Chapter 16 VPN
ADSL Series User’s Guide
219
16.6.8.1 ID Type and Content Examples
Two IPSec routers must have matching ID type and content configuration in order to set up a VPN
tunnel.
The two ZyXEL Devices in this example can complete negotiation and establish a VPN tunnel.
The two ZyXEL Devices in this example cannot complete their negotiation because ZyXEL Device B’s
Local ID type is IP, but ZyXEL Device A’s Peer ID type is set to E-mail. An “ID mismatched”
message displays in the IPSEC LOG.
16.6.9 Pre-Shared Key
A pre-shared key identifies a communicating party during a phase 1 IKE negotiation (see
for more on IKE phases). It is called “pre-shared” because you have to share it
with another party before you can communicate with them over a secure connection.
16.6.10 Diffie-Hellman (DH) Key Groups
Diffie-Hellman (DH) is a public-key cryptography protocol that allows two parties to establish a
shared secret over an unsecured communications channel. Diffie-Hellman is used within IKE SA
setup to establish session keys. 768-bit (Group 1 - DH1) and 1024-bit (Group 2 – DH2) Diffie-
Hellman groups are supported. Upon completion of the Diffie-Hellman exchange, the two peers
have a shared secret, but the IKE SA is not authenticated. For authentication, use pre-shared keys.
16.6.11 Telecommuter VPN/IPSec Examples
The following examples show how multiple telecommuters can make VPN connections to a single
ZyXEL Device at headquarters. The telecommuters use IPSec routers with dynamic WAN IP
addresses. The ZyXEL Device at headquarters has a static public IP address.
16.6.11.1 Telecommuters Sharing One VPN Rule Example
See the following figure and table for an example configuration that allows multiple telecommuters
(A, B and C in the figure) to use one VPN rule to simultaneously access a ZyXEL Device at
headquarters (HQ in the figure). The telecommuters do not have domain names mapped to the
Table 70
Matching ID Type and Content Configuration Example
ZYXEL DEVICE A
ZYXEL DEVICE B
Local ID type: E-mail
Local ID type: IP
Local ID content: [email protected]
Local ID content: 1.1.1.2
Peer ID type: IP
Peer ID type: E-mail
Peer ID content: 1.1.1.2
Peer ID content: [email protected]
Table 71
Mismatching ID Type and Content Configuration Example
ZYXEL DEVICE A
ZYXEL DEVICE B
Local ID type: IP
Local ID type: IP
Local ID content: 1.1.1.10
Local ID content: 1.1.1.10
Peer ID type: E-mail
Peer ID type: IP
Peer ID content: [email protected]
Peer ID content: N/A
Содержание P-660HN-F1
Страница 2: ...Videos ADSL Series User s Guide 2 Videos File Sharing Video Example 55 QoS Video Example 76...
Страница 6: ...Document Conventions ADSL Series User s Guide 6 Server Firewall Router Switch...
Страница 8: ...Safety Warnings ADSL Series User s Guide 8...
Страница 10: ...Contents Overview ADSL Series User s Guide 10...
Страница 19: ...19 PART I User s Guide...
Страница 20: ...20...
Страница 26: ...Chapter 1 Introduction ADSL Series User s Guide 26...
Страница 40: ...Chapter 2 Introducing the Web Configurator ADSL Series User s Guide 40...
Страница 80: ...Chapter 3 Tutorials ADSL Series User s Guide 80...
Страница 81: ...81 PART II Technical Reference...
Страница 82: ...82...
Страница 130: ...Chapter 6 Wireless ADSL Series User s Guide 130...
Страница 160: ...Chapter 8 Routing ADSL Series User s Guide 160...
Страница 164: ...Chapter 9 DNS Route ADSL Series User s Guide 164...
Страница 182: ...Chapter 11 Network Address Translation NAT ADSL Series User s Guide 182...
Страница 190: ...Chapter 13 Firewall ADSL Series User s Guide 190...
Страница 202: ...Chapter 15 Certificates ADSL Series User s Guide 202...
Страница 222: ...Chapter 16 VPN ADSL Series User s Guide 222...
Страница 226: ...Chapter 17 System Monitor ADSL Series User s Guide 226...
Страница 228: ...Chapter 18 User Account ADSL Series User s Guide 228...
Страница 242: ...Chapter 24 Backup Restore ADSL Series User s Guide 242...
Страница 246: ...Chapter 25 Diagnostic ADSL Series User s Guide 246...
Страница 254: ...Chapter 26 Troubleshooting ADSL Series User s Guide 254...
Страница 262: ...Chapter 27 Product Specifications ADSL Series User s Guide 262...
Страница 302: ...Appendix B Setting Up Your Computer s IP Address ADSL Series User s Guide 302...
Страница 310: ...Appendix C Pop up Windows Java Script and Java Permissions ADSL Series User s Guide 310...
Страница 334: ...Appendix E Common Services ADSL Series User s Guide 334...
Страница 355: ...Appendix F Open Software Announcements ADSL Series User s Guide 355...
Страница 356: ...Appendix F Open Software Announcements ADSL Series User s Guide 356...
Страница 360: ...Appendix G Legal Information ADSL Series User s Guide 360...