Страница 364: ......
Страница 365: ...Maintenance X Part X Maintenance This part covers the maintenance screens ...
Страница 366: ......
Страница 378: ......
Страница 380: ......
Страница 386: ...ZyWALL Series Internet Security Gateway 22 6 Introducing the SMT Figure 22 5 Advanced Management SMT Menus ...
Страница 406: ......
Страница 420: ......
Страница 428: ......
Страница 446: ......
Страница 466: ......
Страница 490: ......
Страница 504: ......
Страница 524: ......
Страница 536: ......
Страница 538: ......
Страница 554: ......
Страница 574: ......
Страница 580: ......
Страница 586: ......
Страница 588: ......
Страница 590: ......
Страница 592: ......
Страница 604: ......
Страница 608: ......
Страница 610: ......
Страница 614: ......
Страница 624: ......
Страница 634: ......
Страница 636: ......
Страница 648: ......
Страница 654: ......
Страница 680: ......
Страница 682: ......