ZyWALL 10/50 Internet Security Gateway

Table 27-1 Menu 27.2 — SA Monitor

FIELD

DESCRIPTION

EXAMPLE

 

 

 

#

This is the security association index number.

 

 

 

 

Name

This field displays the identification name for this VPN policy. This name is

Taiwan

 

unique for each connection where the secure gateway IP address is a

 

 

public static IP address.

 

 

When the secure gateway IP address is 0.0.0.0 (as discussed in the last

 

 

chapter), there may be different connections using this same VPN rule. In

 

 

this case, the name is followed by the remote IP address as configured in

 

 

Menu 27.1.1. – IPSec Setup. Individual connections using the same VPN

 

 

rule may be terminated without affecting other connections using the same

 

 

rule.

 

Encap.

This field displays Tunnel mode or Transport mode. See previous for

Tunnel

 

discussion.

 

 

 

 

IPSec

This field displays the security protocols used for an SA. ESP provides

ESP DES MD5

ALgorithm

confidentiality and integrity of data by encrypting the data and

 

 

encapsulating it into IP packets. Encryption methods include 56-bit DES

 

 

and 168-bit 3DES. NULL denotes a tunnel without encryption.

 

 

An incoming SA may have an AH in addition to ESP. The Authentication

 

 

Header provides strong integrity and authentication by adding

 

 

authentication information to IP packets. This authentication information is

 

 

calculated using header and payload data in the IP packet. This provides

 

 

an additional level of security. AH choices are MD5 (default - 128 bits)

 

 

and SHA -1(160 bits).

 

 

Both AH and ESP increase ZyWALL processing requirements and

 

 

communications latency (delay).

 

 

 

 

Select

Press [SPACE BAR] to choose from Refresh, Disconnect, None, Next

Refresh

Command

Page, or Previous Page and then press [ENTER]. You must select a

 

 

connection in the next field when you choose the Disconnect command.

 

 

Refresh displays current active VPN connections. None allows you to

 

 

jump to the “Press ENTER to Confirm…” prompt.

 

 

Select Next Page or Previous Page to view the next or previous page of

 

 

rules (respectively).

 

Select

Type the VPN connection index number that you want to disconnect and

1

Connection

then press [ENTER].

 

When you have completed this menu, press [ENTER] at the prompt “Press ENTER to Confirm…” to save your

27-2

SA Monitor