ZyXEL SBG3300-NB00 User Guide - Page 282

User-FQDN, Local ID Type, Remote ID Type, Negotiation Mode, Pre-Shared Key, Table 90, LABEL,

Page 282 highlights

Chapter 20 IPSec VPN Table 90 VPN > IPSec VPN > Setup > Edit (continued) LABEL Pre-Shared Key DESCRIPTION Select this to have the Device and remote IPSec router use a pre-shared key (password) to identify each other when they negotiate the IKE SA. Type the pre-shared key in the field to the right. The pre-shared key can be • 8 - 32 alphanumeric characters or 8 - 32 pairs of hexadecimal (0-9, A-F) characters, preceded by "0x". If you want to enter the key in hexadecimal, type "0x" at the beginning of the key. For example, "0x0123456789ABCDEF" is in hexadecimal format; in "0123456789ABCDEF" is in ASCII format. If you use hexadecimal, you must enter twice as many characters since you need to enter pairs. The Device and remote IPSec router must use the same pre-shared key. Certificate Note: All remote access application scenario of IPsec rules must use the same preshared key. In order to use Certificate for IPsec authentication, you need to add new host certificates in the Security > Certificates screen. See a tutorial on how to add new host certificates in Chapter 4 on page 57. Select this to have the Device and remote IPSec router use certificates to authenticate each other when they negotiate the IKE SA. Then select the certificate the Device uses to identify itself to the remote IPsec router. This certificate is one of the certificates in Certificates. If this certificate is self-signed, import it into the remote IPsec router. If this certificate is signed by a CA, the remote IPsec router must trust that CA. Local/Remote ID Type Note: The IPSec routers must trust each other's certificates. The Device uses one of its Trusted Certificates to authenticate the remote IPSec router's certificate. The trusted certificate can be a self-signed certificate or that of a trusted CA that signed the remote IPSec router's certificate. Select which type of identification is used to identify the Device during authentication. Any - The Device does not check the identity of the itself/remote IPSec router. IP - The Device/remote IPSec router is identified by its IP address. FQDN - The Device/remote IPSec router is identified by a domain name. User-FQDN - The Device/remote IPSec router is identified by an e-mail address. Local/Remote ID Content Note: The options FQDN and User-FQDN of Local ID Type and Remote ID Type are not applicable if you select Main as the Negotiation Mode with Pre-Shared Key. When you select IP in the Local/Remote ID Type field, type the IP address of your computer in the Local/Remote ID Content field. When you select FQDN or User-FQDN in the Local/Remote ID Type field, type a domain name or e-mail address by which to identify this Device in the Local/Remote ID Content field. 282 SBG3300-N Series User's Guide

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248
  • 249
  • 250
  • 251
  • 252
  • 253
  • 254
  • 255
  • 256
  • 257
  • 258
  • 259
  • 260
  • 261
  • 262
  • 263
  • 264
  • 265
  • 266
  • 267
  • 268
  • 269
  • 270
  • 271
  • 272
  • 273
  • 274
  • 275
  • 276
  • 277
  • 278
  • 279
  • 280
  • 281
  • 282
  • 283
  • 284
  • 285
  • 286
  • 287
  • 288
  • 289
  • 290
  • 291
  • 292
  • 293
  • 294
  • 295
  • 296
  • 297
  • 298
  • 299
  • 300
  • 301
  • 302
  • 303
  • 304
  • 305
  • 306
  • 307
  • 308
  • 309
  • 310
  • 311
  • 312
  • 313
  • 314
  • 315
  • 316
  • 317
  • 318
  • 319
  • 320
  • 321
  • 322
  • 323
  • 324
  • 325
  • 326
  • 327
  • 328
  • 329
  • 330
  • 331
  • 332
  • 333
  • 334
  • 335
  • 336
  • 337
  • 338
  • 339
  • 340
  • 341
  • 342
  • 343
  • 344
  • 345
  • 346
  • 347
  • 348
  • 349
  • 350
  • 351
  • 352
  • 353
  • 354
  • 355
  • 356
  • 357
  • 358
  • 359
  • 360
  • 361
  • 362
  • 363
  • 364
  • 365
  • 366
  • 367
  • 368
  • 369
  • 370
  • 371
  • 372
  • 373
  • 374
  • 375
  • 376
  • 377
  • 378
  • 379
  • 380
  • 381
  • 382
  • 383
  • 384
  • 385
  • 386
  • 387
  • 388
  • 389
  • 390
  • 391
  • 392
  • 393
  • 394
  • 395
  • 396
  • 397
  • 398
  • 399
  • 400
  • 401
  • 402
  • 403
  • 404
  • 405
  • 406
  • 407
  • 408
  • 409
  • 410
  • 411
  • 412
  • 413
  • 414
  • 415
  • 416
  • 417
  • 418
  • 419
  • 420
  • 421
  • 422
  • 423
  • 424
  • 425
  • 426
  • 427
  • 428
  • 429
  • 430
  • 431
  • 432
  • 433
  • 434
  • 435
  • 436
  • 437
  • 438
  • 439
  • 440
  • 441
  • 442

Chapter 20 IPSec VPN
SBG3300-N Series User’s Guide
282
Pre-Shared Key
Select this to have the Device and remote IPSec router use a pre-shared key
(password) to identify each other when they negotiate the IKE SA. Type the pre-shared
key in the field to the right. The pre-shared key can be
8 - 32 alphanumeric characters or ,;|`~!@#$%^&*()_+\{}':./<>=-".
8 - 32 pairs of hexadecimal (0-9, A-F) characters, preceded by “0x”.
If you want to enter the key in hexadecimal, type “0x” at the beginning of the key. For
example, "0x0123456789ABCDEF" is in hexadecimal format; in “0123456789ABCDEF”
is in ASCII format. If you use hexadecimal, you must enter twice as many characters
since you need to enter pairs.
The Device and remote IPSec router must use the same pre-shared key.
Note: All remote access application scenario of IPsec rules must use the same pre-
shared key.
Certificate
In order to use
Certificate
for IPsec authentication, you need to add new host
certificates in the
Security
>
Certificates
screen. See a tutorial on how to add new
host certificates in
Chapter 4 on page 57
.
Select this to have the Device and remote IPSec router use certificates to authenticate
each other when they negotiate the IKE SA. Then select the certificate the Device uses
to identify itself to the remote IPsec router.
This certificate is one of the certificates in
Certificates
. If this certificate is self-signed,
import it into the remote IPsec router. If this certificate is signed by a CA, the remote
IPsec router must trust that CA.
Note: The IPSec routers must trust each other’s certificates.
The Device uses one of its
Trusted Certificates
to authenticate the remote IPSec
router’s certificate. The trusted certificate can be a self-signed certificate or that of a
trusted CA that signed the remote IPSec router’s certificate.
Local/Remote ID
Type
Select which type of identification is used to identify the Device during authentication.
Any
- The Device does not check the identity of the itself/remote IPSec router.
IP
- The Device/remote IPSec router is identified by its IP address.
FQDN
- The Device/remote IPSec router is identified by a domain name.
User-FQDN
- The Device/remote IPSec router is identified by an e-mail address.
Note: The options
FQDN
and
User-FQDN
of
Local ID Type
and
Remote ID Type
are not
applicable if you select
Main
as the
Negotiation Mode
with
Pre-Shared Key
.
Local/Remote ID
Content
When you select
IP
in the
Local/Remote ID Type
field, type the IP address of your
computer in the
Local/Remote ID Content
field.
When you select
FQDN
or
User-FQDN
in the
Local/Remote ID Type
field, type a
domain name or e-mail address by which to identify this Device in the
Local/Remote
ID Content
field.
Table 90
VPN > IPSec VPN > Setup > Edit (continued)
LABEL
DESCRIPTION