Chapter 4 Easy Mode
ZyWALL USG Series User’s Guide
113
IKE
(Internet Key Exchange)
Version
: IKE is a protocol used in security associations to send data securely.
IKE uses certificates or pre-shared keys for authentication and a Diffie–Hellman key exchange to set up
a shared session secret from which encryption keys are derived.
IKEv2 supports Extended Authentication Protocol (EAP) authentication, and IKEv1 supports X-Auth. EAP is
important when connecting to existing enterprise authentication systems.
Rule Name
: Type the name used to identify this VPN connection (and VPN gateway). You may use 1-31
alphanumeric characters, underscores (
_
), or dashes (-), but the first character cannot be a number.
This value is case-sensitive.
Select the scenario that best describes your intended VPN connection. The figure on the left of the
screen changes to match the scenario you select.
•
Site-to-site
- The remote IPSec device has a static IP address or a domain name. This Zyxel Device can
initiate the VPN tunnel.
•
Site-to-site with Dynamic Peer
- The remote IPSec device has a dynamic IP address. Only the remote
IPSec device can initiate the VPN tunnel.
•
Remote Access (Server Role)
- Allow incoming connections from IPSec VPN clients. The clients have
dynamic IP addresses and are also known as dial-in users. Only the clients can initiate the VPN tunnel.
•
Remote Access (Client Role)
- Connect to an IPSec server. This Zyxel Device is the client (dial-in user)
and can initiate the VPN tunnel.
4.6.7 VPN Advanced Wizard - Phase 1 Settings
There are two phases to every IKE (Internet Key Exchange) negotiation – phase 1 (Authentication) and
phase 2 (Key Exchange). A phase 1 exchange establishes an IKE SA (Security Association).
Figure 86
VPN Advanced Wizard: Phase 1 Settings
•
Secure Gateway
:
Any
displays in this field if it is not configurable for the chosen scenario. Otherwise,
enter the WAN IP address or domain name of the remote IPSec device (secure gateway) to identify
the remote IPSec device by its IP address or a domain name. Use 0.0.0.0 if the remote IPSec device
has a dynamic WAN IP address.
•
My Address (interface)
: Select an interface from the drop-down list box to use on your Zyxel Device.
Summary of Contents for USG110
Page 27: ...27 PART I User s Guide ...
Page 195: ...195 PART II Technical Reference ...
Page 309: ...Chapter 10 Interfaces ZyWALL USG Series User s Guide 309 ...
Page 313: ...Chapter 10 Interfaces ZyWALL USG Series User s Guide 313 ...
Page 358: ...Chapter 10 Interfaces ZyWALL USG Series User s Guide 358 ...
Page 373: ...Chapter 10 Interfaces ZyWALL USG Series User s Guide 373 ...