Chapter 20 IPSec VPN

In the ZyWALL Quick Setup wizard, you can use the VPN Settings for Configuration Provisioning wizard to create a VPN rule that will not violate these restrictions.

Figure 186 Configuration > VPN > IPSec VPN > Configuration Provisioning

Each field is discussed in the following table.

Table 113 Configuration > VPN > IPSec VPN > Configuration Provisioning

LABEL

DESCRIPTION

Enable

Select this for users to be able to retrieve VPN rule settings using the ZyWALL IPSec VPN

Configuration

client.

Provisioning

 

 

 

Client

Choose how users should be authenticated. They can be authenticated using the local

Authentication

database on the ZyWALL or an external authentication database such as LDAP, Active

Method

Directory or RADIUS. default is a method you configured in Object > Auth Method. You

 

may configure multiple methods there. If you choose the local database on the ZyWALL,

 

then configure users using the Object > User/Group screen. If you choose LDAP, Active

 

Directory or RADIUS authentication servers, then configure users on the respective server.

 

 

Configuration

When you add or edit a configuration provisioning entry, you are allowed to set the VPN

 

Connection and Allowed User fields.

 

Duplicate entries are not allowed. You cannot select the same VPN Connection and

 

Allowed User pair in a new entry if the same pair exists in a previous entry.

 

You can bind different rules to the same user, but the ZyWALL will only allow VPN rule

 

setting retrieval for the first match found.

 

 

Add

Click Add to bind a configured VPN rule to a user or group. Only that user or group may

 

then retrieve the specified VPN rule settings.

 

If you click Add without selecting an entry in advance then the new entry appears as the

 

first entry. Entry order is important as the ZyWALL searches entries in the order listed here

 

to find a match. After a match is found, the ZyWALL stops searching. If you want to add an

 

entry as number three for example, then first select entry 2 and click Add. To reorder an

 

entry, use Move.

 

 

Edit

Select an existing entry and click Edit to change its settings.

 

 

Remove

To remove an entry, select it and click Remove. The ZyWALL confirms you want to remove

 

it before doing so.

 

 

Activate

To turn on an entry, select it and click Activate. Make sure that Enable Configuration

 

Provisioning is also selected.

 

 

Inactivate

To turn off an entry, select it and click Inactivate.

 

 

304

 

ZyWALL 110/310/1100 Series User’s Guide