ZyXEL Communications 2602H-6XC manual What are Local ID and Peer ID?, When should I use FQDN?

Models: 2602H-6XC

1 159
Download 159 pages 63.33 Kb
Page 126
Image 126

Prestige 2602H-6xC Support Notes

What are Local ID and Peer ID?

Local ID and Peer ID are used in IKE phase 1 negotiation. It’s in FQDN(Fully Qualified Domain Name) format, IKE standard takes it as one type of Phase 1 ID.

Phase 1 ID is an identification for each VPN peer. The type of Phase 1 ID may be IP/FQDN(DNS)/Ueser FQDN(E-mail). The content of Phase 1 ID depends on the Phase 1 ID type. The following is an example for how to configure phase 1 ID.

ID type Content

------------------------------------

IP 202.132.154.1 DNS www.zyxel.com

E-mail support@zyxel.com.tw

Please note that, in Prestige, if "DNS" or "E-mail" type is choosen, you can still use a random string as the content, such as "this_is_Prestige". It's not neccessary to follow the format exactly.

By default, Prestige takes IP as phase 1 ID type for itself and it's remote peer. But if it's remote peer is using DNS or E-mail, you have to ajust the settings to pass phase 1 ID checking.

When should I use FQDN?

If yoour VPN connection is Prestige to Prestige, and both of them have static IP address, and there is no NAT router in between, you can ignore this option. Just leave Local/Peer ID type as IP, then skip this option.

If either side of VPN tunneling end point is using dynamic IP address, you may need to configure ID for the one with dynamic IP address. And in this case, "Aggressive mode" is recommended to be applied in phase 1 negotiation .

Is my Prestige ready for IPSec VPN?

IPSec VPN is available for Prestige since ZyNOS V3.50. It is free upgrade, no registration is needed.

By upgrading the firmware and also configurations (romfile) to ZyNOS V3.50, the IPSec VPN capability

126

All contents copyright (c) 2005 ZyXEL Communications Corporation.

Page 126
Image 126
ZyXEL Communications 2602H-6XC manual What are Local ID and Peer ID?, When should I use FQDN?