Chapter 21 IPSec VPN
USG20(W)-VPN Series User’s Guide
338
• In any VPN connection, you have to select address objects to specify the local policy and remote
policy. You should set up the address objects first.
• In a VPN gateway, you can select an Ethernet interface, virtual Ethernet interface, VLAN
interface, or virtual VLAN interface to specify what address the USG uses as its IP address when
it establishes the IKE SA. You should set up the interface first.
• In a VPN gateway, you can enable extended authentication. If the USG is in server mode, you
should set up the authentication method (AAA server) first. The authentication method specifies
how the USG authenticates the remote IPSec router.
• In a VPN gateway, the USG and remote IPSec router can use certificates to authenticate each
other. Make sure the USG and the remote IPSec router will trust each other’s certificates.
21.2 The VPN Connection Screen
Click
Configuration > VPN > IPSec VPN
to open the
VPN Connection
screen. The
VPN
Connection
screen lists the VPN connection policies and their associated VPN gateway(s), and
various settings. In addition, it also lets you activate or deactivate and connect or disconnect each
VPN connection (each IPSec SA). Click a column’s heading cell to sort the table entries by that
column’s criteria. Click the heading cell again to reverse the sort order.
Click on the icons to go to the OneSecurity.com website where there is guidance on configuration
walkthroughs, troubleshooting and other information.
Figure 225
Configuration > VPN > IPSec VPN > VPN Connection
Summary of Contents for ZyWall USG20-VPN
Page 17: ...17 PART I User s Guide ...
Page 18: ...18 ...
Page 99: ...99 PART II Technical Reference ...
Page 100: ...100 ...