Chapter 20 IPSec VPN

You have to specify one or more rules when you set up this kind of NAT. The ZyWALL checks these rules similar to the way it checks rules for a firewall. The first part of these rules define the conditions in which the rule apply.

Original IP - the original destination address; the remote network (B).

Protocol - the protocol [TCP, UDP, or both] used by the service requesting the connection.

Original Port - the original destination port or range of destination ports; in Figure 266 on page 382, it might be port 25 for SMTP.

The second part of these rules controls the translation when the condition is satisfied.

Mapped IP - the translated destination address; in Figure 266 on page 382, the IP address of the mail server in the local network (A).

Mapped Port - the translated destination port or range of destination ports.

The original port range and the mapped port range must be the same size.

 

383

ZyWALL USG 100/200 Series User’s Guide