ZyXEL Communications 200 Series User Manual

Page 379

Advertising
background image

Chapter 20 IPSec VPN

ZyWALL USG 100/200 Series User’s Guide

379

IPSec SA Overview

Once the ZyWALL and remote IPSec router have established the IKE SA, they can securely
negotiate an IPSec SA through which to send data between computers on the networks.

"

The IPSec SA stays connected even if the underlying IKE SA is not available
anymore.

This section introduces the key components of an IPSec SA.

Local Network and Remote Network

In an IPSec SA, the local network, the one(s) connected to the ZyWALL, may be called the
local policy. Similarly, the remote network, the one(s) connected to the remote IPSec router,
may be called the remote policy.

Active Protocol

The active protocol controls the format of each packet. It also specifies how much of each
packet is protected by the encryption and authentication algorithms. IPSec VPN includes two
active protocols, AH (Authentication Header, RFC 2402) and ESP (Encapsulating Security
Payload, RFC 2406).

"

The ZyWALL and remote IPSec router must use the same active protocol.

Usually, you should select ESP. AH does not support encryption, and ESP is more suitable
with NAT.

Encapsulation

There are two ways to encapsulate packets. Usually, you should use tunnel mode because it is
more secure. Transport mode is only used when the IPSec SA is used for communication
between the ZyWALL and remote IPSec router (for example, for remote management), not
between computers on the local and remote networks.

"

The ZyWALL and remote IPSec router must use the same encapsulation.

Advertising
This manual is related to the following products: