9 pre-shared key, 10 editing vpn policies, 9 pre-shared key 14.10 editing vpn policies – ZyXEL Communications ZyXEL ZyWALL 35 User Manual

Page 249: The editing vpn policies section

Advertising
background image

ZyWALL 35 User’s Guide

Chapter 14 VPN Screens

247

The two ZyWALLs in this example can complete negotiation and establish a VPN tunnel.

The two ZyWALLs in this example cannot complete their negotiation because ZyWALL B’s
Local ID type is IP, but ZyWALL A’s Peer ID type is set to E-mail. An ID mismatched
message displays in the IPSEC LOG.

14.9 Pre-Shared Key

A pre-shared key identifies a communicating party during a phase 1 IKE negotiation (

see the

IKE Phases section

for more on IKE phases). It is called pre-shared because you have to share

it with another party before you can communicate with them over a secure connection.

14.10 Editing VPN Policies

Click the edit icon on the VPN Rules screen to edit VPN policies.

Table 75 Matching ID Type and Content Configuration Example

ZYWALL A

ZYWALL B

Local ID type: E-mail

Local ID type: IP

Local ID content: [email protected]

Local ID content: 1.1.1.2

Peer ID type: IP

Peer ID type: E-mail

Peer ID content: 1.1.1.2

Peer ID content: [email protected]

Table 76 Mismatching ID Type and Content Configuration Example

ZYWALL A

ZYWALL B

Local ID type: IP

Local ID type: IP

Local ID content: 1.1.1.10

Local ID content: 1.1.1.10

Peer ID type: E-mail

Peer ID type: IP

Peer ID content: [email protected]

Peer ID content: N/A

Advertising