
ZyWALL 2 and ZyWALL 2WE
Table
ESP | AH |
|
|
DES (default) | MD5 (default) |
Data Encryption Standard (DES) is a widely used method | MD5 (Message Digest 5) produces a |
of data encryption using a private (secret) key. DES | digest to authenticate packet data. |
applies a |
|
3DES | SHA1 |
Triple DES (3DES) is a variant of DES, which iterates | SHA1 (Secure Hash Algorithm) produces a |
three times with three separate keys (3 x 56 = 168 bits), | |
effectively doubling the strength of DES. |
|
Select DES for minimal security and 3DES for maximum. | Select MD5 for minimal security and |
Select NULL to set up a tunnel without encryption. | maximum security. |
27.3 My IP Address
My IP Address is the WAN IP address of the ZyWALL. If this field is configured as 0.0.0.0, then the ZyWALL will use the current ZyWALL WAN IP address (static or dynamic) to set up the VPN tunnel. The ZyWALL has to rebuild the VPN tunnel if the My IP Address changes after setup.
27.4 Secure Gateway Address
Secure Gateway Address is the WAN IP address or domain name of the remote IPSec router (secure gateway).
If the remote secure gateway has a static WAN IP address, enter it in the Secure Gateway Address field. You may alternatively enter the remote secure gateway’s domain name (if it has one) in the Secure Gateway Address field.
You can also enter a remote secure gateway’s domain name in the Secure Gateway Address field if the remote secure gateway has a dynamic WAN IP address and is using DDNS. The ZyWALL has to rebuild the VPN tunnel each time the remote secure gateway’s WAN IP address changes (there may be a delay until the DDNS servers are updated with the remote gateway’s new WAN IP address).
27.4.1 Dynamic Secure Gateway Address
If the remote secure gateway has a dynamic WAN IP address and does not use DDNS, enter 0.0.0.0 as the secure gateway’s address. In this case only the remote secure gateway can initiate SAs. This may be useful for telecommuters initiating a VPN tunnel to the company network. See section 27.16 for configuration examples.
VPN/IPSec Setup |