Chapter 20 IPSec VPN
ZyWALL ATP Series User’s Guide
385
Figure 270
Configuration > VPN > IPSec VPN > VPN Connection
Each field is discussed in the following table.
Table 155 Configuration > VPN > IPSec VPN > VPN Connection
LABEL
DESCRIPTION
Global Setting
The following two fields are for all IPSec VPN policies.
Click on the VPN icon to go to the Zyxel VPN Client product page at the Zyxel website.
Use Policy
Route to
control
dynamic
IPSec rules
Select this to be able to use policy routes to manually specify the destination addresses of
dynamic IPSec rules. You must manually create these policy routes. The Zyxel Device
automatically obtains source and destination addresses for dynamic IPSec rules that do not
match any of the policy routes.
Clear this to have the Zyxel Device automatically obtain source and destination addresses for all
dynamic IPSec rules.
Ignore
“Don't
Fragment”
setting in
packet
header
Select this to fragment packets larger than the MTU (Maximum Transmission Unit) that have the
“Don't Fragment” bit in the IP header turned on. When you clear this the Zyxel Device drops
packets larger than the MTU that have the “Don't Fragment” bit in the header turned on.
IPv4 / IPv6
Configuration
Add
Click this to create a new entry.
Edit
Double-click an entry or select it and click
Edit
to open a screen where you can modify the
entry’s settings.
Remove
To remove an entry, select it and click
Remove
. The Zyxel Device confirms you want to remove it
before doing so.
Activate
To turn on an entry, select it and click
Activate
.
Inactivate
To turn off an entry, select it and click
Inactivate
.
Connect
To connect an IPSec SA, select it and click
Connect
.
Disconnect
To disconnect an IPSec SA, select it and click
Disconnect
.