All contents copyright (c) 2007 ZyXEL Communications Corporation.
13
ZyWALL 1050/ZyWALL USG 300 Support Notes
[4] no natt
[5] dpd
[6] local-ip interface ge2
[7] peer-ip 210.110.7.1 0.0.0.0
[8] authentication pre-share
[9] keystring 123456789
[10] local-id type ip 167.35.4.3
[11] peer-id type ip 210.110.7.1
[12] peer-id type ip 210.110.7.1
[13] xauth type server default deactivate
[14] group1
[15] exit
Policy Route for VPN traffic:
[0] policy 1
[1] no deactivate
[2] no description
[3] no user
[4] interface ge1
[5] source LAN_SUBNET
[6] destination Remote_Subnet
[7] no schedule
[8] service any
[9] no snat
[10] next-hop tunnel RemoteTunnel
[11] no bandwidth
[12] exit
Tips for application:
1. Make sure the presharekey is the same in both local and remote gateways.
2. Make sure the IKE & IPSec proposal is the same in both local and remote gateways.
3. Select the correct interface for VPN connection.
4. The Local and Peer ID type and content must the opposite and contain the same.
5. Make sure the VPN policy route has been configured in ZyWALL1050.
1.1.2 Site to Site VPN solutions (ZyWALL 1050 Ù ZyWALL USG 300):
Site to Site VPN is the basic VPN solution between local and remote gateway. This type of
VPN connection is used to extend and join local networks of both sites into a single intranet.
There are two kinds of connection interface. Static IP and dynamic DNS.
Configure ZyWALL 1050 with Static IP address:
14
All contents copyright (c) 2007 ZyXEL Communications Corporation.
ZyWALL 1050/ZyWALL USG 300 Support Notes
ZyWALL 1050 uses the static IP address for VPN connection. The topology is shown on the
following figure.
User needs to configure the static IP address and then apply to the VPN Gateway
configuration page. The configuration steps are stated below:
6) Login ZyWALL 1050 GUI, setup the ge2 interface for internet connection and manually
assign a static IP. The configuration path in ZyWALL 1050 and ZyWALL USG 300 menu
are Network > Interface > Ethernet >Edit > ge2
7) Switch to VPN > IPSec VPN > VPN Gateway select interface ge2 as My Address and
then in Security Gateway Address field set the remote gateway IP to 167.35.4.3. The
Local ID Type and content are IP and 210.110.7.1, Peer ID Type and content are IP and
167.35.4.3.
8) Repeat the step1 & 2 to configure the Remote ZyWALL USG 300. The Local ID Type &
content and Peer ID Type & content are reverse to the Local ZyWALL 1050.
15
All contents copyright (c) 2007 ZyXEL Communications Corporation.
ZyWALL 1050/ZyWALL USG 300 Support Notes
9) User can refer to the user guide to complete the rest of the settings for VPN tunnel.
10) The ZyWALL1050 and ZyWALL USG 300 VPN are route-based VPN. This means the
VPN tunnel can be an interface to route the VPN traffic. Thus, we need to configure a
policy route for VPN traffic from the local subnet to the remote subnet after configuring
the VPN gateway and connection (phase1 and phase2). The purpose of this policy route is
to tell the ZyWALL1050 to send the traffic to VPN tunnel when the traffic flows from the
local subnet to a destination that is in the remote subnet. Switch to ZyWALL 1050 >
Network > Routing > Policy Route and add a new policy route. The source and the
destination addresses are the local and remote subnets. The Next-Hop type is VPN tunnel.
Then choose the corresponding VPN connection rule from the VPN tunnel drop down
menu. Now, the VPN tunnel and routing is configured and user can start to test it.
16
All contents copyright (c) 2007 ZyXEL Communications Corporation.
ZyWALL 1050/ZyWALL USG 300 Support Notes
The CLI commands for application:
Local Gateway:
[0] isakmp policy rename RemoteSite LocalSite
[1] isakmp policy LocalSite
[2] mode main
[3] transform-set des-md5
[4] lifetime 86400
[5] no natt
[6] dpd
[7] local-ip interface ge2
[8] peer-ip 167.35.4.3 0.0.0.0
[9] authentication pre-share
[10] keystring 123456789
[11] local-id type ip 210.110.7.1
[12] peer-id type ip 167.35.4.3
[13] peer-id type ip 167.35.4.3
[14] xauth type server default deactivate
[15] group1
[16] exit
All contents copyright (c) 2007 ZyXEL Communications Corporation.
17
ZyWALL 1050/ZyWALL USG 300 Support Notes
[4] no natt
[5] dpd
[6] local-ip interface ge2
[7] peer-ip 210.110.7.1 0.0.0.0
[8] authentication pre-share
[9] keystring 123456789
[10] local-id type ip 167.35.4.3
[11] peer-id type ip 210.110.7.1
[12] peer-id type ip 210.110.7.1
[13] xauth type server default deactivate
[14] group1
[15] exit
Policy Route for VPN traffic:
[0] policy 1
[1] no deactivate
[2] no description
[3] no user
[4] interface ge1
[5] source LAN_SUBNET
[6] destination Remote_Subnet
[7] no schedule
[8] service any
[9] no snat
[10] next-hop tunnel RemoteTunnel
[11] no bandwidth
[12] exit
Tips for application:
6. Make sure the presharekey is the same in both local and remote gateways.
7. Make sure the IKE & IPSec proposal is the same in both local and remote gateways.
8. Select the correct interface for VPN connection.
9. The Local and Peer ID type and content must the opposite and contain the same.
Make sure the VPN policy route has been configured in ZyWALL1050.
All contents copyright (c) 2007 ZyXEL Communications Corporation.
18
ZyWALL 1050/ZyWALL USG 300 Support Notes
1.2 Extranet Deployment
The VPN provides the access to extranets which can provide the security path over internet
to improve the client service, vendor support and company communication. Different flexible
business models have been developed based on the global VPN extranet architecture. For
example, customers can order equipment over the VPN and also suppliers can check the orders
electronically. Another result of its application is that the employees across different branches
can collaborate on project documents and share the different site’s internal resource to
complete the project.
Main Office
Servers
Desktop users
ZyWALL 1050
IPSec VPN Tunnel
The VPN provides
access to both
extranets and
wide-area intranets in
It’s easy to establish VPN
connectivity with your
partner’s/customer’s site
regardless of what their VPN
Branch Office
ZyWALL 70
Remote Office
ZyWALL 35
Customer Site
Partner Site
FortiGate
Check Point VPN-1
The ZyWALL 1050 can be placed as a VPN gateway in the central site. It can communicate
with other ZyXEL’s VPN-capable products as well as VPN products from other major vendors
in the network device industry, e.g. Cisco PIX/IOS VPN products, Check Point VPN Pro,
19
All contents copyright (c) 2007 ZyXEL Communications Corporation.
ZyWALL 1050/ZyWALL USG 300 Support Notes
Juniper NetScreen series and others…
1.2.1 Site to site VPN solutions (ZyWALL1050/ZyWALL USG 300 to ZyWALL70)
The exciting ZyWALL35 or 70 in central office gateway can be replaced by ZyWALL 1050,
and the ZyWALL35 or 70 moved to a remote office. The ZyWALL 1050 can provide higher
VPN throughput and deal with multiple VPN tunnels at the same time. To show how to build
tunnel between ZyWALL5/35/70 and ZyWALL 1050 we used ZyWALL 70 as an example.
Static IP address
210.110.7.1
Static IP address
167.35.4.3
Internet
CenterOffice GatewayBranch Gateway
LAN: 192.168.1.X
1) Login ZyWALL 1050 GUI and setup the ge2 interface for the internet connection and
manually assign a static IP. The configuration path is ZyWALL 1050 > Configuration >
Network > Interface > Edit > ge2
LAN: 192.168.2.X
2) Switch to Configuration > Network > IPSec VPN > VPN Gateway, select My Address
as interface ge2 and then in Security Gateway Address field set the remote gateway IP to
167.35.4.3. The Local ID Type and content are IP and 210.110.7.1, Peer ID Type and
content are IP and 167.35.4.3.
20
All contents copyright (c) 2007 ZyXEL Communications Corporation.
ZyWALL 1050/ZyWALL USG 300 Support Notes
3) Login to ZyWALL70 and go to Security > VPN > Gateway Policy, add a new gateway
policy to connect with central office’s ZyWALL 1050. My Address and Remote Gateway
Address are ZyWALL70 and ZyWALL 1050 WAN IP addresses. The Pre-Shared Key
configured on both sides must exactly the same Local ID Type & content and Peer ID
Type & content are reverse to the Local ZyWALL 1050.
4) The IKE Proposal is very important setting when configuring the VPN tunnel. The
proposal includes Negotiation Mode, Encryption and Authentication Algorithm and….
Make sure the IKE proposal parameters are must the same on both ends.
5) Switch to Configuration > Network > IPSec VPN > VPN Connection, add a new VPN
connection (IPSec phase2). Setup the Phase2 proposal and local and remote policies. The
chosen phase2 proposal chosen must be the same as on the remote site’s ZyWALL70.
6) In ZyWALL70, VPN is a rule based VPN. This means that whether the traffic is going to
the tunnel or not will depend on the local and remote policies. In this example,
21
All contents copyright (c) 2007 ZyXEL Communications Corporation.
ZyWALL 1050/ZyWALL USG 300 Support Notes
ZyWALL70 local and remote policies are 192.168.2.0 and 192.168.1.0 and the traffic
from 192.168.2.X subnet to 192.168.1.X subnet will go through the VPN tunnel to the
remote site as predefined. The ZyWALL1050 local and remote policies must be reverse to
the ZyWALL70’s settings, otherwise the tunnel will not be built up.
7) Check whether the IPSec proposal on both sites is the same and the configuration is done
on both sites.
5
7
6
8) The ZyWALL1050 VPN is a route-based VPN, this means the VPN tunnel can be an
interface to route the VPN traffic. Thus, we need to configure a policy route for VPN
traffic from the local subnet to the remote subnet after configuring the VPN gateway and
the connection (phase1 and phase2). The purpose for this policy route is to tell the
ZyWALL1050 to send the traffic to the VPN tunnel when the traffic goes from the local
subnet to the destination that is in a remote subnet. Switch to Configuration > Policy >
Route > Policy Route and add a new policy route, the source and destination address are
the local and remote subnet and the Next-Hop type is a VPN tunnel. Then choose the
corresponding VPN connection rule from the VPN tunnel drop down menu. Now, the VPN
All contents copyright (c) 2007 ZyXEL Communications Corporation.
22
ZyWALL 1050/ZyWALL USG 300 Support Notes
tunnel and routing is built and user can start to test it.
8
9) After configuring both sides of the VPN, click the Dial up VPN tunnel icon to test the
All contents copyright (c) 2007 ZyXEL Communications Corporation.
24
ZyWALL 1050/ZyWALL USG 300 Support Notes
[5] set pfs none
[6] policy-enforcement
[7] local-policy LAN_SUBNET
[8] remote-policy Remote_Subnet
[9] no nail-up
[10] no replay-detection
[11] no netbios-broadcast
[12] no out-snat activate
[13] no in-snat activate
[14] no in-dnat activate
[15] exit
Policy Route for VPN traffic:
[0] policy 1
[1] no deactivate
[2] no description
[3] no user
[4] interface ge1
[5] source LAN_SUBNET
[6] destination Remote_Subnet
[7] no schedule
[8] service any
[9] no snat
[10] next-hop tunnel RemoteTunnel
[11] no bandwidth
[12] exit
Tips for application:
1. Make sure the presharekey is the same in both the local and the remote gateways.
2. Make sure the IKE & IPSec proposal is the same in both the local and the remote
gateways.
3. Select the correct interface for the VPN connection.
4. The Local and Peer ID type and content must be the opposite and not of the same content.
5. Make sure the VPN policy route had been setup in ZyWALL 1050.
25
All contents copyright (c) 2007 ZyXEL Communications Corporation.
ZyWALL 1050/ZyWALL USG 300 Support Notes
1.2.2 Interoperability – VPN with other vendors
1.2.2.1 ZyWALL with FortiGate VPN Tunneling
This page guides how to setup a VPN connection between the ZyWALL 1050/ZyWALL
USG 300 and FortiGate 200A.
As on the figure shown below, the tunnel between Central and Remote offices ensures the
packet flow between them are secure, because the packets go through the IPSec tunnel are
encrypted. To setup this VPN tunnel, the required settings for ZyWALL and FortiGate are
explained in the following sections.
Static IP address
210.110.7.1
Static IP address
167.35.4.3
Internet
Central Office Gateway
ZyWALL
LAN: 192.168.1.X
The central office gateway ZyWALL 1050’s interface and VPN setting retain the same setting
as in the previous example. If you jumped this section first, please refer to ‘ZyWALL 1050 to
ZYWALL70 VPN tunnel setting’ on page 8.
This list below is to briefly show the VPN phase1 and phase2 configuration parameters:
ZyWALL FortiGate
Branch Gateway
FortiGate 200A
LAN: 192.168.2.X
WAN: 210.110.7.1
LAN: 192.168.1.0/24
Phase 1
Negotiation Mode : Main
Pre-share key: 123456789
Encryption :DES
All contents copyright (c) 2007 ZyXEL Communications Corporation.
WAN: 167.35.4.3
LAN: 192.168.2.0/24
Phase 1
Negotiation Mode : Main
Pre-share key: 123456789
Encryption :DES
26
ZyWALL 1050/ZyWALL USG 300 Support Notes
Authentication :MD5
Key Group :DH1
Phase2
Encapsulation: Tunnel
Active Protocol: ESP
Encryption: DES
Authentication: SHA1
Perfect Forward Secrecy (PFS): None
Perfect Forward Secrecy (PFS): None
Authentication :MD5
Key Group :DH1
Phase2
Encapsulation: Tunnel
Active Protocol: ESP
Encryption: DES
Authentication: SHA1
1) Configure the ZyWALL1050 ‘s VPN gateway and VPN connection as on the list. Also,
remember to configure the policy route for the VPN traffic routing. Refer to the previous
scenario or user guide to find help on setting the ZyWALL1050 VPN.
2) Login to the FortiGate GUI and switch to System > Network > Interface and set the wan1
interface to 167.35.4.3 and internal interface to 192.168.2.1/255.255.255.0.
2
Note: About the detail interface settings, refer to FortiGate user guide.
3) Switch to System > VPN > IPSEC and select the Auto Key (IKE) tab and click the Create
Phase 1 button. This will open a new page for VPN phase1 setup.
3
4) Fill-in the VPN phase1 setting according to the table listed. We don’t have to setup the ID
type and content because the FortiGate accepts any peer ID. Make sure both the pre-shares
key and proposal are the same as in the ZyWALL1050.
27
All contents copyright (c) 2007 ZyXEL Communications Corporation.
ZyWALL 1050/ZyWALL USG 300 Support Notes
4
5) Get back to the VPN configuration page again and click the Create Phase 2 button to add
a new Phase2 policy.
5
6) Select the “ZyWALL”(configured in the step 4) policy from the Phase 1 drop down menu
and click the Advanced… button to edit the phase 2 proposal and source and destination
address. Please make sure the phase 2 proposal is the same as in ZyWALL 1050 phase 2.
28
All contents copyright (c) 2007 ZyXEL Communications Corporation.
ZyWALL 1050/ZyWALL USG 300 Support Notes
6
7) The VPN tunnel configuration is finished and the VPN IPSec page will show the VPN
phase 1 and phase 2 rules in the Auto Key (IKE) tab.
7
8) We need to setup the firewall rules for IPSec VPN traffic transmitting from ZyWALL to
FortiGate and from FortiGate to ZyWALL. Switch to Firewall > VPN >Address menu and
add two new address objects which stand for ZyWALL LAN subnet and FortiGate LAN
subnet. Using the “Create New” button to create a new address object.
8
9) Switch to Firewall > Policy and click “Insert Policy Before” icon to add new policy for the
VPN traffic from FortiGate to ZyWALL.
All contents copyright (c) 2007 ZyXEL Communications Corporation.
9
29
ZyWALL 1050/ZyWALL USG 300 Support Notes
10) We will setup the FortiGate to ZyWALL policy in the new page. The source interface is
internal and Address name is Fortinet (192.168.2.0/255.255.255.0 address object). The
destination interface is wan1 and Address name is Zynet (192.168.1.0/255.255.255.0
address object). Schedule and service type are “always” and “ANY” to ensure that all
kinds of traffic can pass through the VPN tunnel at any time. There are three kinds of
“Action” available for user to configure, because the traffic is send from “internal” to
WAN and will be encrypted by IPSec VPN tunnel. Thus, we select “IPSEC” as action and
chose allow inbound and outbound traffic in the ZyWALL tunnel.
10
11) Switch to Firewall > Policy and click “Create New” button to add new policy for the VPN
traffic from ZyWALL to FortiGate.
11
12) We setup the ZyWALL to FortiGate policy in the new page. The source interface is wan1
and Address name is Zynet (192.168.1.0/255.255.255.0 address object). The destination
interface is internal and the Address name is Fortinet (192.168.2.0/255.255.255.0 address
object). Schedule and service type are always and ANY to ensure that all kinds of traffic
can pass through the VPN tunnel at any time. Select “ACCEPT” as an action this time
30
All contents copyright (c) 2007 ZyXEL Communications Corporation.
Loading...
+ 315 hidden pages
You need points to download manuals.
1 point = 1 manual.
You can buy points or you can get point for every manual you upload.