Chapter 20 IPSec VPN

Table 116 VPN > IPSec VPN > VPN Connection > Edit (continued)

LABEL

DESCRIPTION

Original Port

These fields are available if the protocol is TCP or UDP. Enter the original

 

destination port or range of original destination ports. The size of the original

 

port range must be the same size as the size of the mapped port range.

 

 

Mapped Port

These fields are available if the protocol is TCP or UDP. Enter the translated

 

destination port or range of translated destination ports. The size of the original

 

port range must be the same size as the size of the mapped port range.

 

 

Add icon

This column contains icons to add, move, and remove NAT records.

 

To add a NAT record, click the Add icon at the top of the column.

 

To move a NAT record, click the Move to N icon next to the record, and then

 

type the row number to which you want to move it. The records are renumbered

 

automatically.

 

To remove a NAT record, click the Remove icon next to the record. The

 

ZyWALL confirms that you want to delete the NAT record before doing so.

 

 

OK

Click OK to save the changes.

 

 

Cancel

Click Cancel to discard all changes and return to the main VPN screen.

 

 

20.2.2 The VPN Connection Add/Edit Manual Key Screen

The VPN Connection Add/Edit Manual Key screen allows you to create a new VPN connection or edit an existing one using a manual key. This is useful if you have problems with IKE key management. To access this screen, go to the VPN Connection summary screen (see Section 20.2 on page 353), and click either the Add icon or an existing manual key entry’s Edit icon. In the VPN Gateway section of the screen, select Manual Key.

"Only use manual key as a temporary solution, because it is not as secure as a regular IPSec SA.

360

 

ZyWALL USG 100/200 Series User’s Guide