Chapter 20 IPSec VPN

Application Scenarios

The ZyWALL’s application scenarios make it easier to configure your VPN connection settings.

Table 105 IPSec VPN Application Scenarios

SITE-TO-SITESITE-TO-SITE WITHREMOTE ACCESS

REMOTE ACCESS

DYNAMIC PEER(SERVER ROLE)(CLIENT ROLE)

 

 

 

 

 

Choose this if the remote

Choose this if the remote

Choose this to allow

Choose this to connect to

IPSec router has a static

IPSec router has a

incoming connections

an IPSec server.

IP address or a domain

dynamic IP address.

from IPSec VPN clients.

This ZyWALL is the client

name.

 

 

You don’t specify the

The clients have dynamic

(dial-in user).

 

This ZyWALL can initiate

remote IPSec router’s

IP addresses and are also

Client role ZyWALLs

the VPN tunnel.

address, but you specify

known as dial-in users.

initiate IPSec VPN

 

the remote policy (the

 

The remote IPSec router

You don’t specify the

connections to a server

addresses of the devices

can also initiate the VPN

addresses of the client

role ZyWALL.

behind the remote IPSec

tunnel if this ZyWALL has

IPSec routers or the

 

router).

This ZyWALL can have a

a static IP address or a

remote policy.

 

This ZyWALL must have a

dynamic IP address.

domain name.

This creates a dynamic

 

 

static IP address or a

The IPSec server doesn’t

 

IPSec VPN rule that can

 

domain name.

 

configure this ZyWALL’s

 

let multiple clients

 

 

 

 

IP address or the

 

Only the remote IPSec

connect.

 

addresses of the devices

 

router can initiate the

 

 

Only the clients can

behind it.

 

VPN tunnel.

 

initiate the VPN tunnel.

 

 

 

Only this ZyWALL can

 

 

 

 

 

 

initiate the VPN tunnel.

 

 

 

 

Finding Out More

See Section 20.6 on page 305 for IPSec VPN background information.

20.1.3Before You Begin

This section briefly explains the relationship between VPN tunnels and other features. It also gives some basic suggestions for troubleshooting.

You should set up the following features before you set up the VPN tunnel.

284

 

ZyWALL 110/310/1100 Series User’s Guide