ZyWALL 70 User’s Guide
Chapter 14 VPN Screens
247
The following table describes the labels in this screen.
Table 74
VPN Rules (IKE): Gateway Policy: Edit
LABEL
DESCRIPTION
Property
Name
Type up to 32 characters to identify this VPN gateway policy. You may use any
character, including spaces, but the ZyWALL drops trailing spaces.
NAT Traversal
Select this check box to enable NAT traversal. NAT traversal allows you to set up
a VPN connection when there are NAT routers between the two IPSec routers.
Note:
The remote IPSec router must also have NAT traversal
enabled. See
information.
You can use NAT traversal with
ESP
protocol using
Transport
or
Tunnel
mode,
but not with
AH
protocol nor with manual key management. In order for an IPSec
router behind a NAT router to receive an initiating IPSec packet, set the NAT
router to forward UDP port 500 to the IPSec router behind the NAT router.
Gateway Policy
Information
My ZyWALL
This field identifies the WAN IP address or domain name of the ZyWALL. You can
select
My Address
and enter the ZyWALL's static WAN IP address (if it has one)
or leave the field set to 0.0.0.0.
The following applies if the
My ZyWALL
field is configured as
0.0.0.0
:
•
When the WAN port operation mode is set to
Active/Passive
, the ZyWALL
uses the IP address (static or dynamic) of the WAN port that is in use.
•
When the WAN port operation mode is set to
Active/Active
, the ZyWALL
uses the IP address (static or dynamic) of the primary (highest priority) WAN
port to set up the VPN tunnel as long as the corresponding WAN1 or WAN2
connection is up. If the corresponding WAN1 or WAN2 connection goes down,
the ZyWALL uses the IP address of the other WAN port.
•
If both WAN connections go down, the ZyWALL uses the dial backup IP
address for the VPN tunnel when using dial backup or the LAN IP address
when using traffic redirect. See the chapter on WAN for details on dial backup
and traffic redirect.
Otherwise you can select
My Domain Name
and choose one of the dynamic
domain names that you have configured (in the
DDNS
screen) to have the
ZyWALL use that dynamic domain name's IP address.
The VPN tunnel has to be rebuilt if the
My ZyWALL
IP address changes after
setup.
Remote Gateway
Address
Type the WAN IP address or the domain name (up to 31 characters) of the IPSec
router with which you're making the VPN connection. Set this field to
0.0.0.0
if the
remote IPSec router has a dynamic WAN IP address.
In order to have more than one active rule with the
Remote Gateway Address
field set to
0.0.0.0
, the ranges of the local IP addresses cannot overlap between
rules.
If you configure an active rule with
0.0.0.0
in the
Remote Gateway Address
field
and the LAN’s full IP address range as the local IP address, then you cannot
configure any other active rules with the
Remote Gateway Address
field set to
0.0.0.0
.
Authentication Key
Содержание ZyWALL 70
Страница 1: ...ZyWALL 70 Internet Security Appliance User s Guide Version 3 64 3 2005 ...
Страница 2: ......
Страница 38: ...ZyWALL 70 User s Guide 38 List of Figures ...
Страница 46: ...ZyWALL 70 User s Guide 46 List of Tables ...
Страница 74: ...ZyWALL 70 User s Guide 74 Chapter 2 Introducing the Web Configurator ...
Страница 92: ...ZyWALL 70 User s Guide 92 Chapter 3 Wizard Setup ...
Страница 102: ...ZyWALL 70 User s Guide 102 Chapter 4 LAN Screens ...
Страница 108: ...ZyWALL 70 User s Guide 108 Chapter 5 Bridge Screens ...
Страница 130: ...ZyWALL 70 User s Guide 130 Chapter 6 Wireless LAN ...
Страница 136: ...ZyWALL 70 User s Guide 136 Chapter 7 WAN Screens Figure 45 WAN General ...
Страница 155: ...ZyWALL 70 User s Guide Chapter 7 WAN Screens 155 Figure 55 Dial Backup Setup ...
Страница 188: ...ZyWALL 70 User s Guide 188 Chapter 10 Firewall Screens Figure 71 Creating Editing A Firewall Rule ...
Страница 193: ...ZyWALL 70 User s Guide Chapter 10 Firewall Screens 193 Figure 76 My Service Rule Configuration ...
Страница 234: ...ZyWALL 70 User s Guide 234 Chapter 13 Introduction to IPSec ...
Страница 246: ...ZyWALL 70 User s Guide 246 Chapter 14 VPN Screens Figure 112 VPN Rules IKE Gateway Policy Edit ...
Страница 252: ...ZyWALL 70 User s Guide 252 Chapter 14 VPN Screens Figure 113 VPN Rules IKE Network Policy Edit ...
Страница 275: ...ZyWALL 70 User s Guide Chapter 15 Certificates 275 Figure 125 My Certificate Details ...
Страница 294: ...ZyWALL 70 User s Guide 294 Chapter 16 Authentication Server Figure 136 Local User Database ...
Страница 314: ...ZyWALL 70 User s Guide 314 Chapter 17 Network Address Translation NAT ...
Страница 318: ...ZyWALL 70 User s Guide 318 Chapter 18 Static Route ...
Страница 324: ...ZyWALL 70 User s Guide 324 Chapter 19 Policy Route ...
Страница 340: ...ZyWALL 70 User s Guide 340 Chapter 20 Bandwidth Management ...
Страница 376: ...ZyWALL 70 User s Guide 376 Chapter 22 Remote Management ...
Страница 390: ...ZyWALL 70 User s Guide 390 Chapter 24 Logs Screens Figure 194 Log Settings ...
Страница 413: ...ZyWALL 70 User s Guide Chapter 25 Maintenance 413 Figure 216 Restart Screen ...
Страница 414: ...ZyWALL 70 User s Guide 414 Chapter 25 Maintenance ...
Страница 440: ...ZyWALL 70 User s Guide 440 Chapter 28 WAN and Dial Backup Setup ...
Страница 456: ...ZyWALL 70 User s Guide 456 Chapter 31 DMZ Setup ...
Страница 460: ...ZyWALL 70 User s Guide 460 Chapter 32 Route Setup ...
Страница 470: ...ZyWALL 70 User s Guide 470 Chapter 33 Remote Node Setup ...
Страница 522: ...ZyWALL 70 User s Guide 522 Chapter 39 System Information Diagnosis ...
Страница 538: ...ZyWALL 70 User s Guide 538 Chapter 40 Firmware and Configuration File Maintenance ...
Страница 550: ...ZyWALL 70 User s Guide 550 Chapter 42 Remote Management ...
Страница 558: ...ZyWALL 70 User s Guide 558 Chapter 43 IP Policy Routing ...
Страница 573: ...ZyWALL 70 User s Guide Chapter 45 Troubleshooting 573 Figure 360 Java Sun ...
Страница 574: ...ZyWALL 70 User s Guide 574 Chapter 45 Troubleshooting ...
Страница 582: ...ZyWALL 70 User s Guide 582 Appendix B Removing and Installing a Fuse ...
Страница 602: ...ZyWALL 70 User s Guide 602 Appendix D IP Subnetting ...
Страница 608: ...ZyWALL 70 User s Guide 608 Appendix F PPTP ...
Страница 626: ...ZyWALL 70 User s Guide 626 Appendix H Triangle Route ...
Страница 656: ...ZyWALL 70 User s Guide 656 Appendix K Importing Certificates ...
Страница 658: ...ZyWALL 70 User s Guide 658 Appendix L Command Interpreter ...
Страница 664: ...ZyWALL 70 User s Guide 664 Appendix M Firewall Commands ...
Страница 668: ...ZyWALL 70 User s Guide 668 Appendix N NetBIOS Filter Commands ...
Страница 674: ...ZyWALL 70 User s Guide 674 Appendix P Brute Force Password Guessing Protection ...
Страница 696: ...ZyWALL 70 User s Guide 696 Appendix R Log Descriptions ...