
Chapter 4 Quick Setup Wizards
ZyWALL 110/310/1100 Series User’s Guide
56
• Dead Peer Detection (DPD) has the ZyWALL make sure the remote IPSec device is there
before transmitting data through the IKE SA. If there has been no traffic for at least 15 seconds,
the ZyWALL sends a message to the remote IPSec device. If it responds, the ZyWALL transmits
the data. If it does not respond, the ZyWALL shuts down the IKE SA.
• Authentication Method: Select Pre-Shared Key to use a password or Certificate to use one
of the ZyWALL’s certificates.
4.3.9 VPN Advanced Wizard - Phase 2
Phase 2 in an IKE uses the SA that was established in phase 1 to negotiate SAs for IPSec.
Figure 38
VPN Advanced Wizard: Step 4
• Active Protocol: ESP is compatible with NAT, AH is not.
• Encapsulation: Tunnel is compatible with NAT, Transport is not.
• Encryption Algorithm: 3DES and AES use encryption. The longer the AES key, the higher the
security (this may affect throughput). Null uses no encryption.
• Authentication Algorithm: MD5 gives minimal security and SHA512 gives the highest
security. MD5 (Message Digest 5) and SHA (Secure Hash Algorithm) are hash algorithms used to
authenticate packet data. The stronger the algorithm the slower it is.
• SA Life Time: Set how often the ZyWALL renegotiates the IKE SA. A short SA life time increases
security, but renegotiation temporarily disconnects the VPN tunnel.
• Perfect Forward Secrecy (PFS): Disabling PFS allows faster IPSec setup, but is less secure.
Select DH1, DH2 or DH5 to enable PFS. DH5 is more secure than DH1 or DH2 (although it may
affect throughput). DH1 refers to Diffie-Hellman Group 1 a 768 bit random number. DH2 refers to
Diffie-Hellman Group 2 a 1024 bit (1Kb) random number. DH5 refers to Diffie-Hellman Group 5 a
1536 bit random number (more secure, yet slower).
• Local Policy (IP/Mask): Type the IP address of a computer on your network. You can also
specify a subnet. This must match the remote IP address configured on the remote IPSec device.
• Remote Policy (IP/Mask): Type the IP address of a computer behind the remote IPSec device.
You can also specify a subnet. This must match the local IP address configured on the remote
IPSec device.
• Nailed-Up: This displays for the site-to-site and remote access client role scenarios. Select this
to have the ZyWALL automatically renegotiate the IPSec SA when the SA life time expires.
Содержание ZyWALL 110 Series
Страница 16: ...ZyWALL 110 310 1100 Series User s Guide 16...
Страница 32: ...Chapter 1 Introduction ZyWALL 110 310 1100 Series User s Guide 32...
Страница 42: ...Chapter 3 Hardware Introduction ZyWALL 110 310 1100 Series User s Guide 42...
Страница 68: ...Chapter 4 Quick Setup Wizards ZyWALL 110 310 1100 Series User s Guide 68...
Страница 83: ...Chapter 6 Monitor ZyWALL 110 310 1100 Series User s Guide 83 Figure 60 Monitor System Status Interface Status...
Страница 128: ...Chapter 7 Interfaces ZyWALL 110 310 1100 Series User s Guide 128 Figure 83 Configuration Network Interface PPP Add...
Страница 135: ...Chapter 7 Interfaces ZyWALL 110 310 1100 Series User s Guide 135 Figure 85 Configuration Network Interface Cellular Add...
Страница 176: ...Chapter 7 Interfaces ZyWALL 110 310 1100 Series User s Guide 176...
Страница 186: ...Chapter 8 Trunk ZyWALL 110 310 1100 Series User s Guide 186...
Страница 210: ...Chapter 10 Routing Protocols ZyWALL 110 310 1100 Series User s Guide 210...
Страница 220: ...Chapter 12 DDNS ZyWALL 110 310 1100 Series User s Guide 220...
Страница 228: ...Chapter 13 NAT ZyWALL 110 310 1100 Series User s Guide 228...
Страница 240: ...Chapter 15 ALG ZyWALL 110 310 1100 Series User s Guide 240...
Страница 246: ...Chapter 16 IP MAC Binding ZyWALL 110 310 1100 Series User s Guide 246...
Страница 263: ...Chapter 18 Authentication Policy ZyWALL 110 310 1100 Series User s Guide 263...
Страница 264: ...Chapter 18 Authentication Policy ZyWALL 110 310 1100 Series User s Guide 264...
Страница 270: ...Chapter 19 Firewall ZyWALL 110 310 1100 Series User s Guide 270 Figure 163 Configuration Firewall...
Страница 296: ...Chapter 20 IPSec VPN ZyWALL 110 310 1100 Series User s Guide 296 Figure 182 Configuration VPN IPSec VPN VPN Gateway Edit...
Страница 316: ...Chapter 20 IPSec VPN ZyWALL 110 310 1100 Series User s Guide 316...
Страница 340: ...Chapter 22 SSL User Screens ZyWALL 110 310 1100 Series User s Guide 340...
Страница 442: ...Chapter 36 DHCPv6 ZyWALL 110 310 1100 Series User s Guide 442...
Страница 540: ...Appendix A Legal Information ZyWALL 110 310 1100 Series User s Guide 540...
Страница 558: ...Index ZyWALL 110 310 1100 Series User s Guide 558...
Страница 559: ...Index ZyWALL 110 310 1100 Series User s Guide 559...
Страница 560: ...Index ZyWALL 110 310 1100 Series User s Guide 560...
Страница 561: ...Index ZyWALL 110 310 1100 Series User s Guide 561...
Страница 562: ...Index ZyWALL 110 310 1100 Series User s Guide 562...