ZyXEL Communications 200 Series Benutzerhandbuch

Seite von 902
 Chapter 6 Tutorials
ZyWALL USG 100/200 Series User’s Guide
147
and destination address objects here. The next-hop is the VPN connection that you 
created. Click OK.
Figure 83   Network > Routing > Policy Route > Add
Now set up the VPN settings on the peer IPSec router and try to establish the VPN 
tunnel. To trigger the VPN, either try to connect to a device on the peer IPSec router’s 
LAN or click VPN > IPSec VPN > VPN Connection and use the VPN connection 
screen’s Connect icon.
6.4.4  How to Configure Security Policies for the VPN Tunnel
You configure security policies based on zones. The new VPN connection was assigned to the 
IPSec_VPN  zone. By default, there are no security restrictions on the IPSec_VPN zone, so, 
next, you should set up security policies (firewall rules, IDP, and so on) that apply to the 
IPSec_VPN zone. Make sure all firewalls between the ZyWALL and remote IPSec router 
allow UDP port 500 (IKE) and IP protocol 50 (AH) or 51 (ESP). If you enable NAT traversal, 
all firewalls between the ZyWALL and remote IPSec router should also allow UDP port 4500.