ZyXEL Communications P-202 User Manual

Page 170

Advertising
background image

P-202H Plus v2 Support Notes

The IP addresses we use in this example are as shown below.

PC 1

P-202H Plus v2

Cisco

PC 2

192.168.1.33

LAN: 192.168.1.1

WAN: 172.21.10.50

LAN: 192.168.2.1

WAN: 140.113.10.50

192.168.2.2

Note:

1. When using Cisco Router to establish VPN, back-to-back connection is not
applicable. In other words, the WAN IP of P-202H Plus v2 and Cisco router can't
be in the same subnet.

2. The following configurations are supposed both two VPN gateways have fixed
IP addresses. If one of VPN gateways uses dynamic IP, we enter 0.0.0.0 as the
secure gateway IP address. In this case, the VPN connection can only be
initiated from dynamic side to fixed side to update its dynamic IP to the fixed side.
From this connection, the source IP is obtained and then update to the previous
0.0.0.0 field. However, if both gateways use dynamic IP addresses, it is no way
to establish VPN connection at all.

If the WAN IP of P-202H Plus v2 is also dynamic IP, we enter 0.0.0.0 as its My IP
Address.
When this IP is given by ISP, it will update to this field.

1. Setup P-202H Plus v2

1. Login P-202H Plus v2 by giving the LAN IP address of P-202H Plus v2 in

URL field. Default LAN IP is 192.168.1.1, default password to login web
configurator is 1234.

2. Click Advanced, and click VPN tab on the left.
3. On the SUMMARY menu, Select a policy to edit by clicking Edit.
4. On the CONFIGURE-IKE menu, check Active check box and give a name

to this policy.

5. Select IPSec Keying Mode to IKE and Negotiation Mode to Main, as we

configured in Sonicwall.

6. Source IP Address Start and Source IP Address End are PC 1 IP in

this example. (the secure host behind P-202H Plus v2)

7. Destination IP Address Start and Destination IP Address End are PC

2 IP in this example. (the secure remote host)

8. My IP Addr is the WAN IP of P-202H Plus v2.
9. Secure Gateway IP Addr is the remote secure gateway IP, that is

Sonicwall WAN IP in this example.

10. Select Encapsulation Mode to Tunnel.

All contents copyright © 2006 ZyXEL Communications Corporation.

170

11. Check the ESP check box. (AH can not be used in SUA/NAT case)


Advertising