![ZyXEL Communications ZyWALL SSL 10 Скачать руководство пользователя страница 62](http://html1.mh-extra.com/html/zyxel-communications/zywall-ssl-10/zywall-ssl-10_support-notes_943794062.webp)
ZyWALL SSL 10 Support Notes
62
All contents copyright (c) 2006 ZyXEL Communications Corporation.
1)
UDP 500 (IKE) must be forwarded to ZyWALL to accept incoming VPN connection
from peer VPN gateway or client.
2)
If Firewall is running on the same NAT router, make sure a firewall rule is configured to
allow IKE/IPSec (AH/ESP) traffic to pass-through.
VPN->VPN Rule (IKE) on ZyWALL
VPN->VPN Rule (IKE) on ZyWALL
Configuration on Peer VPN gateway
Configuration on Local ZyWALL
VPN->VPN Rule (IKE) on ZyWALL
WAN->WAN1 or WAN2
3
4
5
6
3)
On ZyWALL, enable “
NAT Traversal
” no matter if the front NAT router supports NAT
Traversal (IPSec pass-through) or not. With this option enabled, ZyWALL can detect if
it is placed behind NAT when peer VPN entity also support NAT Traversal function. If
yes, the IPSec traffic will be encapsulated in UDP packet to avoid traversal problem on
NAT routers.
4)
Under
VPN->Gateway Policy-> Gateway Policy Information
configure the
private
IP address
as “
My Address
” on local ZyWALL gateway (behind NAT router).
Содержание ZyWALL SSL 10
Страница 13: ...ZyWALL SSL 10 Support Notes 13 All contents copyright c 2006 ZyXEL Communications Corporation ...
Страница 36: ...ZyWALL SSL 10 Support Notes 36 All contents copyright c 2006 ZyXEL Communications Corporation ...
Страница 55: ...ZyWALL SSL 10 Support Notes 55 All contents copyright c 2006 ZyXEL Communications Corporation ...