Zyxel-communications 70 Series Bedienungsanleitung Seite 313

  • Herunterladen
  • Zu meinen Handbüchern hinzufügen
  • Drucken
  • Seite
    / 807
  • Inhaltsverzeichnis
  • FEHLERBEHEBUNG
  • LESEZEICHEN
  • Bewertet. / 5. Basierend auf Kundenbewertungen
Seitenansicht 312
ZyWALL 5/35/70 Series User’s Guide
313 Chapter 19 VPN Screens
The two ZyWALLs in this example cannot complete their negotiation because ZyWALL B’s
Local ID type is IP, but ZyWALL As Peer ID type is set to E-mail. An ID mismatched
message displays in the IPSec log.
19.8 IKE Phases
There are two phases to every IKE (Internet Key Exchange) negotiation – phase 1
(Authentication) and phase 2 (Key Exchange). A phase 1 exchange establishes an IKE SA and
the second one uses that SA to negotiate SAs for IPSec.
Figure 147 Two Phases to Set Up the IPSec SA
In phase 1 you must:
Choose a negotiation mode.
Authenticate the connection by entering a pre-shared key.
Choose an encryption algorithm.
Peer ID type: IP Peer ID type: E-mail
Peer ID content: 1.1.1.2 Peer ID content: tom@yourcompany.com
Table 98 Mismatching ID Type and Content Configuration Example
ZYWALL A ZYWALL B
Local ID type: IP Local ID type: IP
Local ID content: 1.1.1.10 Local ID content: 1.1.1.10
Peer ID type: E-mail Peer ID type: IP
Peer ID content: aa@yahoo.com Peer ID content: N/A
Table 97 Matching ID Type and Content Configuration Example
ZYWALL A ZYWALL B
Seitenansicht 312
1 2 ... 308 309 310 311 312 313 314 315 316 317 318 ... 806 807

Kommentare zu diesen Handbüchern

Keine Kommentare