ZyWALL 10/50 Internet Security Gateway
Table
FIELD | DESCRIPTION | EXAMPLE |
|
|
|
Local Addr | When the Addr Type field in Menu 27.1.1 IPSec Setup is configured to | 192.168.1.38 |
End | Single, this is the same (static) IP address as in the Local Addr Start |
|
| field. |
|
| When the Addr Type field in Menu 27.1.1 IPSec Setup is configured to |
|
| Range, this is the end (static) IP address, in a range of computers on the |
|
| LAN behind your ZyWALL. |
|
| When the Addr Type field in Menu 27.1.1 IPSec Setup is configured to |
|
| SUBNET, this is a subnet mask on the LAN behind your ZyWALL. |
|
Encap | This field displays Tunnel mode or Transport mode. See earlier for a | Tunnel |
| discussion of these. You need to finish configuring the VPN policy in menu |
|
| 27.1.1.1 or 27.1.1.2 if ??? is displayed. |
|
IPSec | This field displays the security protocols used for an SA. ESP provides | ESP DES MD5 |
ALgorithm | confidentiality and integrity of data by encrypting the data and |
|
| encapsulating it into IP packets. Encryption methods include |
|
| and |
|
| AH (Authentication Header) provides strong integrity and authentication |
|
| by adding authentication information to IP packets. This authentication |
|
| information is calculated using header and payload data in the IP packet. |
|
| This provides an additional level of security. AH choices are MD5 (default |
|
| - 128 bits) and SHA |
|
| Both AH and ESP increase the ZyWALL’s processing requirements and |
|
| communications latency (delay). |
|
| You need to finish configuring the VPN policy in menu 27.1.1.1 or 27.1.1.2 |
|
| if ??? is displayed. |
|
Key Mgt | This field displays the SA’s type of key management, (IKE or Manual). | IKE |
|
|
|
Remote | When the Addr Type field in Menu 27.1.1 IPSec Setup is configured to | 172.16.2.40 |
Addr Start | Single, this is a (static) IP address on the network behind the remote |
|
| IPSec router. |
|
| When the Addr Type field in Menu 27.1.1 IPSec Setup is configured to |
|
| Range, this is the beginning (static) IP address, in a range of computers |
|
| on the network behind the remote IPSec router. |
|
| When the Addr Type field in Menu 27.1.1 IPSec Setup is configured to |
|
| SUBNET, this is a (static) IP address on the network behind the remote |
|
| IPSec router. |
|
| This field displays N/A when you configure the Secure Gateway Addr |
|
VPN/IPSec Setup |