ZyXEL SBG3300-NB00 User Guide - Page 281

Connection Name, NAT Traversal NAT-T, Application Scenario, Remote, Access, Site-to-Site, Site-to-

Page 281 highlights

Chapter 20 IPSec VPN Table 90 VPN > IPSec VPN > Setup > Edit (continued) LABEL DESCRIPTION Connection Name Enter a name to identify this VPN policy. If you are editing an existing policy, this field is not editable. Nailed-up Note: The Connection Name of an IPsec rule must be unique and cannot be changed once it has been created. Select this if you want the Device to automatically renegotiate the IPSec SA when the VPN connection is down. This feature is only applicable if you set the Application Scenario to Site-to-Site. NAT Traversal (NATT) When Nailed-up is enabled, you cannot disconnect the specified IPsec VPN tunnel in the VPN > IPSec VPN > Monitor screen. Select this check box to enable NAT traversal. NAT traversal allows you to set up a VPN connection when there are NAT routers between the two IPSec routers. The remote IPSec router must also have NAT traversal enabled. You can use NAT traversal with ESP protocol using Transport or Tunnel mode, but not with AH protocol nor with manual key management. In order for an IPSec router behind a NAT router to receive an initiating IPSec packet, set the NAT router to forward UDP ports 500 and 4500 to the IPSec router behind the NAT router. Application Scenario Note: It is suggested to always enable the NAT Traversal (NAT-T) feature if you are not sure if a NAT device is connected to your VPN gateway. Once this feature is enabled, it will automatically detect connected NAT devices for you. Select the scenario that best describes your intended VPN connection. Site-to-Site - Choose this if the remote IPSec router has a static IP address or a domain name. This Device can initiate the VPN tunnel. Site-to-Site with Dynamic Peer - Choose this if the remote IPSec router has a dynamic IP address. Only the remote IPSec router can initiate the VPN tunnel. My Address Remote Access - Choose this to allow incoming connections from IPSec VPN clients. The clients have dynamic IP addresses and are also known as dial-in users. Only the clients can initiate the VPN tunnel. Select an interface from the drop-down list and its IP address will be shown. The IP address of the Device is the IP address of the interface. Peer Gateway Address Authentication Note: Only choose Any when the Application Scenario is configured as Remote Access. It is not applicable to Site-to-Site and Site-to-Site with Dynamic Peer. This field is applicable only if you choose Site-to-Site in the Application Scenario field. The peer gateway address can be either an IP address or FQDN. Note: The Device and remote IPSec router must use the same authentication method to establish the IKE SA. Key Exchange Mode When this field is set to Manual, the specified IPsec VPN tunnel will be considered as connected at any time. You cannot disconnect the specified IPsec VPN tunnel in the IPsec Monitor screen. SBG3300-N Series User's Guide 281

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248
  • 249
  • 250
  • 251
  • 252
  • 253
  • 254
  • 255
  • 256
  • 257
  • 258
  • 259
  • 260
  • 261
  • 262
  • 263
  • 264
  • 265
  • 266
  • 267
  • 268
  • 269
  • 270
  • 271
  • 272
  • 273
  • 274
  • 275
  • 276
  • 277
  • 278
  • 279
  • 280
  • 281
  • 282
  • 283
  • 284
  • 285
  • 286
  • 287
  • 288
  • 289
  • 290
  • 291
  • 292
  • 293
  • 294
  • 295
  • 296
  • 297
  • 298
  • 299
  • 300
  • 301
  • 302
  • 303
  • 304
  • 305
  • 306
  • 307
  • 308
  • 309
  • 310
  • 311
  • 312
  • 313
  • 314
  • 315
  • 316
  • 317
  • 318
  • 319
  • 320
  • 321
  • 322
  • 323
  • 324
  • 325
  • 326
  • 327
  • 328
  • 329
  • 330
  • 331
  • 332
  • 333
  • 334
  • 335
  • 336
  • 337
  • 338
  • 339
  • 340
  • 341
  • 342
  • 343
  • 344
  • 345
  • 346
  • 347
  • 348
  • 349
  • 350
  • 351
  • 352
  • 353
  • 354
  • 355
  • 356
  • 357
  • 358
  • 359
  • 360
  • 361
  • 362
  • 363
  • 364
  • 365
  • 366
  • 367
  • 368
  • 369
  • 370
  • 371
  • 372
  • 373
  • 374
  • 375
  • 376
  • 377
  • 378
  • 379
  • 380
  • 381
  • 382
  • 383
  • 384
  • 385
  • 386
  • 387
  • 388
  • 389
  • 390
  • 391
  • 392
  • 393
  • 394
  • 395
  • 396
  • 397
  • 398
  • 399
  • 400
  • 401
  • 402
  • 403
  • 404
  • 405
  • 406
  • 407
  • 408
  • 409
  • 410
  • 411
  • 412
  • 413
  • 414
  • 415
  • 416
  • 417
  • 418
  • 419
  • 420
  • 421
  • 422
  • 423
  • 424
  • 425
  • 426
  • 427
  • 428
  • 429
  • 430
  • 431
  • 432
  • 433
  • 434
  • 435
  • 436
  • 437
  • 438
  • 439
  • 440
  • 441
  • 442

Chapter 20 IPSec VPN
SBG3300-N Series User’s Guide
281
Connection Name
Enter a name to identify this VPN policy. If you are editing an existing policy, this field is
not editable.
Note: The
Connection Name
of an IPsec rule must be unique and cannot be changed
once it has been created.
Nailed-up
Select this if you want the Device to automatically renegotiate the IPSec SA when the
VPN connection is down.
This feature is only applicable if you set the
Application Scenario
to
Site-to-Site
.
When
Nailed-up
is enabled, you cannot disconnect the specified IPsec VPN tunnel in
the
VPN
>
IPSec VPN
>
Monitor
screen.
NAT Traversal (NAT-
T)
Select this check box to enable NAT traversal. NAT traversal allows you to set up a VPN
connection when there are NAT routers between the two IPSec routers.
The remote IPSec router must also have NAT traversal enabled.
You can use NAT traversal with
ESP
protocol using
Transport
or
Tunnel
mode, but not
with
AH
protocol nor with manual key management. In order for an IPSec router
behind a NAT router to receive an initiating IPSec packet, set the NAT router to forward
UDP ports 500 and 4500 to the IPSec router behind the NAT router.
Note: It is suggested to always enable the
NAT Traversal (NAT-T)
feature if you are not
sure if a NAT device is connected to your VPN gateway. Once this feature is
enabled, it will automatically detect connected NAT devices for you.
Application Scenario
Select the scenario that best describes your intended VPN connection.
Site-to-Site
- Choose this if the remote IPSec router has a static IP address or a
domain name. This Device can initiate the VPN tunnel.
Site-to-Site with Dynamic Peer
- Choose this if the remote IPSec router has a
dynamic IP address. Only the remote IPSec router can initiate the VPN tunnel.
Remote Access
- Choose this to allow incoming connections from IPSec VPN clients.
The clients have dynamic IP addresses and are also known as dial-in users. Only the
clients can initiate the VPN tunnel.
My Address
Select an interface from the drop-down list and its IP address will be shown. The IP
address of the Device is the IP address of the interface.
Note: Only choose
Any
when the
Application Scenario
is configured as
Remote
Access
. It is not applicable to
Site-to-Site
and
Site-to-Site with Dynamic Peer
.
Peer Gateway
Address
This field is applicable only if you choose
Site-to-Site
in the
Application Scenario
field. The peer gateway address can be either an IP address or FQDN.
Authentication
Note: The Device and remote IPSec router must use the same authentication method
to establish the IKE SA.
Key Exchange Mode
When this field is set to
Manual
, the specified IPsec VPN tunnel will be considered as
connected at any time. You cannot disconnect the specified IPsec VPN tunnel in the
IPsec Monitor
screen.
Table 90
VPN > IPSec VPN > Setup > Edit (continued)
LABEL
DESCRIPTION