background image

 

 
 

 

 

 

 

                     

ISG50 

  Application Note 

Version  1.0 

June,  2011 

 

                                             

Содержание ISG50

Страница 1: ...ISG50 Application Note Version 1 0 June 2011...

Страница 2: ...ding VoIP requirements you can connect the ISG50 to the LAN or DMZ of the ZyWALL The USG provides security services and the ISG50 acts as a pure IP PBX to provide VoIP services Goal to Achieve IP phon...

Страница 3: ...guration Guide Network Conditions USG 20W WAN IP 59 124 163 156 SIP server IP ISG50 172 16 1 10 ISG50 WAN IP 172 16 1 10 USG 20W Step 1 Click CONFIGURATION Network Interface Ethernet to assign USG 20W...

Страница 4: ...Step 2 Assume ISG50 s WAN port is connected to LAN2 port 4 of USG 20W Configure an IP for this interface...

Страница 5: ...e to let USG 20W do packet forwarding Fill in the Original IP WAN IP address Fill in the Mapped IP ISG s IP address Configure the Original Port and the Mapped Port here we set the SIP signaling port 5...

Страница 6: ...Step 4 The user can create an address object for ISG50 for further configuration usage Click Create new object for this function...

Страница 7: ...Step 5 Click CONFIGURATION Network Firewall to open the firewall configuration screen Click on the Add button to create a firewall rule to enable the VoIP service to pass from the WAN to LAN2...

Страница 8: ...Step 6 Disable SIP ALG...

Страница 9: ...ISG50 Step 1 Set the WAN IP of USG 20W in the Fake IP field...

Страница 10: ...Step 2 Make sure the SIP signaling port and the RTP port range are the same as those you configured in the port forwarding in USG 20W...

Страница 11: ...Step 3 Disable the firewall in ISG50 since USG 20W acts as firewall...

Страница 12: ...s and corporate resources through the Internet Using IPSec VPN companies can secure connections to branch offices partners and headquarters Besides road warriors and telecommuters can access the compa...

Страница 13: ...4 USG 20W WAN IP 59 124 163 151 Local subnet 192 168 2 0 24 IPSec VPN Conditions Phase 1 Authentication 1234567890 Negotiation mode Main Encryption Algorithm 3DES Authentication Algorirhm MD5 Key Grou...

Страница 14: ...ISG50 Step 1 Click on the Add button to add a VPN gateway rule...

Страница 15: ...the VPN gateway rule the user needs to fill in the following VPN gateway name Gateway address My Address ISG50 s IP and Peer Gateway Address USG s IP Authentication setting Shared Key ID Type setting...

Страница 16: ...Phase 1 setting Negotiation mode Encryption algorithm Authentication algorithm Key Group Step 3 Click CONFIGURATION VPN IPSec VPN VPN Connection to configure the phase 2 rule...

Страница 17: ...Step 4 To configure the phase 2 rule the user needs to fill in the following VPN connection name VPN gateway selection...

Страница 18: ...Settings Active protocol Encapsulation mode Encryption algorithm Authentication algorithm Perfect Forward Secrecy Step 5 Click the Connect button to establish the VPN link Once the tunnel is establish...

Страница 19: ...ay rule Step 2 To configure the VPN gateway rule user needs to fill in VPN gateway name Gateway address My Address USG s IP and Peer Gateway Address ISG50 s IP Authentication setting Shared Key ID Typ...

Страница 20: ...Phase 1 setting Negotiation mode Encryption algorithm Authentication algorithm Key Group Step 3 Configure the phase 2 rule...

Страница 21: ...user needs to fill in VPN connection name VPN gateway selection Policy for Local network side Remote network side Phase 2 Settings Active protocol Encapsulation mode Encryption algorithm Authenticati...

Страница 22: ...e Policy in step 4 the user can create a specific object for the VPN subnet Step 5 Click on the Connect button to establish the VPN link Once the tunnel is established a connected icon will be display...

Страница 23: ...Result When the VPN tunnel is established the user can find the SA information on MONITOR VPN MONITOR IPSec ISG50 USG...

Страница 24: ...2 168 1 0 24 IPSec VPN Conditions Phase 1 Authentication 111111111 Negotiation mode Main Encryption Algorithm DES Authentication Algorithm MD5 Key Group DH1 Phase 2 Active Protocol ESP Encapsulation M...

Страница 25: ...the configuration screen Click on the Add button to add a VPN gateway rule Step 2 To configure the VPN gateway rule the user needs to fill in the following VPN gateway name Gateway address My Address...

Страница 26: ...Phase 1 Setting Step 3 Click CONFIGURATION VPN IPSec VPN VPN Connection to configure the phase 2 rule...

Страница 27: ...Step 4 To configure the phase 2 rule the user needs to fill in the following VPN connection name VPN gateway selection Policy for Phase 2 setting...

Страница 28: ...Step 5 Start the ZyXEL IPSec VPN Client Fill in the Phase 1 configuration...

Страница 29: ...onfigure the phase 2 parameters Since it is a dynamic rule the user MUST enable it from the VPN client Click Open Tunnel to enable it The icon will turn green if the VPN connection is established succ...

Страница 30: ...Step 7 When the VPN tunnel is established the user can find the SA information on MONITOR VPN MONITOR IPSec Result The user from IP 10 59 1 71 can ping the ISG50 s LAN1 IP 192 168 1 1...

Отзывы: