ZyWALL 2 and ZyWALL 2WE

27.16Telecommuter VPN/IPSec Examples

The following examples show how multiple telecommuters can make VPN connections to a single ZyWALL at headquarters from remote IPSec routers that use dynamic WAN IP addresses.

27.16.1Telecommuters Sharing One VPN Rule Example

Multiple telecommuters can use one VPN rule to simultaneously access a ZyWALL at headquarters. They must all use the same IPSec parameters (including the pre-shared key) but the local IP addresses (or ranges of addresses) cannot overlap. See the following table and figure for an example.

Having everyone use the same pre-shared key may create a vulnerability. If the pre-shared key is compromised, all of the VPN connections using that VPN rule are at risk. A recommended alternative is to use a different VPN rule for each telecommuter and identify them by unique IDs (see section 27.16.2 for an example)

Table 27-12 Telecommuter and Headquarters Configuration Example

 

TELECOMMUTER

 

HEADQUARTERS

 

 

 

My IP Address:

0.0.0.0 (dynamic IP address

Public static IP address

 

assigned by the ISP)

 

 

Secure Gateway

Public static IP address or domain

0.0.0.0

With this IP address only the

IP Address:

name.

telecommuter can initiate the IPSec tunnel.

VPN/IPSec Setup

27-27