ZyWALL 2 Series User’s Guide

Table 37-2 Menu 27.1.1: IPSec Setup

FIELD

DESCRIPTION

EXAMPLE

 

 

 

NAT Traversal

Select this check box to enable NAT traversal. NAT traversal allows you to

No

 

set up a VPN connection when there are NAT routers between the two

 

 

IPSec routers.

 

 

The remote IPSec router must also have NAT traversal enabled. You can

 

 

use NAT traversal with ESP protocol using Transport or Tunnel mode,

 

 

but not with AH protocol nor with Manual key management.

 

 

In order for an IPSec router behind a NAT router to receive an initiating

 

 

IPSec packet, set the NAT router to forward UDP port 500 to the IPSec

 

 

router behind the NAT router.

 

Local ID type

Press [SPACE BAR] to choose IP, DNS, or E-mailand press [ENTER].

 

 

Select IP to identify this ZyWALL by its IP address.

 

 

Select DNS to identify this ZyWALL by a domain name.

 

 

Select E-mailto identify this ZyWALL by an e-mail address.

 

 

 

 

Content

When you select IP in the Local ID type field, type the IP address of your

 

 

computer in the local Content field. The ZyWALL automatically uses the IP

 

 

address in the My IP Address field (refer to the My IP Address field

 

 

description) if you configure the local Content field to 0.0.0.0 or leave it

 

 

blank.

 

 

It is recommended that you type an IP address other than 0.0.0.0 in the

 

 

local Content field or use the DNS or E-mailID type in the following

 

 

situations.

 

 

When there is a NAT router between the two IPSec routers.

 

 

When you want the remote IPSec router to be able to distinguish

 

 

between VPN connection requests that come in from IPSec

 

 

routers with dynamic WAN IP addresses.

 

 

When you select DNS or E-mailin the Local ID type field, type a domain

 

 

name or e-mail address by which to identify this ZyWALL in the local

 

 

Content field. Use up to 31 ASCII characters including spaces, although

 

 

trailing spaces are truncated. The domain name or e-mail address is for

 

 

identification purposes only and can be any string.

 

 

 

 

My IP Addr

Enter the IP address of your ZyWALL. The ZyWALL uses its current WAN

0.0.0.0

 

IP address (static or dynamic) in setting up the VPN tunnel if you leave this

 

 

field as 0.0.0.0.

 

 

The VPN tunnel has to be rebuilt if this IP address changes.

 

 

 

 

VPN/IPSec Setup

37-7