
Chapter 14 VPN Screens
P-2802H(W)(L)-I Series User’s Guide
190
NAT is not normally compatible with ESP in transport mode either, but the ZyXEL Device’s
NAT Traversal
feature provides a way to handle this. NAT traversal allows you to set up an
IKE SA when there are NAT routers between the two IPSec routers.
Figure 108
NAT Router Between IPSec Routers
Normally you cannot set up an IKE SA with a NAT router between the two IPSec routers
because the NAT router changes the header of the IPSec packet. NAT traversal solves the
problem by adding a UDP port 500 header to the IPSec packet. The NAT router forwards the
IPSec packet with the UDP port 500 header unchanged. In
, when
IPSec router A tries to establish an IKE SA, IPSec router B checks the UDP port 500 header,
and IPSec routers A and B build the IKE SA.
For NAT traversal to work, you must:
• Use ESP security protocol (in either transport or tunnel mode).
• Use IKE keying mode.
• Enable NAT traversal on both IPSec endpoints.
• Set the NAT router to forward UDP port 500 to IPSec router A.
Finally, NAT is compatible with ESP in tunnel mode because integrity checks are performed
over the combination of the "original header plus original payload," which is unchanged by a
NAT device. The compatibility of AH and ESP with NAT in tunnel and transport modes is
summarized in the following table.
Y* - This is supported in the ZyXEL Device if you enable NAT traversal.
14.8 Remote DNS Server
In cases where you want to use domain names to access Intranet servers on a remote network
that has a DNS server, you must identify that DNS server. You cannot use DNS servers on the
LAN or from the ISP since these DNS servers cannot resolve domain names to private IP
addresses on the remote network
Table 72
VPN and NAT
SECURITY PROTOCOL
MODE
NAT
AH
Transport
N
AH
Tunnel
N
ESP
Transport
Y*
ESP
Tunnel
Y
Содержание P-2802H-I Series
Страница 1: ...www zyxel com P 2802H W L I Series VDSL VoIP IAD User s Guide Version 3 70 6 2007 Edition 1...
Страница 2: ......
Страница 7: ...Safety Warnings P 2802H W L I Series User s Guide 7...
Страница 8: ...Safety Warnings P 2802H W L I Series User s Guide 8...
Страница 10: ...Contents Overview P 2802H W L I Series User s Guide 10...
Страница 32: ...List of Tables P 2802H W L I Series User s Guide 32...
Страница 33: ...33 PART I Introduction Introducing the ZyXEL Device 35 Introducing the Web Configurator 43...
Страница 34: ...34...
Страница 50: ...Chapter 2 Introducing the Web Configurator P 2802H W L I Series User s Guide 50...
Страница 51: ...51 PART II Wizard Internet and Wireless Setup Wizard 53 VoIP Wizard And Example 65...
Страница 52: ...52...
Страница 64: ...Chapter 3 Internet and Wireless Setup Wizard P 2802H W L I Series User s Guide 64...
Страница 70: ...Chapter 4 VoIP Wizard And Example P 2802H W L I Series User s Guide 70...
Страница 72: ...72...
Страница 82: ...Chapter 5 Status Screens P 2802H W L I Series User s Guide 82...
Страница 88: ...Chapter 6 WAN Setup P 2802H W L I Series User s Guide 88...
Страница 116: ...Chapter 8 Wireless LAN P 2802H W L I Series User s Guide 116...
Страница 154: ...Chapter 10 Voice P 2802H W L I Series User s Guide 154...
Страница 174: ...Chapter 11 Firewalls P 2802H W L I Series User s Guide 174...
Страница 178: ...Chapter 12 Content Filtering P 2802H W L I Series User s Guide 178...
Страница 184: ...Chapter 13 Introduction to IPSec P 2802H W L I Series User s Guide 184...
Страница 219: ...Chapter 15 Certificates P 2802H W L I Series User s Guide 219 Figure 122 My Certificate Details...
Страница 238: ...Chapter 16 Static Route P 2802H W L I Series User s Guide 238...
Страница 250: ...Chapter 17 Quality of Service QoS P 2802H W L I Series User s Guide 250...
Страница 254: ...Chapter 18 Dynamic DNS Setup P 2802H W L I Series User s Guide 254...
Страница 282: ...Chapter 20 Universal Plug and Play UPnP P 2802H W L I Series User s Guide 282...
Страница 284: ...284...
Страница 324: ...Chapter 25 Troubleshooting P 2802H W L I Series User s Guide 324...
Страница 334: ...Chapter 26 Product Specifications P 2802H W L I Series User s Guide 334...
Страница 336: ...336...
Страница 348: ...Appendix A Setting up Your Computer s IP Address P 2802H W L I Series User s Guide 348...
Страница 404: ...Appendix G Legal Information P 2802H W L I Series User s Guide 404...
Страница 410: ...Appendix H Customer Support P 2802H W L I Series User s Guide 410...
Страница 418: ...Index P 2802H W L I Series User s Guide 418...