Chapter 23 IPSec VPN

Table 116 Configuration > VPN > IPSec VPN > VPN Gateway > Edit (continued)

LABEL

DESCRIPTION

NAT Traversal

Select this if any of these conditions are satisfied.

 

• This IKE SA might be used to negotiate IPSec SAs that use ESP as

 

the active protocol.

 

• There are one or more NAT routers between the ZyWALL and

 

remote IPSec router, and these routers do not support IPSec

 

pass-thru or a similar feature.

 

The remote IPSec router must also enable NAT traversal, and the

 

NAT routers have to forward packets with UDP port 500 and UDP

 

4500 headers unchanged.

 

 

Dead Peer

Select this check box if you want the ZyWALL to make sure the

Detection

remote IPSec router is there before it transmits data through the IKE

(DPD)

SA. The remote IPSec router must support DPD. If there has been no

 

 

traffic for at least 15 seconds, the ZyWALL sends a message to the

 

remote IPSec router. If the remote IPSec router responds, the

 

ZyWALL transmits the data. If the remote IPSec router does not

 

respond, the ZyWALL shuts down the IKE SA.

 

If the remote IPSec router does not support DPD, see if you can use

 

the VPN connection connectivity check (see Section 23.2.1 on page

 

380).

 

 

More Settings/

Click this button to show or hide the Extended Authentication

Less Settings

fields.

 

 

Extended

When multiple IPSec routers use the same VPN tunnel to connect to

Authentication

a single VPN tunnel (telecommuters sharing a tunnel for example),

 

use extended authentication to enforce a user name and password

 

check. This way even though they all know the VPN tunnel’s security

 

settings, each still has to provide a unique user name and password.

 

 

Enable Extended

Select this if one of the routers (the ZyWALL or the remote IPSec

Authentication

router) verifies a user name and password from the other router

 

using the local user database and/or an external server.

 

 

Server Mode

Select this if the ZyWALL authenticates the user name and password

 

from the remote IPSec router. You also have to select the

 

authentication method, which specifies how the ZyWALL

 

authenticates this information.

 

 

Client Mode

Select this radio button if the ZyWALL provides a username and

 

password to the remote IPSec router for authentication. You also

 

have to provide the User Name and the Password.

 

 

User Name

This field is required if the ZyWALL is in Client Mode for extended

 

authentication. Type the user name the ZyWALL sends to the remote

 

IPSec router. The user name can be 1-31 ASCII characters. It is

 

case-sensitive, but spaces are not allowed.

 

 

Password

This field is required if the ZyWALL is in Client Mode for extended

 

authentication. Type the password the ZyWALL sends to the remote

 

IPSec router. The password can be 1-31 ASCII characters. It is case-

 

sensitive, but spaces are not allowed.

 

 

OK

Click OK to save your settings and exit this screen.

 

 

Cancel

Click Cancel to exit this screen without saving.

 

 

398

 

ZyWALL USG 50 User’s Guide