ZyXEL VFG6005 User Guide - Page 64

Enable/Disable this IPsec rule

Page 64 highlights

2. Configure [Add - IPsec] Settings following the instructions below. Sequence Number Connection Name Rule Enable VPN Mode Local External Interface This defines the sequence of the IPsec rules. Name of the IPsec rule. Enable/Disable this IPsec rule Net-to-Net or Road Warrior Select the external WAN for the local VPN gateway. Local Internal IP Address Select the subnet IP address for the VPN gateway. Local Netmask Remote Gateway Remote Subnet IP Remote Netmask Connection Initiation IKE Key Mode Preshared Key L2TP Enable Advanced Options Phase 1 Mode Phase 1 ID Phase 1 Lifetime Phase 2 Lifetime Phase 1 Authentication Phase I Encryption Phase 1 Group Key Management Phase 2 Authentication Phase 2 Encryption Phase 2 Group Key Management Select the netmask for the local VPN gateway. Enter the IP address or domain name of the remote VPN gateway. This option is needed in Net-to-Net mode. Enter the subnet IP address of the remote VPN gateway. This option is needed in Net-to-Net mode. Enter the subnet netmask of the remote VPN gateway. This option is needed in Net-to-Net mode. Check the local VPN gateway to initiate the connection. This option is needed in Net-to-Net mode. PSK. Enter the preshared key. The key should be at least 8-digit ASCII string. Check the local VPN gateway to enable L2TP. This option is needed in Road Warrior mode. Check it if you need to configure the advanced options. Main. Enter the phase 1 ID. Enter the phase 1 lifetime. This value is between 3600 and 28800 seconds. Enter the phase 2 lifetime. This value is between 3600 and 28800 seconds. Select the phase 1 authentication as MD5 or SHA1. (SHA1 recommended) Select the phase 1 encryption as DES, 3DES or AES. (AES recommended) Select the phase 1 group key management as DH1, DH2 or DH5. Select the phase 2 authentication as MD5 or SHA1. (SHA1 recommended) Select the phase 2 encryption as DES, 3DES or AES. (AES recommended) Select the phase 2 group key management as DH1, DH2 or DH5. 55

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162

55
2.
Configure [Add - IPsec] Settings following the instructions below.
Sequence Number
This defines the sequence of the IPsec rules.
Connection Name
Name of the IPsec rule.
Rule Enable
Enable/Disable this IPsec rule
VPN Mode
Net-to-Net or Road Warrior
Local External Interface
Select the external WAN for the local VPN gateway.
Local Internal IP Address
Select the subnet IP address for the VPN gateway.
Local Netmask
Select the netmask for the local VPN gateway.
Remote Gateway
Enter the IP address or domain name of the remote VPN gateway. This option is
needed in Net-to-Net mode.
Remote Subnet IP
Enter the subnet IP address of the remote VPN gateway. This option is needed in
Net-to-Net mode.
Remote Netmask
Enter the subnet netmask of the remote VPN gateway. This option is needed in
Net-to-Net mode.
Connection Initiation
Check the local VPN gateway to initiate the connection. This option is needed in
Net-to-Net mode.
IKE Key Mode
PSK.
Preshared Key
Enter the preshared key. The key should be at least 8-digit ASCII string.
L2TP Enable
Check the local VPN gateway to enable L2TP. This option is needed in Road
Warrior mode.
Advanced Options
Check it if you need to configure the advanced options.
Phase 1 Mode
Main.
Phase 1 ID
Enter the phase 1 ID.
Phase 1 Lifetime
Enter the phase 1 lifetime. This value is between 3600 and 28800 seconds.
Phase 2 Lifetime
Enter the phase 2 lifetime. This value is between 3600 and 28800 seconds.
Phase 1 Authentication
Select the phase 1 authentication as MD5 or SHA1. (SHA1 recommended)
Phase I Encryption
Select the phase 1 encryption as DES, 3DES or AES. (AES recommended)
Phase 1 Group Key
Management
Select the phase 1 group key management as DH1, DH2 or DH5.
Phase 2 Authentication
Select the phase 2 authentication as MD5 or SHA1. (SHA1 recommended)
Phase 2 Encryption
Select the phase 2 encryption as DES, 3DES or AES. (AES recommended)
Phase 2 Group Key
Management
Select the phase 2 group key management as DH1, DH2 or DH5.