Chapter 14 IPSec VPN

Figure 193 SECURITY > VPN > VPN Rules (IKE)

The following table describes the labels in this screen.

Table 84 SECURITY > VPN > VPN Rules (IKE)

LABEL

DESCRIPTION

VPN Rules

These VPN rules define the settings for creating VPN tunnels for secure

 

connection to other computers or networks.

 

 

 

Click this icon to add a VPN gateway policy (or IPSec rule).

 

 

Gateway Policies

The first row of each VPN rule represents the gateway policy.

 

The gateway policy identifies the IPSec routers at either end of a VPN tunnel

 

(My ZyWALL and Remote Gateway) and specifies the authentication,

 

encryption and other settings needed to negotiate a phase 1 IKE SA (click the

 

edit icon to display the other settings).

 

 

My ZyWALL

This represents your ZyWALL.

 

The WAN IP address, domain name or dynamic domain name of your

 

ZyWALL displays in router mode.

 

The ZyWALL’s IP address displays in bridge mode.

 

 

Remote

This represents the remote secure gateway.

Gateway

The IP address, domain name or dynamic domain name of the remote IPSec

 

router displays if you specify it, otherwise Dynamic displays.

 

 

 

Click this icon to add a VPN network policy.

 

 

Network Policies

The subsequent rows in a VPN rule are network policies. A network policy

 

identifies the devices behind the IPSec routers at either end of a VPN tunnel

 

and specifies the authentication, encryption and other settings needed to

 

negotiate a phase 2 IPSec SA.

 

 

Local

This is the network behind the ZyWALL. A network policy specifies which

Network

devices (behind the IPSec routers) can use the VPN tunnel.

 

 

Remote

This is the remote network behind the remote IPsec router.

Network

 

 

 

 

Click this icon to display a screen in which you can associate a network policy

 

to a gateway policy or move it to the recycle bin.

 

 

304

 

ZyWALL 2WG User’s Guide