Ipsec vpn, 1 ipsec vpn overview, Chapter 13 ipsec vpn – ZyXEL Communications P-334U User Manual

Page 139: Figure 82 vpn: example

Advertising
background image

P-334U/P-335U User’s Guide

Chapter 13 IPSec VPN

139

C

H A P T E R

13

IPSec VPN

This chapter explains how to set up and maintain IPSec VPNs in the ZyXEL Device. First, it
provides an overview of IPSec VPNs. Then, it introduces each screen for IPSec VPN in the
ZyXEL Device. This chapter applies to the P-335U.

13.1 IPSec VPN Overview

A virtual private network (VPN) provides secure communications between sites without the
expense of leased site-to-site lines. A secure VPN is a combination of tunneling, encryption,
authentication, access control and auditing. It is used to transport traffic over the Internet or
any insecure network that uses TCP/IP for communication.
Internet Protocol Security (IPSec) is a standards-based VPN that offers flexible solutions for
secure data communications across a public network like the Internet. IPSec is built around a
number of standardized cryptographic techniques to provide confidentiality, data integrity and
authentication at the IP layer.
The following figure provides one perspective of a VPN tunnel.

Figure 82 VPN: Example

The VPN tunnel connects the ZyXEL Device (X) and the remote IPSec router (Y). These
routers then connect the local network (A) and remote network (B).
A VPN tunnel is usually established in two phases. Each phase establishes a security
association (SA), a contract indicating what security parameters the ZyXEL Device and the
remote IPSec router will use. The first phase establishes an Internet Key Exchange (IKE) SA
between the ZyXEL Device and remote IPSec router. The second phase uses the IKE SA to
securely establish an IPSec SA through which the ZyXEL Device and remote IPSec router can
send data between computers on the local network and remote network. The following figure
illustrates this.

Advertising
This manual is related to the following products: