
Chapter 20 IPSec VPN
DH
Authentication
Before the ZyWALL and remote IPSec router establish an IKE SA, they have to verify each other’s identity. This process is based on
In main mode, the ZyWALL and remote IPSec router authenticate each other in steps 5 and 6, as illustrated below. The identities are also encrypted using the encryption algorithm and encryption key the ZyWALL and remote IPSec router selected in previous steps.
Figure 263 IKE SA: Main Negotiation Mode, Steps 5 - 6: Authentication (continued)
Step 5:
ZyWALL identity, consisting of
- ID type - content Step 6:
Remote IPSec router identity, consisting of
- ID type - content
You have to create (and distribute) a
"The ZyWALL and the remote IPSec router must use the same
| 375 |
ZyWALL USG 100/200 Series User’s Guide | |
|
|