
Chapter 14 IPSec Commands
Figure 1 Dynamic VPN Rule l
192.168.1.0
Using the command ipsec swSkipOverlapIp on has ZyXEL Device X check if a packet’s destination is also at the local network before forwarding the packet. If it is, the ZyXEL Device sends the traffic to the local network. Setting ipsec swSkipOverlapIp to off disables the checking for local network IP addresses.
2You configure an IP alias network that overlaps with the VPN remote network. (See Figure 2.)
For example, you have an IP alias network M (10.1.2.0/24) in ZyXEL Device X’s LAN. For the VPN rule, you configure the VPN network as follows.
•Local IP address start: 192.168.1.1, end: 192.168.1.254
•Remote IP address start: 10.1.2.240, end: 10.1.2.254 IP addresses 10.1.2.240 to 10.1.2.254 overlap.
Figure 2 IP Alias
In this case, if you want to send packets from network A to an overlapped IP (ex. 10.1.2.241) that is in the IP alias network M, you have to set the swSkipOverlapIp command to on.
| 93 |
DSL & IAD CLI Reference Guide | |
|
|