ZyXEL ZYWALL USG 100 User Guide - Page 69

ZyWALL IPSec VPN Client Configuration Provisioning, 4.4.1 Overview of What to

Page 69 highlights

Chapter 4 Create Secure Connections Across the Internet • The hub router must have at least one separate VPN rule for each spoke. In the local policy, specify the IP addresses of the hub-and-spoke networks with which the spoke is to be able to have a VPN tunnel. This may require you to use more than one VPN rule. • To have all Internet access from the spoke routers to go through the VPN tunnel, set the VPN rules in the spoke routers to use 0.0.0.0 (any) as the remote IP address. • Your firewall rules can still block VPN packets. • If the ZLD-based ZyWALLs' VPN tunnels are members of a single zone, make sure it is not set to block intra-zone traffic. • The ZyNOS based ZyWALLs don't have user-configured policy routes so the only way to get traffic destined for another spoke router to go through the ZyNOS ZyWALL's VPN tunnel is to make the remote policy cover both tunnels. • Since the ZLD-based ZyWALLs automatically handle the routing for VPN tunnels, if a ZLD-based ZyWALL ZyWALL is a hub router and the local policy covers both tunnels, the automatic routing takes care of it without needing a VPN concentrator. • If a ZyNOS-based ZyWALL's remote network setting overlaps with its local network settings, set ipsec swSkipOverlapIp to on to send traffic destined to A's local network to A's local network instead of through the VPN tunnel. 4.4 ZyWALL IPSec VPN Client Configuration Provisioning VPN configuration provisioning gives ZyWALL IPSec VPN Client users VPN rule settings automatically. Figure 29 IPSec VPN Configuration Provisioning Process 1 User Charlotte with the ZyWALL IPSec VPN Client sends her user name and password to the ZyWALL. 2 The ZyWALL sends the settings for the matching VPN rule. 4.4.1 Overview of What to Do 1 Create a VPN rule on the ZyWALL using the VPN Configuration Provisioning wizard. 2 Configure a username and password for the rule on the ZyWALL. 3 On a computer, use the ZyWALL IPSec VPN Client to get the VPN rule configuration. ZyWALL USG100-PLUS User's Guide 69

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140

Chapter 4 Create Secure Connections Across the Internet
ZyWALL USG100-PLUS User’s Guide
69
The hub router must have at least one separate VPN rule for each spoke. In the local policy,
specify the IP addresses of the hub-and-spoke networks with which the spoke is to be able to
have a VPN tunnel. This may require you to use more than one VPN rule.
To have all Internet access from the spoke routers to go through the VPN tunnel, set the VPN
rules in the spoke routers to use 0.0.0.0 (any) as the remote IP address.
Your firewall rules can still block VPN packets.
If the ZLD-based ZyWALLs’ VPN tunnels are members of a single zone, make sure it is not set to
block intra-zone traffic.
The ZyNOS based ZyWALLs don't have user-configured policy routes so the only way to get traffic
destined for another spoke router to go through the ZyNOS ZyWALL's VPN tunnel is to make the
remote policy cover both tunnels.
Since the ZLD-based ZyWALLs automatically handle the routing for VPN tunnels, if a ZLD-based
ZyWALL ZyWALL is a hub router and the local policy covers both tunnels, the automatic routing
takes care of it without needing a VPN concentrator.
If a ZyNOS-based ZyWALL’s remote network setting overlaps with its local network settings, set
ipsec swSkipOverlapIp
to
on
to send traffic destined to A’s local network to A’s local network
instead of through the VPN tunnel.
4.4
ZyWALL IPSec VPN Client Configuration Provisioning
VPN configuration provisioning gives ZyWALL IPSec VPN Client users VPN rule settings
automatically.
Figure 29
IPSec VPN Configuration Provisioning Process
1
User Charlotte with the ZyWALL IPSec VPN Client sends her user name and password to the
ZyWALL.
2
The ZyWALL sends the settings for the matching VPN rule.
4.4.1
Overview of What to Do
1
Create a VPN rule on the ZyWALL using the VPN Configuration Provisioning wizard.
2
Configure a username and password for the rule on the ZyWALL.
3
On a computer, use the ZyWALL IPSec VPN Client to get the VPN rule configuration.