ZyXEL NBG-460N User Guide - Page 204

Table 67

Page 204 highlights

Chapter 15 IPSec VPN Table 67 Security > VPN > General > Rule Setup: Manual (continued) LABEL DESCRIPTION Remote Address For a single IP address, enter a (static) IP address on the network behind the remote IPSec router. For a specific range of IP addresses, enter the beginning (static) IP address, in a range of computers on the network behind the remote IPSec router. Remote Address End / Mask To specify IP addresses on a network by their subnet mask, enter a (static) IP address on the network behind the remote IPSec router. When the remote IP address is a single address, type it a second time here. When the remote IP address is a range, enter the end (static) IP address, in a range of computers on the network behind the remote IPSec router. Remote Port Start Remote Port End My IP Address When the remote IP address is a subnet address, enter a subnet mask on the network behind the remote IPSec router. 0 is the default and signifies any port. Type a port number from 0 to 65535. Some of the most common IP ports are: 21, FTP; 53, DNS; 23, Telnet; 80, HTTP; 25, SMTP; 110, POP3. Enter a port number in this field to define a port range. This port number must be greater than that specified in the previous field. If Remote Port Start is left at 0, Remote Port End will also remain at 0. Enter the NBG-460N's static WAN IP address (if it has one) or leave the field set to 0.0.0.0. The NBG-460N uses its current WAN IP address (static or dynamic) in setting up the VPN tunnel if you leave this field as 0.0.0.0. If the WAN connection goes down, the NBG-460N uses the dial backup IP address for the VPN tunnel when using dial backup or the LAN IP address when using traffic redirect. Otherwise, you can enter one of the dynamic domain names that you have configured (in the DDNS screen) to have the NBG-460N use that dynamic domain name's IP address. Secure Gateway Address SPI Encapsulation Mode Enable Replay Detection The VPN tunnel has to be rebuilt if My IP Address changes after setup. Type the WAN IP address or the domain name (up to 31 characters) of the IPSec router with which you're making the VPN connection. Type a unique SPI (Security Parameter Index) from one to four characters long. Valid Characters are "0, 1, 2, 3, 4, 5, 6, 7, 8, and 9". Select Tunnel mode or Transport mode from the drop-down list box. As a VPN setup is processing intensive, the system is vulnerable to Denial of Service (DoS) attacks The IPSec receiver can detect and reject old or duplicate packets to protect against replay attacks. Select Yes from the drop-down menu to enable replay detection, or select No to disable it. 204 NBG-460N User's Guide

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248
  • 249
  • 250
  • 251
  • 252
  • 253
  • 254
  • 255
  • 256
  • 257
  • 258
  • 259
  • 260
  • 261
  • 262
  • 263
  • 264
  • 265
  • 266
  • 267
  • 268
  • 269
  • 270
  • 271
  • 272
  • 273
  • 274
  • 275
  • 276
  • 277
  • 278
  • 279
  • 280
  • 281
  • 282
  • 283
  • 284
  • 285
  • 286
  • 287
  • 288
  • 289
  • 290
  • 291
  • 292
  • 293
  • 294
  • 295
  • 296
  • 297
  • 298
  • 299
  • 300
  • 301
  • 302
  • 303
  • 304
  • 305
  • 306
  • 307
  • 308
  • 309
  • 310
  • 311
  • 312
  • 313
  • 314
  • 315
  • 316
  • 317
  • 318
  • 319
  • 320
  • 321
  • 322
  • 323
  • 324
  • 325
  • 326
  • 327
  • 328
  • 329
  • 330
  • 331
  • 332
  • 333
  • 334
  • 335
  • 336
  • 337
  • 338
  • 339
  • 340
  • 341
  • 342
  • 343
  • 344
  • 345
  • 346
  • 347
  • 348
  • 349
  • 350
  • 351
  • 352
  • 353
  • 354
  • 355
  • 356
  • 357
  • 358
  • 359
  • 360
  • 361
  • 362
  • 363
  • 364
  • 365
  • 366
  • 367
  • 368
  • 369
  • 370

Chapter 15 IPSec VPN
NBG-460N User’s Guide
204
Remote
Address
For a single IP address, enter a (static) IP address on the network
behind the remote IPSec router.
For a specific range of IP addresses, enter the beginning (static) IP
address, in a range of computers on the network behind the remote
IPSec router.
To specify IP addresses on a network by their subnet mask, enter a
(static) IP address on the network behind the remote IPSec router.
Remote
Address End /
Mask
When the remote IP address is a single address, type it a second time
here.
When the remote IP address is a range, enter the end (static) IP
address, in a range of computers on the network behind the remote
IPSec router.
When the remote IP address is a subnet address, enter a subnet mask
on the network behind the remote IPSec router.
Remote Port
Start
0 is the default and signifies any port. Type a port number from 0 to
65535. Some of the most common IP ports are: 21, FTP; 53, DNS; 23,
Telnet; 80, HTTP; 25, SMTP; 110, POP3.
Remote Port
End
Enter a port number in this field to define a port range. This port
number must be greater than that specified in the previous field. If
Remote Port Start
is left at 0,
Remote Port End
will also remain at 0.
My IP Address
Enter the NBG-460N's static WAN IP address (if it has one) or leave the
field set to
0.0.0.0
.
The NBG-460N uses its current WAN IP address (static or dynamic) in
setting up the VPN tunnel if you leave this field as
0.0.0.0
. If the WAN
connection goes down, the NBG-460N uses the dial backup IP address
for the VPN tunnel when using dial backup or the LAN IP address when
using traffic redirect.
Otherwise, you can enter one of the dynamic domain names that you
have configured (in the
DDNS
screen) to have the NBG-460N use that
dynamic domain name's IP address.
The VPN tunnel has to be rebuilt if
My IP Address
changes after setup.
Secure
Gateway
Address
Type the WAN IP address or the domain name (up to 31 characters) of
the IPSec router with which you're making the VPN connection.
SPI
Type a unique
SPI
(Security Parameter Index) from one to four
characters long. Valid Characters are "0, 1, 2, 3, 4, 5, 6, 7, 8, and 9".
Encapsulation
Mode
Select
Tunnel
mode or
Transport
mode from the drop-down list box.
Enable Replay
Detection
As a VPN setup is processing intensive, the system is vulnerable to
Denial of Service (DoS) attacks The IPSec receiver can detect and reject
old or duplicate packets to protect against replay attacks. Select
Yes
from the drop-down menu to enable replay detection, or select
No
to
disable it.
Table 67
Security > VPN > General > Rule Setup: Manual (continued)
LABEL
DESCRIPTION