Chapter 14 IPSec VPN

Figure 210 SECURITY > VPN > VPN Rules (Manual)

The following table describes the labels in this screen.

Table 91 SECURITY > VPN > VPN Rules (Manual)

LABEL

DESCRIPTION

#

This is the VPN policy index number.

 

 

Name

This field displays the identification name for this VPN policy.

 

 

Active

This field displays whether the VPN policy is active or not. A Yes signifies that this

 

VPN policy is active. No signifies that this VPN policy is not active.

 

 

Local Network

This is the IP address(es) of computer(s) on your local network behind your

 

ZyWALL.

 

The same (static) IP address is displayed twice when the Local Network Address

 

Type field in the VPN - Manual Key - Edit screen is configured to Single Address.

 

The beginning and ending (static) IP addresses, in a range of computers are

 

displayed when the Local Network Address Type field in the VPN - Manual Key -

 

Edit screen is configured to Range Address.

 

A (static) IP address and a subnet mask are displayed when the Local Network

 

Address Type field in the VPN - Manual Key - Edit screen is configured to

 

Subnet Address.

 

 

Remote Network

This is the IP address(es) of computer(s) on the remote network behind the remote

 

IPSec router.

 

This field displays N/A when the Remote Gateway Address field displays 0.0.0.0.

 

In this case only the remote IPSec router can initiate the VPN.

 

The same (static) IP address is displayed twice when the Remote Network

 

Address Type field in the VPN - Manual Key - Edit screen is configured to Single

 

Address.

 

The beginning and ending (static) IP addresses, in a range of computers are

 

displayed when the Remote Network Address Type field in the VPN - Manual

 

Key - Edit screen is configured to Range Address.

 

A (static) IP address and a subnet mask are displayed when the Remote Network

 

Address Type field in the VPN - Manual Key - Edit screen is configured to

 

Subnet Address.

 

 

Encap.

This field displays Tunnel or Transport mode (Tunnel is the default selection).

 

 

IPSec Algorithm

This field displays the security protocols used for an SA.

 

Both AH and ESP increase ZyWALL processing requirements and

 

communications latency (delay).

 

 

Remote Gateway

This is the static WAN IP address of the remote IPSec router.

Address

 

 

 

Modify

Click the edit icon to edit the VPN policy.

 

Click the delete icon to remove the VPN policy. A window displays asking you to

 

confirm that you want to delete the VPN rule. When a VPN policy is deleted,

 

subsequent policies move up in the page list.

 

 

Add

Click Add to add a new VPN policy.

 

 

334

 

ZyWALL 2WG User’s Guide