
Chapter 20 IPSec VPN
ZyWALL 110/310/1100 Series User’s Guide
305
20.6 IPSec VPN Background Information
Here is some more detailed IPSec VPN background information.
IKE SA Overview
The IKE SA provides a secure connection between the ZyWALL and remote IPSec router.
It takes several steps to establish an IKE SA. The negotiation mode determines how many. There
are two negotiation modes--main mode and aggressive mode. Main mode provides better security,
while aggressive mode is faster.
Note: Both routers must use the same negotiation mode.
These modes are discussed in more detail in
. Main mode is used in
various examples in the rest of this section.
IP Addresses of the ZyWALL and Remote IPSec Router
To set up an IKE SA, you have to specify the IP addresses of the ZyWALL and remote IPSec router.
You can usually enter a static IP address or a domain name for either or both IP addresses.
Sometimes, your ZyWALL might offer another alternative, such as using the IP address of a port or
interface, as well.
You can also specify the IP address of the remote IPSec router as 0.0.0.0. This means that the
remote IPSec router can have any IP address. In this case, only the remote IPSec router can initiate
an IKE SA because the ZyWALL does not know the IP address of the remote IPSec router. This is
often used for telecommuters.
Move
Use Move to reorder a selected entry. Select an entry, click Move, type the number where
the entry should be moved, press <ENTER>, then click Apply.
Status
This icon shows if the entry is active (yellow) or not (gray). VPN rule settings can only be
retrieved when the entry is activated (and Enable Configuration Provisioning is also
selected).
Priority
Priority shows the order of the entry in the list. Entry order is important as the ZyWALL
searches entries in the order listed here to find a match. After a match is found the ZyWALL
stops searching.
VPN Connection This field shows all configured VPN rules that match the rule criteria for the
ZyWALL IPSec
VPN client. Select a rule to bind to the associated user or group.
Allowed User
Select which user or group of users is allowed to retrieve the associated VPN rule settings
using the
ZyWALL IPSec
VPN client. A user may belong to a number of groups. If entries
are configured for different groups, the ZyWALL will allow VPN rule setting retrieval based
on the first match found.
Users of type admin or limited-admin are not allowed.
Apply
Click Apply to save your changes back to the ZyWALL.
Reset
Click Reset to return the screen to its last-saved settings.
Table 113
Configuration > VPN > IPSec VPN > Configuration Provisioning (continued)
LABEL
DESCRIPTION
Содержание ZyWALL 110 Series
Страница 16: ...ZyWALL 110 310 1100 Series User s Guide 16...
Страница 32: ...Chapter 1 Introduction ZyWALL 110 310 1100 Series User s Guide 32...
Страница 42: ...Chapter 3 Hardware Introduction ZyWALL 110 310 1100 Series User s Guide 42...
Страница 68: ...Chapter 4 Quick Setup Wizards ZyWALL 110 310 1100 Series User s Guide 68...
Страница 83: ...Chapter 6 Monitor ZyWALL 110 310 1100 Series User s Guide 83 Figure 60 Monitor System Status Interface Status...
Страница 128: ...Chapter 7 Interfaces ZyWALL 110 310 1100 Series User s Guide 128 Figure 83 Configuration Network Interface PPP Add...
Страница 135: ...Chapter 7 Interfaces ZyWALL 110 310 1100 Series User s Guide 135 Figure 85 Configuration Network Interface Cellular Add...
Страница 176: ...Chapter 7 Interfaces ZyWALL 110 310 1100 Series User s Guide 176...
Страница 186: ...Chapter 8 Trunk ZyWALL 110 310 1100 Series User s Guide 186...
Страница 210: ...Chapter 10 Routing Protocols ZyWALL 110 310 1100 Series User s Guide 210...
Страница 220: ...Chapter 12 DDNS ZyWALL 110 310 1100 Series User s Guide 220...
Страница 228: ...Chapter 13 NAT ZyWALL 110 310 1100 Series User s Guide 228...
Страница 240: ...Chapter 15 ALG ZyWALL 110 310 1100 Series User s Guide 240...
Страница 246: ...Chapter 16 IP MAC Binding ZyWALL 110 310 1100 Series User s Guide 246...
Страница 263: ...Chapter 18 Authentication Policy ZyWALL 110 310 1100 Series User s Guide 263...
Страница 264: ...Chapter 18 Authentication Policy ZyWALL 110 310 1100 Series User s Guide 264...
Страница 270: ...Chapter 19 Firewall ZyWALL 110 310 1100 Series User s Guide 270 Figure 163 Configuration Firewall...
Страница 296: ...Chapter 20 IPSec VPN ZyWALL 110 310 1100 Series User s Guide 296 Figure 182 Configuration VPN IPSec VPN VPN Gateway Edit...
Страница 316: ...Chapter 20 IPSec VPN ZyWALL 110 310 1100 Series User s Guide 316...
Страница 340: ...Chapter 22 SSL User Screens ZyWALL 110 310 1100 Series User s Guide 340...
Страница 442: ...Chapter 36 DHCPv6 ZyWALL 110 310 1100 Series User s Guide 442...
Страница 540: ...Appendix A Legal Information ZyWALL 110 310 1100 Series User s Guide 540...
Страница 558: ...Index ZyWALL 110 310 1100 Series User s Guide 558...
Страница 559: ...Index ZyWALL 110 310 1100 Series User s Guide 559...
Страница 560: ...Index ZyWALL 110 310 1100 Series User s Guide 560...
Страница 561: ...Index ZyWALL 110 310 1100 Series User s Guide 561...
Страница 562: ...Index ZyWALL 110 310 1100 Series User s Guide 562...