ZyXEL Communications 2 Plus User Manual

Page of 686
Chapter 14 IPSec VPN
ZyWALL 2 Plus User’s Guide
282
Figure 184   SECURITY > VPN > VPN Rules (Manual) 
The following table describes the labels in this screen. 
Table 71   SECURITY > VPN > VPN Rules (Manual)
LABEL
DESCRIPTION
#
This is the VPN policy index number.
Name
This field displays the identification name for this VPN policy. 
Active
This field displays whether the VPN policy is active or not. A Yes signifies that this 
VPN policy is active. No signifies that this VPN policy is not active.
Local Network
This is the IP address(es) of computer(s) on your local network behind your 
ZyWALL. 
The same (static) IP address is displayed twice when the Local Network Address 
Type field in the VPN - Manual Key - Edit screen is configured to Single Address
The beginning and ending (static) IP addresses, in a range of computers are 
displayed when the Local Network Address Type field in the VPN - Manual Key - 
Edit screen is configured to Range Address.
A (static) IP address and a subnet mask are displayed when the Local Network 
Address Type field in the VPN - Manual Key - Edit screen is configured to 
Subnet Address
Remote Network
This is the IP address(es) of computer(s) on the remote network behind the remote 
IPSec router.
This field displays N/A when the Remote Gateway Address field displays 0.0.0.0
In this case only the remote IPSec router can initiate the VPN.
The same (static) IP address is displayed twice when the Remote Network 
Address Type field in the VPN - Manual Key - Edit screen is configured to Single 
Address
The beginning and ending (static) IP addresses, in a range of computers are 
displayed when the Remote Network Address Type field in the VPN - Manual 
Key - Edit screen is configured to Range Address.
A (static) IP address and a subnet mask are displayed when the Remote Network 
Address Type field in the VPN - Manual Key - Edit screen is configured to 
Subnet Address
Encap.
This field displays Tunnel or Transport mode (Tunnel is the default selection).
IPSec Algorithm
This field displays the security protocols used for an SA. 
Both AH and ESP increase ZyWALL processing requirements and 
communications latency (delay). 
Remote Gateway 
Address
This is the static WAN IP address of the remote IPSec router. 
Modify
Click the edit icon to edit the VPN policy. 
Click the delete icon to remove the VPN policy. A window displays asking you to 
confirm that you want to delete the VPN rule. When a VPN policy is deleted, 
subsequent policies move up in the page list.
Add
Click Add to add a new VPN policy.