ZyXEL Communications Network Card unified security gateway Manuel d'utilisateur Page 392

  • Télécharger
  • Ajouter à mon manuel
  • Imprimer
  • Page
    / 959
  • Table des matières
  • DEPANNAGE
  • MARQUE LIVRES
  • Noté. / 5. Basé sur avis des utilisateurs
Vue de la page 391
Chapter 23 IPSec VPN
ZyWALL USG 20/20W User’s Guide
392
•Use the VPN Gateway screens (see Section 23.2.1 on page 396) to manage
the ZyWALL’s VPN gateways. A VPN gateway specifies the IPSec routers at
either end of a VPN tunnel and the IKE SA settings (phase 1 settings). You can
also activate and deactivate each VPN gateway.
23.1.2 What You Need to Know
An IPSec VPN tunnel is usually established in two phases. Each phase establishes
a security association (SA), a contract indicating what security parameters the
ZyWALL and the remote IPSec router will use. The first phase establishes an
Internet Key Exchange (IKE) SA between the ZyWALL and remote IPSec router.
The second phase uses the IKE SA to securely establish an IPSec SA through
which the ZyWALL and remote IPSec router can send data between computers on
the local network and remote network. This is illustrated in the following figure.
Figure 239 VPN: IKE SA and IPSec SA
In this example, a computer in network A is exchanging data with a computer in
network B. Inside networks A and B, the data is transmitted the same way data is
normally transmitted in the networks. Between routers X and Y, the data is
protected by tunneling, encryption, authentication, and other security features of
the IPSec SA. The IPSec SA is secure because routers X and Y established the IKE
SA first.
Vue de la page 391
1 2 ... 387 388 389 390 391 392 393 394 395 396 397 ... 958 959

Commentaires sur ces manuels

Pas de commentaire