P-662H/HW-D Series User’s Guide
244
Chapter 16 VPN Screens
16.7 VPN, NAT, and NAT Traversal
NAT is incompatible with the AH protocol in both transport
and tunnel
mode. An IPSec VPN
using the AH protocol digitally signs the outbound packet, both data payload and headers,
with a hash value appended to the packet, but a NAT device between the IPSec endpoints
rewrites the source or destination address. As a result, the VPN device at the receiving end
finds a mismatch between the hash value and the data and assumes that the data has been
maliciously altered.
NAT is not normally compatible with ESP in transport mode either, but the ZyXEL Device’s
NAT Traversal
feature provides a way to handle this. NAT traversal allows you to set up an
IKE SA when there are NAT routers between the two IPSec routers.
Figure 130
NAT Router Between IPSec Routers
Normally you cannot set up an IKE SA with a NAT router between the two IPSec routers
because the NAT router changes the header of the IPSec packet. NAT traversal solves the
problem by adding a UDP port 500 header to the IPSec packet. The NAT router forwards the
IPSec packet with the UDP port 500 header unchanged. In
, when
IPSec router A tries to establish an IKE SA, IPSec router B checks the UDP port 500 header,
and IPSec routers A and B build the IKE SA.
For NAT traversal to work, you must:
• Use ESP security protocol (in either transport or tunnel mode).
• Use IKE keying mode.
• Enable NAT traversal on both IPSec endpoints.
• Set the NAT router to forward UDP port 500 to IPSec router A.
Finally, NAT is compatible with ESP in tunnel mode because integrity checks are performed
over the combination of the "original header plus original payload," which is unchanged by a
NAT device. The compatibility of AH and ESP with NAT in tunnel and transport modes is
summarized in the following table.
Table 89
VPN and NAT
SECURITY PROTOCOL
MODE
NAT
AH
Transport
N
AH
Tunnel
N
ESP
Transport
Y*
ESP
Tunnel
Y
Summary of Contents for 802.11g ADSL 2+ 4-Port Security Gateway HW-D Series
Page 2: ......
Page 10: ...P 662H HW D Series User s Guide 10 Customer Support ...
Page 24: ...P 662H HW D Series User s Guide 24 Table of Contents ...
Page 32: ...P 662H HW D Series User s Guide 32 List of Figures ...
Page 38: ...P 662H HW D Series User s Guide 38 List of Tables ...
Page 64: ...P 662H HW D Series User s Guide 64 Chapter 2 Introducing the Web Configurator ...
Page 84: ...P 662H HW D Series User s Guide 84 Chapter 4 Bandwidth Management Wizard ...
Page 108: ...P 662H HW D Series User s Guide 108 Chapter 5 WAN Setup ...
Page 122: ...P 662H HW D Series User s Guide 122 Chapter 6 LAN Setup ...
Page 156: ...P 662H HW D Series User s Guide 156 Chapter 8 DMZ ...
Page 202: ...P 662H HW D Series User s Guide 202 Chapter 11 Firewall Configuration ...
Page 210: ...P 662H HW D Series User s Guide 210 Chapter 12 Anti Virus Packet Scan ...
Page 214: ...P 662H HW D Series User s Guide 214 Chapter 13 Content Filtering ...
Page 232: ...P 662H HW D Series User s Guide 232 Chapter 14 Content Access Control ...
Page 238: ...P 662H HW D Series User s Guide 238 Chapter 15 Introduction to IPSec ...
Page 273: ...P 662H HW D Series User s Guide Chapter 17 Certificates 273 Figure 144 My Certificate Details ...
Page 292: ...P 662H HW D Series User s Guide 292 Chapter 18 Static Route ...
Page 304: ...P 662H HW D Series User s Guide 304 Chapter 19 Bandwidth Management ...
Page 308: ...P 662H HW D Series User s Guide 308 Chapter 20 Dynamic DNS Setup ...
Page 332: ...P 662H HW D Series User s Guide 332 Chapter 22 Universal Plug and Play UPnP ...
Page 338: ...P 662H HW D Series User s Guide 338 Chapter 23 System ...
Page 344: ...P 662H HW D Series User s Guide 344 Chapter 24 Logs ...
Page 350: ...P 662H HW D Series User s Guide 350 Chapter 25 Tools ...
Page 364: ...P 662H HW D Series User s Guide 364 Chapter 27 Troubleshooting ...
Page 368: ...P 662H HW D Series User s Guide 368 Product Specifications ...
Page 372: ...P 662H HW D Series User s Guide 372 Appendix C Wall mounting Instructions ...
Page 408: ...P 662H HW D Series User s Guide 408 Appendix F Wireless LANs ...
Page 420: ...P 662H HW D Series User s Guide 420 Appendix H Command Interpreter ...
Page 436: ...P 662H HW D Series User s Guide 436 Appendix L NetBIOS Filter Commands ...
Page 462: ...P 662H HW D Series User s Guide 462 Appendix M Internal SPTGEN ...
Page 484: ...P 662H HW D Series User s Guide 484 Appendix P Triangle Route ...