ZyWALL P1 User’s Guide
138
Chapter 9 VPN Screens
Peer ID Type
Select from the following when you set
Authentication Method
to
Pre-shared
Key
.
•
Select
IP
to identify the remote IPSec router by its IP address.
•
Select
DNS
to identify the remote IPSec router by a domain name.
•
Select
to identify the remote IPSec router by an e-mail address.
Select from the following when you set
Authentication Method
to
Certificate
.
•
Select
IP
to identify the remote IPSec router by the IP address in the subject
alternative name field of the certificate it uses for this VPN connection.
•
Select
DNS
to identify the remote IPSec router by the domain name in the
subject alternative name field of the certificate it uses for this VPN connection.
•
Select
to identify the remote IPSec router by the e-mail address in the
subject alternative name field of the certificate it uses for this VPN connection.
•
Select
Subject Name
to identify the remote IPSec router by the subject name
of the certificate it uses for this VPN connection.
•
Select
Any
to have the ZyWALL not check the remote IPSec router's ID.
Content
The configuration of the peer content depends on the peer ID type.
Do the following when you set
Authentication Method
to
Pre-shared Key
.
•
For
IP
, type the IP address of the computer with which you will make the VPN
connection. If you configure this field to
0.0.0.0
or leave it blank, the ZyWALL
will use the address in the
Remote Gateway Address
field (refer to the
Remote Gateway Address
field description).
•
For
DNS
or
, type a domain name or e-mail address by which to identify
the remote IPSec router. Use up to 31 ASCII characters including spaces,
although trailing spaces are truncated. The domain name or e-mail address is
for identification purposes only and can be any string.
It is recommended that you type an IP address other than
0.0.0.0
or use the
DNS
or
ID type in the following situations:
•
When there is a NAT router between the two IPSec routers.
•
When you want the ZyWALL to distinguish between VPN connection requests
that come in from remote IPSec routers with dynamic WAN IP addresses.
Do the following when you set
Authentication Method
to
Certificate
.
•
For
IP
, type the IP address from the subject alternative name field of the
certificate the remote IPSec router will use for this VPN connection. If you
configure this field to
0.0.0.0
or leave it blank, the ZyWALL will use the
address in the
Remote Gateway Address
field (refer to the
Remote
Gateway Address
field description).
•
For
DNS
or
, type the domain name or e-mail address from the subject
alternative name field of the certificate the remote IPSec router will use for this
VPN connection.
•
For
Subject Name
, type the subject name of the certificate the remote IPSec
router will use for this VPN connection. Use up to255 ASCII characters
including spaces.
•
For
Any
, the peer
Content
field is not available.
•
Regardless of how you configure the
ID Type
and
Content
fields, two active
SAs cannot have both the local and remote IP address ranges overlap
between rules.
Authentication for
Activating VPN
Confiugre the fields below to set the authentication method the ZyWALL uses to
allow a user to activate a VPN connection.
Table 43
VPN Rules (IKE): Gateway Policy (continued)
LABEL
DESCRIPTION
Содержание ZyXEL ZyWALL P1
Страница 1: ...ZyWALL P1 Internet Security Appliance User s Guide Version 3 64 8 2005...
Страница 9: ...ZyWALL P1 User s Guide 8 Customer Support...
Страница 25: ...ZyWALL P1 User s Guide 24 List of Figures...
Страница 39: ...ZyWALL P1 User s Guide 38 Chapter 1 Getting to Know Your ZyWALL...
Страница 51: ...ZyWALL P1 User s Guide 50 Chapter 2 Introducing the Web Configurator...
Страница 72: ...ZyWALL P1 User s Guide Chapter 3 Wizard Setup 71 Figure 22 VPN Wizard Complete...
Страница 73: ...ZyWALL P1 User s Guide 72 Chapter 3 Wizard Setup...
Страница 91: ...ZyWALL P1 User s Guide 90 Chapter 5 WAN Screens...
Страница 116: ...ZyWALL P1 User s Guide Chapter 7 Firewall Screens 115 Figure 44 Firewall Example My Service Rule Configuration...
Страница 129: ...ZyWALL P1 User s Guide 128 Chapter 8 Introduction to IPSec...
Страница 151: ...ZyWALL P1 User s Guide 150 Chapter 9 VPN Screens...
Страница 191: ...ZyWALL P1 User s Guide 190 Chapter 12 Static Route...
Страница 215: ...ZyWALL P1 User s Guide 214 Chapter 13 Remote Management...
Страница 248: ...ZyWALL P1 User s Guide Chapter 16 Maintenance 247 Figure 134 Restart Screen...
Страница 249: ...ZyWALL P1 User s Guide 248 Chapter 16 Maintenance...
Страница 269: ...ZyWALL P1 User s Guide 268 Chapter 18 Troubleshooting...
Страница 289: ...ZyWALL P1 User s Guide 288 Appendix B IP Subnetting...
Страница 295: ...ZyWALL P1 User s Guide 294 Appendix D PPTP...
Страница 299: ...ZyWALL P1 User s Guide 298 Appendix E Triangle Route...
Страница 329: ...ZyWALL P1 User s Guide 328 Appendix H Importing Certificates...
Страница 331: ...ZyWALL P1 User s Guide 330 Appendix I Command Interpreter...
Страница 337: ...ZyWALL P1 User s Guide 336 Appendix J Firewall Commands...
Страница 341: ...ZyWALL P1 User s Guide 340 Appendix K NetBIOS Filter Commands...
Страница 347: ...ZyWALL P1 User s Guide 346 Appendix M Brute Force Password Guessing Protection...
Страница 369: ...ZyWALL P1 User s Guide 368 Index X X Auth 132 Z ZyNOS 250 ZyXEL Limited Warranty Note 4 ZyXEL s Firewall Introduction 92...