Справочник Пользователя для ZyXEL Communications 5 Series

Скачать
Страница из 824
 Chapter 19 IPSec VPN
ZyWALL 5/35/70 Series User’s Guide
387
Figure 224   Hub-and-spoke VPN Example
19.13.2  Hub-and-spoke Example VPN Rule Addresses
The VPN rules for this hub-and-spoke example would use the following address settings.
Branch Office A:
• Remote Gateway: 10.0.0.1
• Local IP address: 192.168.167.0/255.255.255.0
• Remote IP address: 192.168.168.0~192.168.169.255
Headquarters:
Rule 1: 
• Remote Gateway: 10.0.0.2
• Local IP address: 192.168.168.0~192.168.169.255
• Remote IP address:192.168.167.0/255.255.255.0
Rule 2:
• Remote Gateway: 10.0.0.3
• Local IP address: 192.168.167.0~192.168.168.255
• Remote IP address: 192.168.169.0/255.255.255.0
Branch Office B:
• Remote Gateway: 10.0.0.1
• Local IP address: 192.168.169.0/255.255.255.0
• Remote IP address: 192.168.167.0~192.168.168.255
19.13.3  Hub-and-spoke VPN Requirements and Suggestions
Consider the following when implementing a hub-and-spoke VPN.
• The local IP addresses configured in the VPN rules cannot overlap