Chapter 30 IPSec VPN
ZyWALL USG Series User’s Guide
631
30.6 IPSec VPN Background Information
Here is some more detailed IPSec VPN background information.
IKE SA Overview
The IKE SA provides a secure connection between the Zyxel Device and remote IPSec router.
It takes several steps to establish an IKE SA. The negotiation mode determines how many. There are two
negotiation modes--main mode and aggressive mode. Main mode provides better security, while
aggressive mode is faster.
Add
Click
Add
to bind a configured VPN rule to a user or group. Only that user or group may then
retrieve the specified VPN rule settings.
If you click
Add
without selecting an entry in advance then the new entry appears as the first
entry. Entry order is important as the Zyxel Device searches entries in the order listed here to find
a match. After a match is found, the Zyxel Device stops searching. If you want to add an entry
as number three for example, then first select entry 2 and click
Add
. To reorder an entry, use
Move
.
Edit
Select an existing entry and click
Edit
to change its settings.
Remove
To remove an entry, select it and click
Remove
. The Zyxel Device confirms you want to remove it
before doing so.
Activate
To turn on an entry, select it and click
Activate
. Make sure that
Enable Configuration Provisioning
is also selected.
Inactivate
To turn off an entry, select it and click
Inactivate
.
Move
Use
Move
to reorder a selected entry. Select an entry, click
Move
, type the number where the
entry should be moved, press <ENTER>, then click
Apply
.
Status
This icon shows if the entry is active (yellow) or not (gray). VPN rule settings can only be retrieved
when the entry is activated (and
Enable Configuration Provisioning
is also selected).
Priority
Priority shows the order of the entry in the list. Entry order is important as the Zyxel Device
searches entries in the order listed here to find a match. After a match is found the Zyxel Device
stops searching.
VPN
Connection
This field shows all configured VPN rules that match the rule criteria for the
Zyxel Device IPSec
VPN client. Select a rule to bind to the associated user or group.
Allowed User
Select which user or group of users is allowed to retrieve the associated VPN rule settings using
the Zyxel Device
IPSec VPN client. A user may belong to a number of groups. If entries are
configured for different groups, the Zyxel Device will allow VPN rule setting retrieval based on the
first match found.
Users of type
admin
or
limited-admin
are not allowed.
Type
This field shows how traffic is tunneled from the Zyxel Device to the Zyxel VPN client:
•
6in4
(tunnel IPv6 traffic from the Zyxel Device to the Zyxel client in an IPv4 network);
•
4in6
(tunnel IPv4 traffic from the Zyxel Device to the Zyxel VPN client in an IPv6 network);
•
4in4
(tunnel IPv4 traffic from the Zyxel Device to the Zyxel VPN client in an IPv4 network).
Apply
Click
Apply
to save your changes back to the Zyxel Device.
Reset
Click
Reset
to return the screen to its last-saved settings.
Table 226 Configuration > VPN > IPSec VPN > Configuration Provisioning (continued)
LABEL
DESCRIPTION
Содержание USG110
Страница 27: ...27 PART I User s Guide ...
Страница 67: ...Chapter 2 Initial Setup Wizard ZyWALL USG Series User s Guide 67 Figure 41 Object Service Service Group HTTPS ...
Страница 195: ...195 PART II Technical Reference ...
Страница 282: ...Chapter 9 Wireless ZyWALL USG Series User s Guide 282 Figure 229 Configuration Wireless AP Management AP Group Add Edit ...
Страница 309: ...Chapter 10 Interfaces ZyWALL USG Series User s Guide 309 ...
Страница 310: ...Chapter 10 Interfaces ZyWALL USG Series User s Guide 310 Configuration Network Interface Ethernet Edit External Type ...
Страница 312: ...Chapter 10 Interfaces ZyWALL USG Series User s Guide 312 Configuration Network Interface Ethernet Edit Internal Type ...
Страница 313: ...Chapter 10 Interfaces ZyWALL USG Series User s Guide 313 ...
Страница 314: ...Chapter 10 Interfaces ZyWALL USG Series User s Guide 314 Figure 246 Configuration Network Interface Ethernet Edit OPT ...
Страница 315: ...Chapter 10 Interfaces ZyWALL USG Series User s Guide 315 Configuration Network Interface Ethernet Edit OPT ...
Страница 334: ...Chapter 10 Interfaces ZyWALL USG Series User s Guide 334 Figure 255 Configuration Network Interface PPP Add ...
Страница 342: ...Chapter 10 Interfaces ZyWALL USG Series User s Guide 342 Figure 257 Configuration Network Interface Cellular Add Edit ...
Страница 357: ...Chapter 10 Interfaces ZyWALL USG Series User s Guide 357 Figure 267 Configuration Network Interface VLAN Add Edit ...
Страница 358: ...Chapter 10 Interfaces ZyWALL USG Series User s Guide 358 ...
Страница 372: ...Chapter 10 Interfaces ZyWALL USG Series User s Guide 372 Figure 269 Configuration Network Interface Bridge Add Edit ...
Страница 373: ...Chapter 10 Interfaces ZyWALL USG Series User s Guide 373 ...
Страница 565: ...Chapter 25 Walled Garden ZyWALL USG Series User s Guide 565 Figure 399 Walled Garden Login Example ...
Страница 613: ...Chapter 30 IPSec VPN ZyWALL USG Series User s Guide 613 Figure 431 Configuration VPN IPSec VPN VPN Connection Add Edit ...
Страница 621: ...Chapter 30 IPSec VPN ZyWALL USG Series User s Guide 621 Figure 433 Configuration VPN IPSec VPN VPN Gateway Add Edit ...
Страница 651: ...Chapter 31 SSL VPN ZyWALL USG Series User s Guide 651 Figure 454 Create a Web Application SSL Application Object ...
Страница 664: ...Chapter 32 SSL User Screens ZyWALL USG Series User s Guide 664 4 Next run and log into the SecuExtender client ...
Страница 730: ...Chapter 38 IDP ZyWALL USG Series User s Guide 730 Figure 508 Configuration UTM Profile IDP Custom Signatures Add Edit ...
Страница 784: ...Chapter 42 Device HA ZyWALL USG Series User s Guide 784 Figure 541 Configuration Device HA Device HA ...
Страница 929: ...Chapter 44 System ZyWALL USG Series User s Guide 929 Figure 648 Configuration System WWW Login Page Desktop View ...
Страница 978: ...Chapter 45 Log and Report ZyWALL USG Series User s Guide 978 Figure 696 Log Category Settings AC ...
Страница 1011: ...Chapter 47 Diagnostics ZyWALL USG Series User s Guide 1011 Figure 720 Maintenance Diagnostics Network Tool ...