ZyWALL Series Internet Security Gateway
VPN/IPSec Setup
40-7
Table 40-2 Menu 27.1.1: IPSec Setup
FIELD DESCRIPTION
EXAMPLE
NAT Traversal
Select this check box to enable NAT traversal. NAT traversal allows you to
set up a VPN connection when there are NAT routers between the two
IPSec routers.
The remote IPSec router must also have NAT traversal enabled. You can
use NAT traversal with
ESP
protocol using
Transport
or
Tunnel
mode,
but not with
AH
protocol nor with
Manual
key management.
In order for an IPSec router behind a NAT router to receive an initiating
IPSec packet, set the NAT router to forward UDP port 500 to the IPSec
router behind the NAT router.
No
Local ID type
Press [SPACE BAR] to choose
IP
,
DNS
, or
and press [ENTER].
Select
IP
to identify this ZyWALL by its IP address.
Select
DNS
to identify this ZyWALL by a domain name.
Select
to identify this ZyWALL by an e-mail address.
The
Local ID type
and
Content
fields display
N/A
when you set
Authentication Method
to
Certificate
in
Menu 27.1.1.1 IKE Setup
(see
the
Edit Key Management Setup
field). The ZyWALL takes the local ID
type and content from the certificate you select.
Content
When you select
IP
in the
Local ID type
field, type the IP address of your
computer in the local
Content
field. The ZyWALL automatically uses the IP
address in the
My IP Address
field (refer to the My IP Address field
description) if you configure the local
Content
field to
0.0.0.0
or leave it
blank.
It is recommended that you type an IP address other than
0.0.0.0
in the
local
Content
field or use the
DNS
or
ID type in the following
situations.
When there is a NAT router between the two IPSec routers.
When you want the remote IPSec router to be able to distinguish
between VPN connection requests that come in from IPSec
routers with dynamic WAN IP addresses.
When you select
DNS
or
in the
Local ID type
field, type a domain
name or e-mail address by which to identify this ZyWALL in the local
Content field. Use up to 31 ASCII characters including spaces, although
trailing spaces are truncated. The domain name or e-mail address is for
identification purposes only and can be any string.
Содержание Internet Security Gateway ZyWALL 100
Страница 1: ...ZyWALL 10W 30W 50 100 Internet Security Gateway User s Guide Version 3 62 February 2004 ...
Страница 8: ......
Страница 32: ......
Страница 42: ......
Страница 52: ...ZyWALL Series Internet Security Gateway 1 10 Getting to Know Your ZyWALL Figure 1 2 VPN Application ...
Страница 60: ......
Страница 74: ......
Страница 92: ......
Страница 102: ......
Страница 103: ...DMZ and WAN III Part III DMZ and WAN This part covers configuration of the DMZ and WAN screens ...
Страница 104: ......
Страница 108: ......
Страница 124: ...ZyWALL Series Internet Security Gateway 8 16 WAN Screens Figure 8 10 Dial Backup Setup ...
Страница 132: ......
Страница 134: ......
Страница 156: ......
Страница 170: ......
Страница 217: ...VPN IPSec VI Part VI VPN IPSec This part provides information on how to configure Virtual Private Networks ...
Страница 218: ......
Страница 224: ......
Страница 235: ...ZyWALL Series Internet Security Gateway VPN Screens 15 11 Figure 15 5 VPN IKE ...
Страница 260: ......
Страница 262: ......
Страница 282: ...ZyWALL Series Internet Security Gateway 16 20 Certificates Figure 16 9 Trusted CA Details ...
Страница 291: ...ZyWALL Series Internet Security Gateway Certificates 16 29 Figure 16 14 Trusted Remote Host Details ...
Страница 298: ......
Страница 300: ......
Страница 302: ...ZyWALL Series Internet Security Gateway 17 2 Authentication Server Figure 17 1 Local User Database ...
Страница 308: ......
Страница 350: ......
Страница 351: ...Logs IX Part IX Logs This part provides information and instructions for the logs and reports ...
Страница 352: ......
Страница 356: ...ZyWALL Series Internet Security Gateway 20 4 Log Screens Figure 20 2 Log Settings ...
Страница 364: ......
Страница 365: ...Maintenance X Part X Maintenance This part covers the maintenance screens ...
Страница 366: ......
Страница 378: ......
Страница 380: ......
Страница 386: ...ZyWALL Series Internet Security Gateway 22 6 Introducing the SMT Figure 22 5 Advanced Management SMT Menus ...
Страница 406: ......
Страница 420: ......
Страница 428: ......
Страница 446: ......
Страница 466: ......
Страница 490: ......
Страница 504: ......
Страница 524: ......
Страница 536: ......
Страница 538: ......
Страница 554: ......
Страница 574: ......
Страница 580: ......
Страница 586: ......
Страница 588: ......
Страница 590: ......
Страница 592: ......
Страница 604: ......
Страница 608: ......
Страница 610: ......
Страница 614: ......
Страница 624: ......
Страница 634: ......
Страница 636: ......
Страница 648: ......
Страница 654: ......
Страница 680: ......
Страница 682: ......