ZyXEL Communicationsメーカー2WGの使用説明書/サービス説明書
ページ先へ移動 of 264
ZyW ALL 2WG Security Appliance Support Notes V ersion 4.03 Sep. 2007.
ZyW ALL 2WG Support Notes 2 INDEX Application Notes ...................................................................................................... 9 Mobility Internet Access .....................................................................
ZyW ALL 2WG Support Notes 3 T o filter non-work r elated and unp roductive web surfing to mitigate spywar e and phishing threats ................................................................. 209 Centralized Management .............................
ZyW ALL 2WG Support Notes 4 gateway behind ZyW ALL? ..................................................................... 226 A28. How do I setup my ZyW ALL for r outing IPSec packets over NA T? ........................................................
ZyW ALL 2WG Support Notes 5 D02. In addition to r egistration, what can I do with myZyXEL.com? 235 D03. Is there anything changed on myZ yXEL.com because of the launch of ZyNOS v4.00? Which ZyW ALL models can be r egistered via myZyXEL.com? ..........
ZyW ALL 2WG Support Notes 6 E15. How many URL keywords does Z yW ALL support? .................... 240 E16. How do I keep database of Content Filtering service updated? . 241 E17. What is BlueCoat Filter list? .........................................
ZyW ALL 2WG Support Notes 7 What do I need to know? ......................................................................... 250 F18. Does ZyW ALL support dynamic secure gatew ay IP? .................. 251 F19. What VPN gateway that has been tested with ZyW ALL successfully? .
ZyW ALL 2WG Support Notes All contents c opyright (c) 2006 ZyXEL Comm unications Corp oration. 8 G16. W ill Self-signed certificate be erased if I reset to default configuration file? ...................................................................
ZyW ALL 2WG Support Notes All contents c opyright (c) 2006 ZyXEL Comm unications Corporat ion. 9 Application Notes Mobility Internet Access Y ou may have the experienced a need of Internet acce ss in a location where wired connection is dif ficult to deploy , e.
ZyW ALL 2WG Support Notes All contents c opyright (c) 2006 ZyXEL Comm unications Corporat ion. 10 Utilize 3G and Wireless for the Internet Access Following we will show you how to configure it step-by-step. Utilize 3G card to g et Internet access 1). Plug the 3G card to ZyWALL 2WG's card slot before powering on the ZyWALL 2WG device.
ZyW ALL 2WG Support Notes All contents c opyright (c) 2006 ZyXEL Comm unications Corporat ion. 11 3). Then the 3G wireless card will be dialed up automatically w hen WAN1 is not available.
ZyW ALL 2WG Support Notes All contents c opyright (c) 2006 ZyXEL Comm unications Corporat ion. 12 4) If dialed up successfully, you can see the GUI home page as shown below. You will get the "WAN2 connection is up" and "3G card's signal strength" messages in t he latest alerts.
ZyW ALL 2WG Support Notes All contents c opyright (c) 2006 ZyXEL Comm unications Corporat ion. 13 Utilize the em bedded wireless card to provide LAN users a ccess 1). Go to GUI menu Network > WIRELESS CARD , enable it and configure the other parameters like 802.
ZyW ALL 2WG Support Notes All contents c opyright (c) 2006 ZyXEL Comm unications Corporat ion. 14 To configure the security and the MAC filter, go to Wireless Card > Security or Wireless Card > MAC Filter to further configure it. For example, we would like to provide the wireless access clien ts with preset MAC address filtering list.
ZyW ALL 2WG Support Notes All contents c opyright (c) 2006 ZyXEL Comm unications Corporat ion. 15.
ZyW ALL 2WG Support Notes All contents c opyright (c) 2006 ZyXEL Comm unications Corporat ion. 16.
ZyW ALL 2WG Support Notes All contents c opyright (c) 2006 ZyXEL Comm unications Corporat ion. 17 After you have configured the Security and MAC filter profiles, you can choose them in the main page o.
ZyW ALL 2WG Support Notes All contents c opyright (c) 2006 ZyXEL Comm unications Corporat ion. 18 Seamless Incorporation into your network Using T ransp arent (Bridge Mode) Firewall If user wants to insert a firewall into current network, IP set ting of hosts and server s may need to change.
ZyW ALL 2WG Support Notes All contents c opyright (c) 2006 ZyXEL Comm unications Corporat ion. 19 Deploying a transparent mode firewa ll doesn’t require any changes of settings on the original network topology . It works as bridge/switch; therefore, all the hosts can comm unicate with each other as without firewall in between.
ZyW ALL 2WG Support Notes All contents c opyright (c) 2006 ZyXEL Comm unications Corporat ion. 20 User can configure ZyW ALL to act as a router mode firewall or bridge (transpa rent) firewall.
ZyW ALL 2WG Support Notes All contents c opyright (c) 2006 ZyXEL Comm unications Corporat ion. 21 assign a management IP for ZyW ALL. The Gateway IP Address is used as next-hop of default route.
ZyW ALL 2WG Support Notes All contents c opyright (c) 2006 ZyXEL Comm unications Corporat ion. 22 S tep3. Aft er reboo ting, login ZyW ALL ’ s GUI by accessing ZyW ALL ’ s management IP address.
ZyW ALL 2WG Support Notes All contents c opyright (c) 2006 ZyXEL Comm unications Corporat ion. 23.
ZyW ALL 2WG Support Notes All contents c opyright (c) 2006 ZyXEL Comm unications Corporat ion. 24 Internet Connection A typical Internet access applicati on of the ZyWALL is shown below. This section guides you how to configure ZyWALL to gain the Internet access.
ZyW ALL 2WG Support Notes All contents c opyright (c) 2006 ZyXEL Comm unications Corporat ion. 25 Following picture is an exam ple while PPPoE is selected. Once the required information is co rrectly configured, click on the “ Finish ” button to apply the setting and then you have finished configuring Internet Access on W AN link.
ZyW ALL 2WG Support Notes All contents c opyright (c) 2006 ZyXEL Comm unications Corp oration. 26 2. When choosing DHCP setting as a ‘Server ’, the LAN will automatically assign IP , subnet, gateway and DNS to the associated clients. 3. When choosing DHCP setting as a ‘Relay’, the LAN will forward the DHCP request to another DHCP server .
ZyW ALL 2WG Support Notes All contents c opyright (c) 2006 ZyXEL Comm unications Corporat ion. 27 • How NA T works If we define the local IP addre sses as the Internal Local Addre sses (ILA) and the global IP addresses as the Inside Global Address (IGA), see the following figure.
ZyW ALL 2WG Support Notes All contents c opyright (c) 2006 ZyXEL Comm unications Corporat ion. 28 5. Server In Server mode, the ZyW ALL maps multiple inside serv ers to one global IP address. This allows us to specify multiple servers of dif ferent types behind th e NA T for outside access.
ZyW ALL 2WG Support Notes All contents c opyright (c) 2006 ZyXEL Comm unications Corporat ion. 29 Step 1. Applying NAT in WAN Interface You can choose the NAT mapping types to either SUA Only or Full Feature in WAN setup.
ZyW ALL 2WG Support Notes All contents c opyright (c) 2006 ZyXEL Comm unications Corporat ion. 30 Key Settings Field Options Description Full Featur e Set to 'Full Feature' if there a re multiple IP addresses given by ISP and can assigned to your clients.
ZyW ALL 2WG Support Notes All contents c opyright (c) 2006 ZyXEL Comm unications Corporat ion. 31 Step 3. Using Multiple Global IP addresses for clients and serv ers (One-to-One, Many- to-One, Se rver Set mapping types) In this case we have 3 IGAs (IGA1, IGA2 and IGA3) from the ISP.
ZyW ALL 2WG Support Notes All contents c opyright (c) 2006 ZyXEL Comm unications Corporat ion. 32 Rule 2 Setup: Selecting One- to -One type to map the FTP Server 2 with ILA2 (192.168.1.11) to IGA2 (200.1.1.2). Rule 3 Setup: Select Many-to-One type to map the other clients to IGA3.
ZyW ALL 2WG Support Notes All contents c opyright (c) 2006 ZyXEL Comm unications Corporat ion. 33 Now we configure all other incoming traffic to go to our web se rver and mail server in " Port Ma.
ZyW ALL 2WG Support Notes All contents c opyright (c) 2006 ZyXEL Comm unications Corporat ion. 34 Application for Non NAT Friendly Support Some servers providing Internet applications such as some mIRC servers do not allow users to login using the same IP address.
ZyW ALL 2WG Support Notes All contents c opyright (c) 2006 ZyXEL Comm unications Corporat ion. 35 Optimize network performance & availability Using Bandwidth Ma nagement Why Bandwidth Manag ement (BWM)? Nowadays, we have many dif ferent traf fic types for In ternet applications.
ZyW ALL 2WG Support Notes All contents c opyright (c) 2006 ZyXEL Comm unications Corporat ion. 36 How Bandwidth Management in ZyW ALL? ZyW ALL achieves BWM by classifying packets, and c ontrol when to send out the classified packets. Bandwidth Management of ZyXEL appliances operates on the IP layer .
ZyW ALL 2WG Support Notes All contents c opyright (c) 2006 ZyXEL Comm unications Corporat ion. 37 Go to ADV ANCED->BW MGMT ->Summary , activat e bandwidth m anagement on the interface you would like to manage. W e enable the BWM fu nction on W AN interface in this example.
ZyW ALL 2WG Support Notes All contents c opyright (c) 2006 ZyXEL Comm unications Corporat ion. 38 Key Settings: Class Name Give this class a name, for exam ple, 'App' Bandwidth Budget Configure the speed you would like to allocate to this class Priority Enter a number between 0 and 7 to set the prio rity of this class.
ZyW ALL 2WG Support Notes All contents c opyright (c) 2006 ZyXEL Comm unications Corporat ion. 39 Source IP Address Enter the IP address of source that meats this class. Note tha t for traff ic from 'LAN to W AN' , since BWM is before NA T , you shoul d use the IP address before NA T processing.
ZyW ALL 2WG Support Notes All contents c opyright (c) 2006 ZyXEL Comm unications Corporat ion. 40 S tep1. Activate Bandwidth Management on th e interface on which you want to c ontrol. In this exam ple, it is LAN. Assign 2048Kbps to LAN interface. S tep2.
ZyW ALL 2WG Support Notes All contents c opyright (c) 2006 ZyXEL Comm unications Corporat ion. 41 S tep3. Add another service and allocate 800kbps for FT P and destined to FTP Client B. Select the Service as FTP from drop-down list. Input Client B’ s IP address as Des tination IP Address.
ZyW ALL 2WG Support Notes All contents c opyright (c) 2006 ZyXEL Comm unications Corporat ion. 42 S tep4. Add another service and alloca te 800kbps for IPTV user and destined to Media traf fic to IPTV user . Select the Service as Custom from drop-down list and set Protocol IP as 17 (UDP).
ZyW ALL 2WG Support Notes All contents c opyright (c) 2006 ZyXEL Comm unications Corporat ion. 43 Secure Connections across the Internet Site-to-Site VPN (Intranet) Scenario A site-to-site VPN protects the netw ork resources on your protected networks from unauthorized use by users on an unprotected network, such as the public Internet.
ZyW ALL 2WG Support Notes All contents c opyright (c) 2006 ZyXEL Comm unications Corporat ion. 44 1) Configure the static Public IP address to W AN interface through Network-> W AN-> W AN IP Add.
ZyW ALL 2WG Support Notes All contents c opyright (c) 2006 ZyXEL Comm unications Corporat ion. 45 address is assigned to ZyW ALL ’ s W AN interface, ZyW ALL will upda tes the related record in DDNS server . Therefore the peer VPN gateway can resolve ZyW ALL ’ s IP address to make a VPN tunnel.
ZyW ALL 2WG Support Notes All contents c opyright (c) 2006 ZyXEL Comm unications Corporat ion. 46 4) Configure the DDNS entry under DNS-> DDNS and bind it to a W AN interface. 5) Under Gateway Policy menu, select the DDNS entry from drop-down list and use it as My Domain Name.
ZyW ALL 2WG Support Notes All contents c opyright (c) 2006 ZyXEL Comm unications Corporat ion. 47 placed behind the NA T router . For example, the NA T router has a dif ferent interface (e.g. leased line, ISDN) which are not supported by IPSec gateway .
ZyW ALL 2WG Support Notes All contents c opyright (c) 2006 ZyXEL Comm unications Corporat ion. 48 when peer VPN entity also support N A T Traversa l function. If yes, the IPSec traf fic will be encapsulated in UDP packet to avoi d traversal problem on NA T routers.
ZyW ALL 2WG Support Notes All contents c opyright (c) 2006 ZyXEL Comm unications Corporat ion. 49 The configuration goal is to achieve following two: 1) Setup VPN rule to allow PC1 to access De pt.1 through the tunnel between GW 1 & GW2 2) Setup VPN rule to allow PC2 to access De pt.
ZyW ALL 2WG Support Notes All contents c opyright (c) 2006 ZyXEL Comm unications Corporat ion. 50 6) Extended Authentication (xAuth) can be enabled or not depending on your appl ication. For detailed info, you can refer to XXX. 7) Under “IKE Proposal”, select the Encryption and Authentication Algorithm.
ZyW ALL 2WG Support Notes All contents c opyright (c) 2006 ZyXEL Comm unications Corporat ion. 51 10) Click on the icon to add a new “Network Po licy” over the configured Gateway Policy . 11) Activate the profile and name this policy as “PC1-t o-Dept1” in this exam ple.
ZyW ALL 2WG Support Notes All contents c opyright (c) 2006 ZyXEL Comm unications Corporat ion. 52 14) Under “Remote Network”, choose “Single” and input “192.168.1.101” for PC1 in this example. 15) Under “IPSec Proposal”, select the Encryption and Authentication Algorithm.
ZyW ALL 2WG Support Notes All contents c opyright (c) 2006 ZyXEL Comm unications Corporat ion. 53 18) Follow the same procedures as step 10~16 to add 2 nd Network Policy , PC2-to-Dept2. Finish Using Certificate for Device Authentication IKE must authenticate the identities of the systems using the Dif fie-Hellman algorithm.
ZyW ALL 2WG Support Notes All contents c opyright (c) 2006 ZyXEL Comm unications Corporat ion. 54 DNS, E-mail, Subject Name and Any . Depending how certificates are generated, it ca n be classified in.
ZyW ALL 2WG Support Notes All contents c opyright (c) 2006 ZyXEL Comm unications Corporat ion. 55 The factory default self-signe d certificates are the same on all ZyW ALL models.
ZyW ALL 2WG Support Notes All contents c opyright (c) 2006 ZyXEL Comm unications Corporat ion. 56 2) Or mark the certificate in PEM (Base-64) Encoded Format and then copy to a test editor (e.g. Notepad) and then save to you local computer in PEM (Base-64) Encoded Format.
ZyW ALL 2WG Support Notes All contents c opyright (c) 2006 ZyXEL Comm unications Corporat ion. 57 When you configure VPN rule with certificate, select Certificate under VPN-> Gateway Policy.
ZyW ALL 2WG Support Notes All contents c opyright (c) 2006 ZyXEL Comm unications Corporat ion. 58 servers, and finally get a certificate for further usage.
ZyW ALL 2WG Support Notes All contents c opyright (c) 2006 ZyXEL Comm unications Corporat ion. 59 Step 2. Create certificate reque st and enroll certificate reque st on ZyWALL A 1. Input a name, for this Certificat e so you can identify this Cer tificate later.
ZyW ALL 2WG Support Notes All contents c opyright (c) 2006 ZyXEL Comm unications Corporat ion. 60 After pressing the Apply button, ZyWALL would create the certification request and send it to the CA server for enrollment. It may take one minutes to complete the whole p rocess.
ZyW ALL 2WG Support Notes All contents c opyright (c) 2006 ZyXEL Comm unications Corporat ion. 61 1. Input a name, for this Certificat e so you can identify this Cer tificate later. 2. In Subject Information, give this certificate a Common Name by either Host IP Address, Host Domain Name or E-Mail address.
ZyW ALL 2WG Support Notes All contents c opyright (c) 2006 ZyXEL Comm unications Corporat ion. 62 After pressing the Apply button, ZyWALL would create the certification request and send it to the CA server for enrollment.
ZyW ALL 2WG Support Notes All contents c opyright (c) 2006 ZyXEL Comm unications Corporat ion. 63 13. You can check detailed settings by clicking Advanced button.
ZyW ALL 2WG Support Notes All contents c opyright (c) 2006 ZyXEL Comm unications Corporat ion. 64 Step 5. Using Certifica e in VPN on ZyWALL B t 1. Activate the rule 2. Give this VPN rule a name " toZyWALL_A " 3. Select Key Management to " IKE " 4.
ZyW ALL 2WG Support Notes All contents c opyright (c) 2006 ZyXEL Comm unications Corporat ion. 65 13. You can check detailed settings by clicking Advanced button.
ZyW ALL 2WG Support Notes All contents c opyright (c) 2006 ZyXEL Comm unications Corporat ion. 66 Offline Enroll Certificates In this guide, we describe how ZyW ALL devices, both ZyW ALL A and ZyW ALL B as IPSec/VPN tunnel end points, authenticate each other through PKI.
ZyW ALL 2WG Support Notes All contents c opyright (c) 2006 ZyXEL Comm unications Corporat ion. 67 LAN 1 ZyW AL L A ZyW AL L B LAN 2 10.1.133.0/24 LAN: 10.1.133.1 WAN: 192.168.1.35 LAN: 192.168.2.1 WAN: 192.168.1.36 192.168.2.0/24 t Step 1. Create Certifi cate Reques on ZyWALL A 1.
ZyW ALL 2WG Support Notes All contents c opyright (c) 2006 ZyXEL Comm unications Corporat ion. 68 2. Input a name, for this Certific ate so you can identify this Certificate later. In Subject Inf ormation, give this certificate a Common Name by either Host IP Address, Host Domai n Name or E-Mail address.
ZyW ALL 2WG Support Notes All contents c opyright (c) 2006 ZyXEL Comm unications Corporat ion. 69 5. In My Certificat es tab, you can get a new entry in grey color. This is the Certific ate Request you just created. Click Details to export the request.
ZyW ALL 2WG Support Notes All contents c opyright (c) 2006 ZyXEL Comm unications Corporat ion. 70 In this support note, we utilize certificate enrollment service from Microsof t Window s 2000 CA server . The enrollment procedure of your CA server may be different, you ma y need to check your CA service provider for details.
ZyW ALL 2WG Support Notes All contents c opyright (c) 2006 ZyXEL Comm unications Corporat ion. 71 3, Select Request a Certificate , then press Next> button.
ZyW ALL 2WG Support Notes All contents c opyright (c) 2006 ZyXEL Comm unications Corporat ion. 72 4. Choose Advanced r equest , the press Next> button.
ZyW ALL 2WG Support Notes All contents c opyright (c) 2006 ZyXEL Comm unications Corporat ion. 73 5. Choose " Submit a c ertificate request using a base64.
ZyW ALL 2WG Support Notes All contents c opyright (c) 2006 ZyXEL Comm unications Corporat ion. 74 6. Right click your mouse, then paste the certif icate request y ou get in step 2.
ZyW ALL 2WG Support Notes All contents c opyright (c) 2006 ZyXEL Comm unications Corporat ion. 75 7. Click " Download CA cer tification path " 8. A file download would pop out, press Save button, and choose the local folder you would like to store th e certification path.
ZyW ALL 2WG Support Notes All contents c opyright (c) 2006 ZyXEL Comm unications Corporat ion. 76 9. Double click the saved file, Select Certificates , right click the Certificate, choose All Tasks-> Export... 10. Certificate Export Wizard would be popped up, then press Next> .
ZyW ALL 2WG Support Notes All contents c opyright (c) 2006 ZyXEL Comm unications Corporat ion. 77 11. Choose DER encoded binary X.509(.CE R) , then press Nxet> , 12.
ZyW ALL 2WG Support Notes All contents c opyright (c) 2006 ZyXEL Comm unications Corporat ion. 78 13. Click Finish . 14. Go to ZyWALL WEB GUI -> VPN -> My Certificates -> click Import button. 15. Click Browse... button to find the location you st ored ZyWALL's certificate the n press Apply button.
ZyW ALL 2WG Support Notes All contents c opyright (c) 2006 ZyXEL Comm unications Corporat ion. 79 16. After a while, if you see the gray entry turns to a black o ne, then it means the import of ZyWALL's certificate is successful. 17. Repeat the same procedure from 9 to 13, to export CA's cert ificate.
ZyW ALL 2WG Support Notes All contents c opyright (c) 2006 ZyXEL Comm unications Corporat ion. 80 After import CA's certificate, you will get this display. t Step 3. Create Certifi cate Reques on ZyWALL_B 1. Go to VPN -> My Certificates -> Click Create but ton.
ZyW ALL 2WG Support Notes All contents c opyright (c) 2006 ZyXEL Comm unications Corporat ion. 81 2. Input a name, for this Certific ate so you can identify this Certificate later. In Subject Inf ormation, give this certificate a Common Name by either Host IP Address, Host Domai n Name or E-Mail address.
ZyW ALL 2WG Support Notes All contents c opyright (c) 2006 ZyXEL Comm unications Corporat ion. 82 3. Wait for 1-2 minutes until " Request Generation Successful " displays. During this period, ZyWALL is working on creation of private, public key pair, and certificat e request.
ZyW ALL 2WG Support Notes All contents c opyright (c) 2006 ZyXEL Comm unications Corporat ion. 83 Step 4. Enroll Certificate Request on ZyWALLB 1. Copy the content of Certificate in PEM Encoded Format, by se lecting all of the content, then right click your mouse, and select Copy .
ZyW ALL 2WG Support Notes All contents c opyright (c) 2006 ZyXEL Comm unications Corporat ion. 84 3, Select Request a Certificate , then press Next> button.
ZyW ALL 2WG Support Notes All contents c opyright (c) 2006 ZyXEL Comm unications Corporat ion. 85 4. Choose Advanced r equest , the press Next> button.
ZyW ALL 2WG Support Notes All contents c opyright (c) 2006 ZyXEL Comm unications Corporat ion. 86 5. Choose " Submit a c ertificate request using a base64.
ZyW ALL 2WG Support Notes All contents c opyright (c) 2006 ZyXEL Comm unications Corporat ion. 87 6. Right click your mouse, then paste the certif icate request y ou get in step 4.
ZyW ALL 2WG Support Notes All contents c opyright (c) 2006 ZyXEL Comm unications Corporat ion. 88 7. Click " Download CA cer tification path " 8. A file download would pop out, press Save button, and choose the local folder you would like to store th e certification path.
ZyW ALL 2WG Support Notes All contents c opyright (c) 2006 ZyXEL Comm unications Corporat ion. 89 9. Double click the saved file, Select Certificates , right click the Certificate, choose All Tasks-> Export... 10. Certificate Export Wizard would be popped up, then press Next> .
ZyW ALL 2WG Support Notes All contents c opyright (c) 2006 ZyXEL Comm unications Corporat ion. 90 11. Choose DER encoded binary X.509(.CE R) , then press Nxet> ,.
ZyW ALL 2WG Support Notes All contents c opyright (c) 2006 ZyXEL Comm unications Corporat ion. 91 12. Specify the path to sto re your exported Certificate.
ZyW ALL 2WG Support Notes All contents c opyright (c) 2006 ZyXEL Comm unications Corporat ion. 92 13. Click Finish . 14. Go to ZyWALL WEB GUI -> VPN -> My Certificates -> click Import button. 15. Click Browse... button to find the location you st ored ZyWALL's certificate the n press Apply button.
ZyW ALL 2WG Support Notes All contents c opyright (c) 2006 ZyXEL Comm unications Corporat ion. 93 16. After a while, if you see the gray entry turns to a black o ne, then it means the import of ZyWALL's certificate is successful. 17. Repeat the same procedure from 9 to 13, to export CA's cert ificate.
ZyW ALL 2WG Support Notes All contents c opyright (c) 2006 ZyXEL Comm unications Corporat ion. 94 18. After import CA's certificate, you will get this display. Step 5. Using Certifica e in VPN on ZyWALL A t 1. Activate the rule 2. Give this VPN rule a name " toZyWALL_B " 3.
ZyW ALL 2WG Support Notes All contents c opyright (c) 2006 ZyXEL Comm unications Corp oration. 95 9. Peer ID type= " ANY ". 10. Secure Gateway Address= " 192.168.1.36 " 11. Encapsulation Mode=" Tunnel " 12. Leave other options as default.
ZyW ALL 2WG Support Notes All contents c opyright (c) 2006 ZyXEL Comm unications Corporat ion. 96 13. You can check detailed settings by clicking Advanced button.
ZyW ALL 2WG Support Notes All contents c opyright (c) 2006 ZyXEL Comm unications Corporat ion. 97 Step 6. Using Certificate in VPN on ZyWALL B 1. Activate the rule 2. Give this VPN rule a name " toZyWALL_A " 3. Select Key Management to " IKE " 4.
ZyW ALL 2WG Support Notes All contents c opyright (c) 2006 ZyXEL Comm unications Corporat ion. 98 13. You can check detailed settings by clicking Advanced button.
ZyW ALL 2WG Support Notes All contents c opyright (c) 2006 ZyXEL Comm unications Corporat ion. 99 Using Pre-Shared Key for Device Authentication The IKE protocol also provides primary authenticati on - ver i fying the identity of the remote system before negotiating the encryption algorithm and keys.
ZyW ALL 2WG Support Notes All contents c opyright (c) 2006 ZyXEL Comm unications Corporat ion. 100 Pre- Shared Key must be identica l on bot h e ntities Local ID Type & Content on L ocal ZyWAL L m.
ZyW ALL 2WG Support Notes All contents c opyright (c) 2006 ZyXEL Comm unications Corporat ion. 101 As the figure shown below, each branch office have a VPN tunnel to headquarter, thus PCs in branch offices can access systems in headquarter via the tunnel.
ZyW ALL 2WG Support Notes All contents c opyright (c) 2006 ZyXEL Comm unications Corp oration. 102 2. check Activ e check box and give a name to this policy. 3. Give this VPN rule a name, Br anch_A . 4. Select Key Management to IKE and Negotiation Mode to Main .
ZyW ALL 2WG Support Notes All contents c opyright (c) 2006 ZyXEL Comm unications Corporat ion. 103 You can setup IKE phase 1 and phase 2 parameters by pressing Advanced button. Please make sure th at parameters you set in this menu match with all the parameters w ith the correspondent VPN rule in headquarter.
ZyW ALL 2WG Support Notes All contents c opyright (c) 2006 ZyXEL Comm unications Corporat ion. 104 2. Setup VPN in branch office B Be very careful about the remote IP address in branch office B, because for systems behind branch office B want to systems behind branch office A and headquarter, we have to specify these two segments in Remote section.
ZyW ALL 2WG Support Notes All contents c opyright (c) 2006 ZyXEL Comm unications Corporat ion. 105.
ZyW ALL 2WG Support Notes All contents c opyright (c) 2006 ZyXEL Comm unications Corporat ion. 106 Note that since Branch B's LAN is also included in remote polic y, please go to ZyWALL's SMT menu 24.
ZyW ALL 2WG Support Notes All contents c opyright (c) 2006 ZyXEL Comm unications Corporat ion. 107.
ZyW ALL 2WG Support Notes All contents c opyright (c) 2006 ZyXEL Comm unications Corporat ion. 108 2. The correspondent rule for Branch_B.
ZyW ALL 2WG Support Notes All contents c opyright (c) 2006 ZyXEL Comm unications Corporat ion. 109.
ZyW ALL 2WG Support Notes All contents c opyright (c) 2006 ZyXEL Comm unications Corporat ion. 11 0 NA T over IPSec on ZyNOS Network T opology The above is an IPSec VPN application running in tunnel mode. In the network topology shown, both the local area networks (LAN) are a ssigned with the sam e network IP/network mask 172.
ZyW ALL 2WG Support Notes All contents c opyright (c) 2006 ZyXEL Comm unications Corporat ion. 111 change at least one of the LAN IP addresses in or der to prevent the routi ng problem. Unfortunately, changing the entire network settin g takes extra effort in configur ation, which is never preferable.
ZyW ALL 2WG Support Notes All contents c opyright (c) 2006 ZyXEL Comm unications Corporat ion. 11 2 ZyWALL 2 (Remote) STEP 2: Create the Gateway Policy (Pha se 1) on the ZyWALL 1 and ZyWALL 2 Click Security > VPN > Add Gateway Policy in or der to add a new IPSec VPN Gateway Policy.
ZyW ALL 2WG Support Notes All contents c opyright (c) 2006 ZyXEL Comm unications Corporat ion. 11 3 Gateway Policy on ZyWALL 1 Click “Apply” in order to complete the settings.
ZyW ALL 2WG Support Notes All contents c opyright (c) 2006 ZyXEL Comm unications Corporat ion. 11 4 Gateway Policy on ZyWALL 2 Gateway Policy on ZyWALL 2 STEP 3: Create the Network Policy (Pha se 2) o.
ZyW ALL 2WG Support Notes All contents c opyright (c) 2006 ZyXEL Comm unications Corporat ion. 11 5 policy. Check the “Active” checkbox in the “Virtual Address Mapping Rule” bl ock to enable NAT over IPSec. You can decide the amount of IP addresses for NAT (Network Address Translation) from the “Type” drop-down menu.
ZyW ALL 2WG Support Notes All contents c opyright (c) 2006 ZyXEL Comm unications Corporat ion. 11 6 On ZyWALL 1, the remote network will be changed to 172.1 6.3.0. Click “Apply” in order to complete the setting. Repeat the steps for ZyWALL 2 in order to configure Network Policy.
ZyW ALL 2WG Support Notes All contents c opyright (c) 2006 ZyXEL Comm unications Corporat ion. 11 7 On ZyWALL 2, the Virtual IP Addresses starts from 172.
ZyW ALL 2WG Support Notes All contents c opyright (c) 2006 ZyXEL Comm unications Corporat ion. 11 8 Click Security > VPN > Connect in order to establish the IPSec VPN Tunnel connection. Once the IPSec works correctly, you will see the message as it appears in the following screensho t, and click “Return” to back to VPN page.
ZyW ALL 2WG Support Notes All contents c opyright (c) 2006 ZyXEL Comm unications Corporat ion. 11 9 1) Ping the local gateway. 2) Ping the IPSec Remote Gateway 3) Ping the remote host with virtual IP addr ess that’s located on the remote network. Never lost your VPN connection (IPSec High Availa bility) 1.
ZyW ALL 2WG Support Notes All contents c opyright (c) 2006 ZyXEL Comm unications Corporat ion. 120 The VPN high availability is design for securing VPN connection . Normally we will deploy the ZyWALL2 Plus as branch office or SOHO gateway and build up the VPN tunn el to central office.
ZyW ALL 2WG Support Notes All contents c opyright (c) 2006 ZyXEL Comm unications Corporat ion. 121 3. Give a name for your policy, for example “ Dual_GW_VPN ” 4. My IP Addr is the WAN IP of ZyWALL . In this exam ple, you should type 220.123.23.7 IP address on My ZyW ALL text box.
ZyW ALL 2WG Support Notes All contents c opyright (c) 2006 ZyXEL Comm unications Corporat ion. 122.
ZyW ALL 2WG Support Notes All contents c opyright (c) 2006 ZyXEL Comm unications Corporat ion. 123 Access control and security VPN connecti on (Security policy enforcement IPSec) Setup ZyW ALL VPN wit.
ZyW ALL 2WG Support Notes All contents c opyright (c) 2006 ZyXEL Comm unications Corporat ion. 124 3. For example, the remote VPN policy is 192.168.2.0/24 and we want to block the traffic from 192.
ZyW ALL 2WG Support Notes All contents c opyright (c) 2006 ZyXEL Comm unications Corporat ion. 125 4. Click the Insert button to insert a new rule. 5. Edit the source and destination address as 192.
ZyW ALL 2WG Support Notes All contents c opyright (c) 2006 ZyXEL Comm unications Corporat ion. 126 6. The service type is Any to block all kind of traffi c from 192.168.2.33 to access LAN subnet and Action for Matched Packets is Drop and then click apply to save and activ ate the configuration.
ZyW ALL 2WG Support Notes All contents c opyright (c) 2006 ZyXEL Comm unications Corporat ion. 127 7. We can see a new rule had been configured and showed in th e rule summary page. This will achieve our goal to block all traffic fr om VPN remote host 192.
ZyW ALL 2WG Support Notes All contents c opyright (c) 2006 ZyXEL Comm unications Corporat ion. 128 How to configure Web filtering ru le over VPN – Content Filter 1. The switch to enable the content filtering over VPN traffic is available in Content Filter general configuration page.
ZyW ALL 2WG Support Notes All contents c opyright (c) 2006 ZyXEL Comm unications Corp oration. 129.
ZyW ALL 2WG Support Notes All contents c opyright (c) 2006 ZyXEL Comm unications Corporat ion. 130 ZyW ALL vs 3rd Party VPN Gateway SonicW ALL with ZyW ALL VPN T unneling 1. Setup ZyWALL VPN 2. Setup SonicWALL VPN This page guides us to setup a VPN connect ion between the ZyWALL a nd SonicWALL router.
ZyW ALL 2WG Support Notes All contents c opyright (c) 2006 ZyXEL Comm unications Corporat ion. 131 11. Go to SECURITY->VPN->Press Add button 12. Give a name for your policy, for example “ ToSonicWALL ” 13. My IP Addr is the WAN IP of ZyWALL .
ZyW ALL 2WG Support Notes All contents c opyright (c) 2006 ZyXEL Comm unications Corporat ion. 132 16. Select Negotiation Mode to Main mode , Encryption Algorithm to DES , Authentication Algorithm to MD5 , Key Group to DH1 , and then press Apply button on this page.
ZyW ALL 2WG Support Notes All contents c opyright (c) 2006 ZyXEL Comm unications Corporat ion. 133 18. Check Active check box and give a name to this policy. 19. On Gateway Policy Information, you should choose ToSonicWALL IKE policy for your IPSec rule.
ZyW ALL 2WG Support Notes All contents c opyright (c) 2006 ZyXEL Comm unications Corporat ion. 134 20. On Local Network, choose Subnet Address for your Address Type. Starting IP Address and Ending IP Address/Subnet are your local site LAN IP addre sses.
ZyW ALL 2WG Support Notes All contents c opyright (c) 2006 ZyXEL Comm unications Corporat ion. 135 23. When you finished doing your settings, you will see the following page. 2. Setup SonicWALL VPN (We choose SonicWALL TZ150 device in this example.) 1.
ZyW ALL 2WG Support Notes All contents c opyright (c) 2006 ZyXEL Comm unications Corporat ion. 136 2. Click General tab, on Security Policy settings, give a name to this policy. In this example, type ToZyWALL on Name text box. IPSec Primary Gatew ay Name or Address is the ZyW ALL 's WAN IP Address (remote gateway IP address).
ZyW ALL 2WG Support Notes All contents c opyright (c) 2006 ZyXEL Comm unications Corporat ion. 137 4. Network IP Address and Subnet Mask are your remote site LAN IP addresses. In this exam ple, you should type 192.168.1.0 on Network text box and then type 255.
ZyW ALL 2WG Support Notes All contents c opyright (c) 2006 ZyXEL Comm unications Corporat ion. 138 6. When you finished doing your settings, you will see the following page.
ZyW ALL 2WG Support Notes All contents c opyright (c) 2006 ZyXEL Comm unications Corporat ion. 139 NetScreen with ZyW ALL VPN T unneling 1. Setup ZyWALL VPN 2. Setup NetScreen VPN This page guides us to setup a VPN connect ion between the ZyWALL a nd NetScreen router.
ZyW ALL 2WG Support Notes All contents c opyright (c) 2006 ZyXEL Comm unications Corporat ion. 140 The IP addresses we use in this example are as shown below. PC 1 ZyWALL Netscreen PC2 192.168.2.33 WAN: 172.22.3.89 LAN: 192.168.2.1 WAN: 172.22.1.251 LAN: 192.
ZyW ALL 2WG Support Notes All contents c opyright (c) 2006 ZyXEL Comm unications Corporat ion. 141 6. In Authentication Key , enter the key string 12345678 in the Pre-Shared Key text box.
ZyW ALL 2WG Support Notes All contents c opyright (c) 2006 ZyXEL Comm unications Corporat ion. 142 8. You will see an IKE rule on your VPN page, click L/R button to edit your IPSec rule. 9. Check Active check box and give a name to this policy. 10. On Gateway Policy Information, you should choose ToNetScreen IKE policy for your IPSec rule.
ZyW ALL 2WG Support Notes All contents c opyright (c) 2006 ZyXEL Comm unications Corporat ion. 143 type 192.168.2.0 on Starting IP Address field and then type 255.255.255.0 on Ending IP Address/Subnet field. 12. On Remote Network, choose Subnet Address for your Address Type.
ZyW ALL 2WG Support Notes All contents c opyright (c) 2006 ZyXEL Comm unications Corporat ion. 144 14. When you finished doing your settings, you will see the following page. 2. Setup NetScreen VPN (We choose NetScreen-5GT device in this example.) 3. Using a web browser, login NetScreen by giving th e LAN IP address of NetS creen in URL field.
ZyW ALL 2WG Support Notes All contents c opyright (c) 2006 ZyXEL Comm unications Corporat ion. 145 Note: About the settings, you could reference to Ne tScreen user guide to get the d etail info. 5. If you set a static IP address for your WAN port, you should click Network -> Routing -> Routing Entries to edit your Gateway IP address.
ZyW ALL 2WG Support Notes All contents c opyright (c) 2006 ZyXEL Comm unications Corporat ion. 146 6. On Security Level settings, you could set up phase 1 IKE rules.
ZyW ALL 2WG Support Notes All contents c opyright (c) 2006 ZyXEL Comm unications Corporat ion. 147 8. To edit your IPSec rule, click VPNs -> AutoKey IKE , and then press New button to edit your IPSec rules. 9. Give a name for your VPN, for example “ ToZyWALL IPSec ”.
ZyW ALL 2WG Support Notes All contents c opyright (c) 2006 ZyXEL Comm unications Corporat ion. 148 11. Check VPN Monitor check box, thus you can monitor your VP N tunnels. Then, press Return button, and press OK button on next pa ge to save your settings.
ZyW ALL 2WG Support Notes All contents c opyright (c) 2006 ZyXEL Comm unications Corporat ion. 149 14. Give a name for your policy, for example “ ZyWALL & NetScreen ”. 15. On Source Address , you should set up Local LAN IP addresses. In this example, select New Address option, and type 192.
ZyW ALL 2WG Support Notes All contents c opyright (c) 2006 ZyXEL Comm unications Corporat ion. 150 17. When you finished doing the settings, you will see the policy rules on the page.
ZyW ALL 2WG Support Notes All contents c opyright (c) 2006 ZyXEL Comm unications Corporat ion. 151 18. Move your policy rules to top, thus your device will check the rule at first. 19. Click VPNs -> Monitor Status, this page displays a table that lists all the VPN groups configured on the NetScreen device.
ZyW ALL 2WG Support Notes All contents c opyright (c) 2006 ZyXEL Comm unications Corporat ion. 152 This page guides us to setup a VPN connection be tween the ZyWALL and a PC which uses Check Point software. As the figure shown below, the tunnel between PC1 and PC2 ensures the packet flows between them are secure.
ZyW ALL 2WG Support Notes All contents c opyright (c) 2006 ZyXEL Comm unications Corporat ion. 153 3. Give a name for your policy, for example “ ToCheckPoint ” 4. My IP Addr is the WAN IP of ZyWALL . In this exam ple, you should type 172.22.1.236 IP address on My ZyW ALL text box.
ZyW ALL 2WG Support Notes All contents c opyright (c) 2006 ZyXEL Comm unications Corporat ion. 154 7. Select Negotiation Mode to Main mode , Encryption Algorithm to DES , Authentication Algorithm to MD5 , Key Group to DH1 , and then press Apply button on this page.
ZyW ALL 2WG Support Notes All contents c opyright (c) 2006 ZyXEL Comm unications Corporat ion. 155 10. On Gateway Policy Information, you should choose ToCheckPoint IKE policy for your IPSec rule. 11. On Local Network, choose Subnet Address for your Address Type.
ZyW ALL 2WG Support Notes All contents c opyright (c) 2006 ZyXEL Comm unications Corporat ion. 156 13. On IPSec Proposal, select Encapsulation Mode to Tunnel, Active Protocol to ESP, Encryption Algorithm to DES and Authentication Algorithm to SHA1 , and then press Apply button on this page.
ZyW ALL 2WG Support Notes All contents c opyright (c) 2006 ZyXEL Comm unications Corporat ion. 157 1. on your PC, clicking Start->Programmer->Check Point SmartConsole R60 -> Sm artDashboard 2. Enter your user name and password, then press OK button to use your Check Point.
ZyW ALL 2WG Support Notes All contents c opyright (c) 2006 ZyXEL Comm unications Corporat ion. 158 6. On General Properties , the IP Addrrss field is the WAN IP of your PC . In this example, you should type 172.22.2.58 IP address on the text box. On Check Point Products settings, check VPN check box here.
ZyW ALL 2WG Support Notes All contents c opyright (c) 2006 ZyXEL Comm unications Corporat ion. 159 7. On Topology settings, you should see two interfaces of IP settings here if your PC has two network cards.
ZyW ALL 2WG Support Notes All contents c opyright (c) 2006 ZyXEL Comm unications Corporat ion. 160 8. Selecting 172.22.2.58 interface , and press Edit button to check its settings. Clicking Topology screen, choose External (leads out to the internet) for the interface.
ZyW ALL 2WG Support Notes All contents c opyright (c) 2006 ZyXEL Comm unications Corporat ion. 161 II. Setup Interoperable Device 10. On the main menu, click Manage -> Network Objects .
ZyW ALL 2WG Support Notes All contents c opyright (c) 2006 ZyXEL Comm unications Corporat ion. 162 11. You will see the network objects window, press new button and select Interoperable Device .
ZyW ALL 2WG Support Notes All contents c opyright (c) 2006 ZyXEL Comm unications Corporat ion. 163 12. On General Properties settings, give a name and an IP addre ss for the Interoperable Device. In this example, the IP address is ZyWA LL’s WAN IP address.
ZyW ALL 2WG Support Notes All contents c opyright (c) 2006 ZyXEL Comm unications Corporat ion. 164 14. Giving a name for the interface, and assign the IP address/ subnet mask for the in terface. In this example, you should assign ZyWALL’s WAN port settings.
ZyW ALL 2WG Support Notes All contents c opyright (c) 2006 ZyXEL Comm unications Corporat ion. 165 17. Giving a name for the interface, and assign the IP address/ subnet mask for the in terface. In this example, you should assign ZyWALL’s LAN port settings.
ZyW ALL 2WG Support Notes All contents c opyright (c) 2006 ZyXEL Comm unications Corporat ion. 166 19. Pressing OK button to save the settings..
ZyW ALL 2WG Support Notes All contents c opyright (c) 2006 ZyXEL Comm unications Corporat ion. 167 III. Setup Networks.
ZyW ALL 2WG Support Notes All contents c opyright (c) 2006 ZyXEL Comm unications Corporat ion. 168 20. Selecting Networks object and click the right bu tton of your mouse, and choose New Network . 21. Give a name for your network policy, and set the network IP address to 192.
ZyW ALL 2WG Support Notes All contents c opyright (c) 2006 ZyXEL Comm unications Corporat ion. 169 22. To add another network policy, and set the netw ork IP address 192.168.2.0/24 . Then, press OK button to save the settings. IV. Setup VPN Communities 23.
ZyW ALL 2WG Support Notes All contents c opyright (c) 2006 ZyXEL Comm unications Corporat ion. 170 26. On Center Gateways settings, press Add button to add a center gateway.
ZyW ALL 2WG Support Notes All contents c opyright (c) 2006 ZyXEL Comm unications Corporat ion. 171 27. If you have already done the pr evious settings, you should see a cen tral gateway here. Select the gateway, and then press OK button. 28. On Satellite Gateways settings, press Add button to add a remote gateway.
ZyW ALL 2WG Support Notes All contents c opyright (c) 2006 ZyXEL Comm unications Corporat ion. 172 29. If you have already done the pr evious settings, you should see a re mote gateway here.
ZyW ALL 2WG Support Notes All contents c opyright (c) 2006 ZyXEL Comm unications Corporat ion. 173 31. On Tunnel Management , leave the settings to default settings. 32. On VPN routing settings, choose To center, or through the center to other satellites, to inte rnet and other VPN targets option.
ZyW ALL 2WG Support Notes All contents c opyright (c) 2006 ZyXEL Comm unications Corporat ion. 174 33. On Shared Secret settings, choose ToZyWALL option, and press Edit button 34. Enter the secret key in th e text box, and then press OK button. 35. On Advanced VPN Properties settings, choose Group 1 for Diffie-Hellman settings.
ZyW ALL 2WG Support Notes All contents c opyright (c) 2006 ZyXEL Comm unications Corporat ion. 175 36. Press OK button to save your settings..
ZyW ALL 2WG Support Notes All contents c opyright (c) 2006 ZyXEL Comm unications Corporat ion. 176 37. After you press OK button, you s hould see a new object here. IV. Setup Security 38. Click Security tab on the right side to do the security settings.
ZyW ALL 2WG Support Notes All contents c opyright (c) 2006 ZyXEL Comm unications Corporat ion. 177 39. Press Add button to add a rule. 40. On the default rule, select the source field, and click right button of your mouse, and then choose Add… option to add your network objects.
ZyW ALL 2WG Support Notes All contents c opyright (c) 2006 ZyXEL Comm unications Corporat ion. 178 42. To use the same way to add another network object ( Net_192.168.2.0 ) on the source field. 43. On the destination field, please use the same way to add your network objects: N et_192.
ZyW ALL 2WG Support Notes All contents c opyright (c) 2006 ZyXEL Comm unications Corporat ion. 179 44. On the VPN field, click right button of your mouse, and choose Edit Cell… option to add your VPN communities.
ZyW ALL 2WG Support Notes All contents c opyright (c) 2006 ZyXEL Comm unications Corporat ion. 180 47. Clicking OK button to save your settings. 48. On action field, click right bu tton of your mouse, and choose accept option for your rule.
ZyW ALL 2WG Support Notes All contents c opyright (c) 2006 ZyXEL Comm unications Corporat ion. 181 49. On the track field, click right button of your mouse, and choose Log option for your rule. 50. If you finished the settings, you should see a rule as below.
ZyW ALL 2WG Support Notes All contents c opyright (c) 2006 ZyXEL Comm unications Corporat ion. 182 51. Pressing add button to add anot her rule which could drop packets if it doesn’t match your VPN rule. V. Install Policy 52. On your main menu, click Policy -> In stall.
ZyW ALL 2WG Support Notes All contents c opyright (c) 2006 ZyXEL Comm unications Corporat ion. 183 54. Waiting few seconds for the installation..
ZyW ALL 2WG Support Notes All contents c opyright (c) 2006 ZyXEL Comm unications Corporat ion. 184 55. If you install the policy successfully, your VPN tunnel should work norm ally with your ZyWALL.
ZyW ALL 2WG Support Notes All contents c opyright (c) 2006 ZyXEL Comm unications Corporat ion. 185 FortiNet with ZyW A LL VPN T unneling 1. Setup ZyWALL VPN 2. Setup FortiNet VPN This page guides us to setup a VPN connect ion between the ZyWALL a nd FortiNet router.
ZyW ALL 2WG Support Notes All contents c opyright (c) 2006 ZyXEL Comm unications Corporat ion. 186 The IP addresses we use in this example are as shown below. ZyWALL FortiNet WAN: 172.22.1.147 LAN: 192.168.2.0/24 WAN: 172.22.2.138 LAN: 192.168.1.0/24 1.
ZyW ALL 2WG Support Notes All contents c opyright (c) 2006 ZyXEL Comm unications Corporat ion. 187 6. In Authentication Key , enter the key string 12345678 in the Pre-Shared Key text box.
ZyW ALL 2WG Support Notes All contents c opyright (c) 2006 ZyXEL Comm unications Corporat ion. 188 8. After you press the Apply button, you will see an IKE rule on this page, click L/R button to edit your IPSec rule. 9. Check Active check box and give a name to this policy.
ZyW ALL 2WG Support Notes All contents c opyright (c) 2006 ZyXEL Comm unications Corporat ion. 189 12. On Remote Network, choose Subnet Address for your Address Type. Starting IP Address and Ending IP Address/Subnet are your remote site LAN IP addr esses.
ZyW ALL 2WG Support Notes All contents c opyright (c) 2006 ZyXEL Comm unications Corporat ion. 190 14. After you press the Apply button, you will see the following page. 2. Setup FortiNet VPN (We choose FortiGate-60 device in this example.) 1. Using a web browser, login FortiNet by giving th e LAN IP address of FortiNet in URL field.
ZyW ALL 2WG Support Notes All contents c opyright (c) 2006 ZyXEL Comm unications Corporat ion. 191 4. On P1 proposal settings, select Encryption to DES , Authentication to MD5, and DH Group to Group1 . Then, press “-” button to delete the second P1 proposal rules.
ZyW ALL 2WG Support Notes All contents c opyright (c) 2006 ZyXEL Comm unications Corporat ion. 192 6. After you press the OK button, you will see a Phase 1 rule on this pag e. 7. To edit your IPSec rule(phase 2), click VPN -> IPSec -> Phase 2 , and then press Create New button to edit your IPSec rules.
ZyW ALL 2WG Support Notes All contents c opyright (c) 2006 ZyXEL Comm unications Corporat ion. 193 9. On P2 Proposal settings, select Encryption to DES , and Authentication to SHA1 , and also press “-” button to delete the second P2 proposal rules.
ZyW ALL 2WG Support Notes All contents c opyright (c) 2006 ZyXEL Comm unications Corporat ion. 194 11. After you press the OK button, you will see your IPSec rule(Phase2) on this page. 12. On the main page, click Firewall -> Address , and then press Create New button to edit your address rules.
ZyW ALL 2WG Support Notes All contents c opyright (c) 2006 ZyXEL Comm unications Corporat ion. 195 13. To define the IP source address of the Network behind FortiNet. Givi ng a name for your address rule, for example “ Fortinet network ”, and enter the IP Range/Subnet in the text box.
ZyW ALL 2WG Support Notes All contents c opyright (c) 2006 ZyXEL Comm unications Corporat ion. 196 17. On the main page, click Firewall -> Policy , and then press Create N ew button to edit your policy rules.
ZyW ALL 2WG Support Notes All contents c opyright (c) 2006 ZyXEL Comm unications Corporat ion. 197 21. After you press the OK button, you will the policy rule on this page. 22. Click VPN -> IPSec -> Monitor , this page displays a table that lists all the VPN rules configured on the FortiNet device.
ZyW ALL 2WG Support Notes All contents c opyright (c) 2006 ZyXEL Comm unications Corporat ion. 198 Remote Access VPN Scenario The remote access VPN scenario is to provide a remo te users secure connections to access corpo rate network over a public networking infrastructure.
ZyW ALL 2WG Support Notes All contents c opyright (c) 2006 ZyXEL Comm unications Corporat ion. 199 existing Internet Key Exchange (IKE) Protocol featur e. Xauth allows authentication methods to perform user authentication in a separate phase after the IK E authentication phase 1 exchange.
ZyW ALL 2WG Support Notes All contents c opyright (c) 2006 ZyXEL Comm unications Corporat ion. 200 Local User RADIUS When external “RADIUS” is selecte d, please input the Service IP addre ss of the external RADIUS server and the shared Key which must be configured on the RADIUS.
ZyW ALL 2WG Support Notes All contents c opyright (c) 2006 ZyXEL Comm unications Corporat ion. 201 1. Setup ZyW ALL VPN Client 2. Setup ZyW ALL This page guides us to setup a VPN connection between the VPN s oftware and ZyWALL router. There will be several devices we need to setup for this case.
ZyW ALL 2WG Support Notes All contents c opyright (c) 2006 ZyXEL Comm unications Corporat ion. 202 Remote Party Identity a nd Addressing settings: 4. In ID Type option, please choose IP Address option, and enter the IP address of the remote PC (PC 2 in thi s case).
ZyW ALL 2WG Support Notes All contents c opyright (c) 2006 ZyXEL Comm unications Corporat ion. 203 Pre-Share Key Sett ings: 6. Extend ZyWALL icon, you may see My Identity . 7. Click My Identity ; click the Pre-Shar ed Key icon in the right side of the window.
ZyW ALL 2WG Support Notes All contents c opyright (c) 2006 ZyXEL Comm unications Corporat ion. 204 Security Policy Settings: 9. Click Security Policy option to choose Main Mode as Phase 1 Negotiation .
ZyW ALL 2WG Support Notes All contents c opyright (c) 2006 ZyXEL Comm unications Corporat ion. 205 10. Extend Security Policy icon, you will see two icons, Authentication (Phase 1) and Key Exchange (Phase 2) . 11. The settings shown in the following two figures for both Ph ases are our examples.
ZyW ALL 2WG Support Notes All contents c opyright (c) 2006 ZyXEL Comm unications Corporat ion. 206.
ZyW ALL 2WG Support Notes All contents c opyright (c) 2006 ZyXEL Comm unications Corporat ion. 207 2. Setup ZyWALL VPN 1. Using a web browser , login ZyW ALL by giving th e LAN IP address of ZyW ALL in URL field. Default LAN IP is 192.168.1.1 , default password to login web configurator is 1234 .
ZyW ALL 2WG Support Notes All contents c opyright (c) 2006 ZyXEL Comm unications Corporat ion. 208 You can further adjust IKE Phase 1/Phase 2 parameters by pressi ng Advanced button.
ZyW ALL 2WG Support Notes All contents c opyright (c) 2006 ZyXEL Comm unications Corporat ion. 209 Content Filter Application T o filter non-work related and unproductive web surfi ng to mitigate spyware and phishing threat s W eb browsing is one of the most common activity people do on daily bases.
ZyW ALL 2WG Support Notes All contents c opyright (c) 2006 ZyXEL Comm unications Corporat ion. 210 1. Minimize Spywar e Attack As mentioned earlier, pornography websites are known to contain Spyware and Trojans, thus it is recommended to use ZyWALL 2 Plus to prevent users from access these ty pes of websites.
ZyW ALL 2WG Support Notes All contents c opyright (c) 2006 ZyXEL Comm unications Corporat ion. 21 1 “ Violence/Hate/Racism ”, “ Gay/Lesbian ”, “ Gambling ”, “ Illegal/Questionable ”, .
ZyW ALL 2WG Support Notes All contents c opyright (c) 2006 ZyXEL Comm unications Corporat ion. 212 2. Proactively Prevent Phishing Phishing – T he act of sending an email to a user fal sely claiming.
ZyW ALL 2WG Support Notes All contents c opyright (c) 2006 ZyXEL Comm unications Corporat ion. 213 2.1.2 Customize the Forbidden web sites which are known phishing w eb sites In addition to use external content filter server to do filtering policies, we can customize the filter policies as our own.
ZyW ALL 2WG Support Notes All contents c opyright (c) 2006 ZyXEL Comm unications Corporat ion. 214 3. Prevent non-business web surfing Below is an example that demonstrates how to configure the ZyW ALL 2 Plus CF service to prevent employee from surfing websites that are not related to work.
ZyW ALL 2WG Support Notes All contents c opyright (c) 2006 ZyXEL Comm unications Corporat ion. 215 3 . 2 Using external database content filtering If you have registered the CF service, you can en abl.
ZyW ALL 2WG Support Notes All contents c opyright (c) 2006 ZyXEL Comm unications Corporat ion. 216 to www.zyxel.com with “ (W ebsite Blocking) ” message displayed at the moment.
ZyW ALL 2WG Support Notes All contents c opyright (c) 2006 ZyXEL Comm unications Corporat ion. 217 T o manage your ZyW ALLs through V antage CNM, user needs to prepare V antage CNM server and 3rd party FTP/Syslog/T elnet servers. For the detailed in stallation & registration process (to myZyXEL.
ZyW ALL 2WG Support Notes All contents c opyright (c) 2006 ZyXEL Comm unications Corporat ion. 218 the following section, we will explain how to regi ster device m anually . Devices can be also added (imported) to V antage CNM through XML f iles. For detailed operation, please refer to V antage CNM Support Note .
ZyW ALL 2WG Support Notes All contents c opyright (c) 2006 ZyXEL Comm unications Corporat ion. 219 1. device type 2. device name 3. device's LAN MAC address The XML file can be used for mass deployment. User can assign a device owner or l eave it to the owner of folder AAA.
ZyW ALL 2WG Support Notes All contents c opyright (c) 2006 ZyXEL Comm unications Corporat ion. 220 S tep 4. On the device, go to ADV ANCED->REMOTE MGMT ->CNM , enable V antage CNM and configure V antage CNM Server Address in the filed.
ZyW ALL 2WG Support Notes All contents c opyright (c) 2006 ZyXEL Comm unications Corporat ion. 221 On V antage CNM, the device icon will turn green and the device status will chang e to “On” and the W AN IP of the device will be shown on the content screen.
ZyW ALL 2WG Support Notes All contents c opyright (c) 2006 ZyXEL Comm unications Corp oration. 222 A02. Will the Zy W ALL work wi th my Internet connection? The ZyWALL is designed to be compatible with most network envir onment (cable or xDSL modems).
ZyW ALL 2WG Support Notes All contents c opyright (c) 2006 ZyXEL Comm unications Corp oration. 223 A08. How can I configure the ZyW ALL? T elnet remote management- CLI command line W eb browser- web server em bedded for easy configurations A09.
ZyW ALL 2WG Support Notes All contents c opyright (c) 2006 ZyXEL Comm unications Corp oration. 224 table. Therefore, to m ake a local server accessible to the outsider , the port nu mber and the internal IP address of the server must be configured in NA T menu.
ZyW ALL 2WG Support Notes All contents c opyright (c) 2006 ZyXEL Comm unications Corp oration. 225 A20. My ZyW ALL can not get an IP address from the ISP to connect to the Internet, what can I do? Currently, there are various ways that ISPs control their users .
ZyW ALL 2WG Support Notes All contents c opyright (c) 2006 ZyXEL Comm unications Corp oration. 226 computer to be more easily accessed from various locat ions on the Internet. T o use the service, you must first apply an account from several free W eb servers such as WWW .
ZyW ALL 2WG Support Notes All contents c opyright (c) 2006 ZyXEL Comm unications Corp oration. 227 understand the ESP packet with protocol number 50, replace the source IP address of the IPSec gateway to the router's WAN IP address. However , NAT should not change the sou rce port of the UDP packets which are used for key managements.
ZyW ALL 2WG Support Notes All contents c opyright (c) 2006 ZyXEL Comm unications Corp oration. 228 B01. What is a network firewall? A firewall is a system or group of systems that enfo rces an access-control po licy between two networks. It may also be defined as a mechanism used to prot ect a trusted network from an un-trusted network.
ZyW ALL 2WG Support Notes All contents c opyright (c) 2006 ZyXEL Comm unications Corp oration. 229 B04. What kind of fire wall is the Zy WALL? 1. The ZyWALL's firewall inspects packets conten ts and IP headers.
ZyW ALL 2WG Support Notes All contents c opyright (c) 2006 ZyXEL Comm unications Corp oration. 230 B07. What is Ping of Death attack? Ping of Death uses a 'PING' utility to create an IP packet that exceed s the maximum 65535 bytes of data allowed by the IP specification.
ZyW ALL 2WG Support Notes All contents c opyright (c) 2006 ZyXEL Comm unications Corporat ion. 231 B12. What is IP Spoofing attack? Many DoS attacks also use IP Spoofing as part of th eir attack. IP Spoofing may be used to break into systems, to hide the hacker's identity, or to m agni fy the effect of the DoS attack.
ZyW ALL 2WG Support Notes All contents c opyright (c) 2006 ZyXEL Comm unications Corporat ion. 232 The above figure indicates the " triangle route " topology. It works fine if you turn off firewall function on ZyWALL box. However, if you turn on firewall, your connecti on will be blocked by firewall because of the following reason.
ZyW ALL 2WG Support Notes All contents c opyright (c) 2006 ZyXEL Comm unications Corp oration. 233 (C) T o resolve this conflict, we add an option for users to allow/disallow such T riangle Route topology in both CI command and W eb configurat or .
ZyW ALL 2WG Support Notes All contents c opyright (c) 2006 ZyXEL Comm unications Corp oration. 234 • Destination IP Mask =w.x.y.z • Action Matched =Drop • Action No Matched =Forward Where a.b.c.d is an IP address on your local network and w.x.y.
ZyW ALL 2WG Support Notes All contents c opyright (c) 2006 ZyXEL Comm unications Corp oration. 235 C06. What kind of iCard should I buy? It depends on the ZyW ALL m odel you have, the s ecurity service you desire and the license period you need. See the following table for those mappings.
ZyW ALL 2WG Support Notes All contents c opyright (c) 2006 ZyXEL Comm unications Corp oration. 236 In summary , myZyXEL.com delivers a convenient, central ized way to register all your ZyW ALL security appliances and security services.
ZyW ALL 2WG Support Notes All contents c opyright (c) 2006 ZyXEL Comm unications Corp oration. 237 D05. If I were new to my Zy XEL.com, what are the required fields when I register my ZyW ALL device on myZyXEL.com? The required fields include: user name, password, valid email address and country .
ZyW ALL 2WG Support Notes All contents c opyright (c) 2006 ZyXEL Comm unications Corp oration. 238 D09. Who maint ains mySecurityZone & Up date Server? It’ s maintained by ZyXEL Security Respons.
ZyW ALL 2WG Support Notes All contents c opyright (c) 2006 ZyXEL Comm unications Corp oration. 239 E04. Can I decide whether to forw ard or drop the HTTP response if the query to BlueCoat dat a center is timed out? Yes, you can set the policy, drop or forward, when query is timed out.
ZyW ALL 2WG Support Notes All contents c opyright (c) 2006 ZyXEL Comm unications Corp oration. 240 E10. Who needs ZyXEL Content Filtering? Is ZyXEL Content Filteri ng for small comp anies or for large.
ZyW ALL 2WG Support Notes All contents c opyright (c) 2006 ZyXEL Comm unications Corp oration. 241 E16. How do I keep database of C ontent Filtering service updated? From the current design, there is no local Conten t Filtering signature database sto red on the ZyW ALL devices.
ZyW ALL 2WG Support Notes All contents c opyright (c) 2006 ZyXEL Comm unications Corp oration. 242 BlueCoat uses expert Web content ra ters to train the ratings technology. Initially, category experts create a list of URLs that represent good c ontent for each category.
ZyW ALL 2WG Support Notes All contents c opyright (c) 2006 ZyXEL Comm unications Corp oration. 243 · Sex Education · Violence/Hate/Racism · Weapons Potential Non-Productive Categories · Abortion .
ZyW ALL 2WG Support Notes All contents c opyright (c) 2006 ZyXEL Comm unications Corp oration. 244 · Sports/Recreation/Hobbies · Streaming Media/MP3 · Travel · Vehicles · Web Advertisements · Web Communications · Web Hosting E24.
ZyW ALL 2WG Support Notes All contents c opyright (c) 2006 ZyXEL Comm unications Corporat ion. 245 E29. Which User Name & Password shoul d I input for Conten t Filtering report? The User Name is the smallest Ethernet MAC address of your device.
ZyW ALL 2WG Support Notes All contents c opyright (c) 2006 ZyXEL Comm unications Corporat ion. 246 policy , Gateway_1. In this case, this will be counted as two VPN tunnels. F02. What is VPN? A VPN gives users a secure link to access co rporate network over the Internet or other public or private networks without the expense of lease lines.
ZyW ALL 2WG Support Notes All contents c opyright (c) 2006 ZyXEL Comm unications Corp oration. 247 company to carry the data traf fic over its Internet access lines, thus re ducing the need for som e installed lines. F04. What are most common VPN protocols? There are currently three major tunneling protocols for VPNs.
ZyW ALL 2WG Support Notes All contents c opyright (c) 2006 ZyXEL Comm unications Corp oration. 248 In this case, T ransport mode only pr otects the upper-layer protocols of IP payload (user data). T unneling mode protects the entire IP payload including user data.
ZyW ALL 2WG Support Notes All contents c opyright (c) 2006 ZyXEL Comm unications Corp oration. 249 F1 1. What are Local ID and Peer ID? Local ID and Peer ID are used in IKE phase 1 ne gotiation. It’ s in FQDN(Fully Qualified Domain Name) format, IKE standard takes it as one type of Phase 1 ID.
ZyW ALL 2WG Support Notes All contents c opyright (c) 2006 ZyXEL Comm unications Corp oration. 250 F14. What VPN protocols are supported by ZyW ALL? All ZyW ALL series support ESP (protocol num ber 50) and AH (protocol number 51). F15. What types of encryp tion does ZyW ALL VPN support? ZyW ALL supports 56-bit DES and 168-bit 3DES.
ZyW ALL 2WG Support Notes All contents c opyright (c) 2006 ZyXEL Comm unications Corp oration. 251 172.31.255.255 (these address ranges are reserved by inte rnet standard for private LAN numberings behind NA T devices). It is usually a static IP so that we can pre-c onfigure it in ZyW ALL for m aking VPN connections.
ZyW ALL 2WG Support Notes All contents c opyright (c) 2006 ZyXEL Comm unications Corp oration. 252 F21. Will ZyXEL support Secure Remote Management? Y es, we will support it and we are working on it currently . F22. Does ZyW ALL VPN support NetBIOS broadcast? Y es, the ZyW ALL does support NetBIOS broadcast over VPN.
ZyW ALL 2WG Support Notes All contents c opyright (c) 2006 ZyXEL Comm unications Corporat ion. 253 If firewall is turned on in ZyW ALL, you must forward IKE port in Internet in terface.
ZyW ALL 2WG Support Notes All contents c opyright (c) 2006 ZyXEL Comm unications Corp oration. 254 F28. Single, Range, Subnet, which typ es of IP address does ZyW ALL support in VPN/IPSec? All ZyW ALL series support single , range, and subnet configuration fo r VPN IPSec.
ZyW ALL 2WG Support Notes All contents c opyright (c) 2006 ZyXEL Comm unications Corp oration. 255 cryptography as asymmetric. Symmetric cryptography , such as DES, 3DES, AES, is normally used for data transmission, since it requires less computation power than asymmetric cr yptography .
ZyW ALL 2WG Support Notes All contents c opyright (c) 2006 ZyXEL Comm unications Corp oration. 256 Certificate Polic ies A Certification Practice S tatement. G05. What is a Certification Authority? A Certification Authority is a trusted third party that verifies the ident ity of an applicant registering for a digital certificate.
ZyW ALL 2WG Support Notes All contents c opyright (c) 2006 ZyXEL Comm unications Corporat ion. 257 describe the rules governing the dif f erent uses of these certificates. G09. How does a PKI ensure data confidentiality? Users' public keys are published in an accessible directory .
ZyW ALL 2WG Support Notes All contents c opyright (c) 2006 ZyXEL Comm unications Corporat ion. 258 When Bob clicks on the digital signature option on his e-mail application, special software applies a mathematical formula known as a hash function to the message, converting it to a fixed-length string of characters called a message digest.
ZyW ALL 2WG Support Notes All contents c opyright (c) 2006 ZyXEL Comm unications Corp oration. 259 G12. Does ZyXEL provide CA service? No, ZyXEL doesn't maintain CA service for customers, customers need to find CA server (trusted 3rd party) in order to use PKI functionality on ZyW ALL.
ZyW ALL 2WG Support Notes All contents c opyright (c) 2006 ZyXEL Comm unications Corp oration. 260 configuration to the local com puter . Then import them back to ZyXEL appliance.
ZyW ALL 2WG Support Notes All contents c opyright (c) 2006 ZyXEL Comm unications Corp oration. 261 b. Installation Speed and Simplicity: Installing a wireless LAN system ca n be fast and easy and can eliminate the need to pull cable through walls and ceilings.
ZyW ALL 2WG Support Notes All contents c opyright (c) 2006 ZyXEL Comm unications Corp oration. 262 at 1 1 Mbps or lower depending on range. The range at 54 Mbps is less than for 802.1 1b operating at 1 1 Mbps. H08. What is 802.1 1a? 802.1 1a the second revision of 802.
ZyW ALL 2WG Support Notes All contents c opyright (c) 2006 ZyXEL Comm unications Corp oration. 263 2. Building Materials: metal door, aluminum studs. 3. Electrical devices: microwaves , m onitors, electric motors. Solution : 1.Minimizing the number of walls and ceilings 2.
ZyW ALL 2WG Support Notes All contents c opyright (c) 2006 ZyXEL Comm unications Corp oration. 264 see the SSID. H17. What is 802.1x? IEEE 802.1x Port-Based Network Access Control is an IEEE (Institut.
デバイスZyXEL Communications 2WGの購入後に(又は購入する前であっても)重要なポイントは、説明書をよく読むことです。その単純な理由はいくつかあります:
ZyXEL Communications 2WGをまだ購入していないなら、この製品の基本情報を理解する良い機会です。まずは上にある説明書の最初のページをご覧ください。そこにはZyXEL Communications 2WGの技術情報の概要が記載されているはずです。デバイスがあなたのニーズを満たすかどうかは、ここで確認しましょう。ZyXEL Communications 2WGの取扱説明書の次のページをよく読むことにより、製品の全機能やその取り扱いに関する情報を知ることができます。ZyXEL Communications 2WGで得られた情報は、きっとあなたの購入の決断を手助けしてくれることでしょう。
ZyXEL Communications 2WGを既にお持ちだが、まだ読んでいない場合は、上記の理由によりそれを行うべきです。そうすることにより機能を適切に使用しているか、又はZyXEL Communications 2WGの不適切な取り扱いによりその寿命を短くする危険を犯していないかどうかを知ることができます。
ですが、ユーザガイドが果たす重要な役割の一つは、ZyXEL Communications 2WGに関する問題の解決を支援することです。そこにはほとんどの場合、トラブルシューティング、すなわちZyXEL Communications 2WGデバイスで最もよく起こりうる故障・不良とそれらの対処法についてのアドバイスを見つけることができるはずです。たとえ問題を解決できなかった場合でも、説明書にはカスタマー・サービスセンター又は最寄りのサービスセンターへの問い合わせ先等、次の対処法についての指示があるはずです。