P-793H v 2 Support Notes
\
Non-secure host
11. How can I keep a tunnel alive?
To keep a tunnel alive, you can check "keep alive" option when configuring
your VPN tunnel. With this option, whenever phase 2 SA lifetime is due, IKE
negotiation procedure will be invoked automatically even without traffic to
make the connection stay.
But to reduce the consumption of system resource, if VPN tunnels get
disconnected either manually, by idle timer, or because of power cycle, packet
triggering is still necessary to make the tunnel up.
12. Single, Range, Subnet, which types of IP address do P-793H v2
support
in VPN/IPSec?
The mentioned P-793H v2 series support all of the types. In other words, you
can specify a single PC, a range of PCs or even a network of PCs to utilize the
VPN/IPSec service.
13. Can P-793H v2 support IPSec passthrough?
Yes, P-793H v2 can support IPSec passthrough. P-793H v2 series don't only
support IPSec/VPN gateway, it can also be a NAT router supporting IPSec
passthrough.
If the VPN connection is initiated from the security gateway behind P-793H v2,
no configuration is necessary for NAT nor Firewall.
If the VPN connection is initiated from the security gateway outside of P-793H
v2, NAT port forwarding and Firewall forwarding are necessary.
To configure NAT port forwarding, please go to WEB interface, Setup/
"SUA/NAT", put the secure gateway's IP address in default server.
To configure Firewall forwarding, please go to WEB interface, Setup/Firewall,
select Packet Direction to WAN to LAN, and create a firewall rule the forwards
IKE(UDP:500).
14. Can P-793H v2 behave as a NAT router supporting IPSec
passthrough and an IPSec gateway simultaneously?
No, P-793H v2 can't support them simultaneously. You need to choose either
one. If P-793H v2 is to support IPSec passthrough, you have to disable the VPN
36
All contents copy right © 2010 Zy XEL Communications Corporation.