ZyWALL 2 Series User’s Guide

Table 38-1 Menu 27.2: SA Monitor

FIELD

DESCRIPTION

EXAMPLE

 

 

 

#

This is the security association index number.

 

 

 

 

Name

This field displays the identification name for this VPN policy. This name is

Taiwan

 

unique for each connection where the secure gateway IP address is a public

 

 

static IP address.

 

 

When the secure gateway IP address is 0.0.0.0 (as discussed in the last

 

 

chapter), there may be different connections using this same VPN rule. In this

 

 

case, the name is followed by the remote IP address as configured in Menu

 

 

27.1.1. – IPSec Setup. Individual connections using the same VPN rule may

 

 

be terminated without affecting other connections using the same rule.

 

Encap.

This field displays Tunnel mode or Transport mode. See previous for

Tunnel

 

discussion.

 

IPSec

This field displays the security protocols used for an SA. ESP provides

ESP DES

ALgorithm

confidentiality and integrity of data by encrypting the data and encapsulating it

MD5

 

into IP packets. Encryption methods include 56-bit DES, 168-bit 3DES and

 

 

128-bit AES. NULL denotes a tunnel without encryption.

 

 

An incoming SA may have an AH in addition to ESP. The Authentication

 

 

Header provides strong integrity and authentication by adding authentication

 

 

information to IP packets. This authentication information is calculated using

 

 

header and payload data in the IP packet. This provides an additional level of

 

 

security. AH choices are MD5 (default - 128 bits) and SHA -1(160 bits).

 

 

Both AH and ESP increase ZyWALL processing requirements and

 

 

communications latency (delay).

 

 

 

 

Select

Press [SPACE BAR] to choose from Refresh, Disconnect, None, Next Page,

Refresh

Command

or Previous Page and then press [ENTER]. You must select a connection in

 

 

the next field when you choose the Disconnect command. Refresh displays

 

 

current active VPN connections. None allows you to jump to the “Press

 

 

ENTER to Confirm…” prompt.

 

 

Select Next Page or Previous Page to view the next or previous page of rules

 

 

(respectively).

 

Select

Type the VPN connection index number that you want to disconnect and then

1

Connection

press [ENTER].

 

When you have completed this menu, press [ENTER] at the prompt “Press ENTER to Confirm…” to save your configuration, or press [ESC] at any time to cancel.

38-2

SA Monitor