Chapter 30 IPSec VPN
ZyWALL USG Series User’s Guide
640
• Source - the original source address; the remote network (
B
).
• Destination - the original destination address; the local network (
A
).
• SNAT - the translated source address; a different IP address (range of addresses) to hide the original
source address.
Destination Address in Inbound Packets (Inbound Traffic, Destination NAT)
You can set up this translation if you want the Zyxel Device to forward some packets from the remote
network to a specific computer in the local network. For example, in
, you can
configure this kind of translation if you want to forward mail from the remote network to the mail server in
the local network (
A
).
You have to specify one or more rules when you set up this kind of NAT. The Zyxel Device checks these
rules similar to the way it checks rules for a security policy. The first part of these rules define the
conditions in which the rule apply.
• Original IP - the original destination address; the remote network (
B
).
• Protocol - the protocol [TCP, UDP, or both] used by the service requesting the connection.
• Original Port - the original destination port or range of destination ports; in
, it
might be port 25 for SMTP.
The second part of these rules controls the translation when the condition is satisfied.
• Mapped IP - the translated destination address; in
, the IP address of the mail
server in the local network (
A
).
• Mapped Port - the translated destination port or range of destination ports.
The original port range and the mapped port range must be the same size.
IPSec VPN Example Scenario
Here is an example site-to-site IPSec VPN scenario.
Figure 444
Site-to-site IPSec VPN Example
Summary of Contents for USG110
Page 27: ...27 PART I User s Guide ...
Page 195: ...195 PART II Technical Reference ...
Page 309: ...Chapter 10 Interfaces ZyWALL USG Series User s Guide 309 ...
Page 313: ...Chapter 10 Interfaces ZyWALL USG Series User s Guide 313 ...
Page 358: ...Chapter 10 Interfaces ZyWALL USG Series User s Guide 358 ...
Page 373: ...Chapter 10 Interfaces ZyWALL USG Series User s Guide 373 ...