ZyWALL 2 and ZyWALL 2WE

 

Table 27-9 Manual IKE VPN Rule Setup

LABEL

DESCRIPTION

 

 

 

Select IKE or Manual from the drop-down list box. IKE is the preferred choice as the

IPSec Keying Mode

key is generated automatically; Manual is useful for troubleshooting.

 

Make sure the remote gateway has the same configuration in this field.

 

 

Protocol Number

Enter 1 for ICMP, 6 for TCP, 17 for UDP, etc. 0 is the default and signifies any

protocol.

 

 

 

 

This is the IP address of the computer for which you are configuring the VPN

Local Address

connection. This IP address must correspond to the remote secure gateway's

configured remote IP address in order for the remote secure gateway to initiate the

 

 

VPN connection.

 

 

Local Port Start

0 is the default and signifies any port. Type a port number from 0 to 65535. Some of

the most common IP ports are: 21, FTP; 53, DNS; 23, Telnet; 80, HTTP; 25, SMTP;

 

110, POP3

 

 

 

Enter a port number in this field to define a port range. This port number must be

Local Port End

greater than that specified in the previous field (or equal to it for configuring an

 

individual port).

 

 

 

Enter the beginning (static) IP address, in a range of computers behind the remote

Remote Address Start

secure gateway. This address should be specific to the remote computer using the

VPN tunnel. If you wish to configure the tunnel for a single IP address, enter it in this

 

field and again in the Remote Address End field.

 

 

Remote Address

Enter the end (static) IP address, in a range of computers on behind the remote

secure gateway. This address should be specific to the remote computer using the

End/Mask

VPN tunnel. If you wish to configure the tunnel for a single IP address, enter it in both

 

the Remote Address Start field and here.

 

 

 

0 is the default and signifies any port. Type a port number from 0 to 65535. Some of

Remote Port Start

the most common IP ports are: 21, FTP; 53, DNS; 23, Telnet; 80, HTTP; 25, SMTP;

 

110, POP3

 

 

Remote Port End

Enter a port number in this field to define a port range. This port number must be

greater than that specified in the previous field (or equal to it for configuring an

 

individual port).

 

 

27-22

VPN/IPSec Setup