(2) Make connection from another PC to ZyWALL via SSH, but second
connection could not be established.
9. [BUG FIX] SPR ID: 090105014
Symptom:
Firewall blocks GRE packets between two Cisco routers.
Topology:
/----DMZ(public IP)------Cisco router2(LAN:8.1.1.2)
(lan:8.1.1.1)Cisco router1------(wan)ZW5--
\----LAN
Condition:
(1) In firewall, traffic between WAN & DMZ is allowed. And log is enabled for
WAN ---- >DMZ.
(2) Configure NAT only for lan to wan, no nat between dmz and wan.
(3) Ping from 8.1.1.1 to 8.1.1.2 to start the tunnel, tunnel could not be built up
and ping failed, no log is shown
(4)If tunnel has been built up already, ping from 8.1.1.1 to 8.1.1.2 failed, no log
is shown
(5) If firewall is disabled, problem disappeared
10. [BUG FIX] SPR ID: 090121708
Symptom:
Fail to build VPN tunnel after SA lifetime expires.
Topology:
PC-------------(L)NAT router(W)-----(L)DUT(W)---Internet
(ZyXEL VPN Client)
Condition:
(1)Get ZyXEL VPN client from ftp://ftp.
zyxel.com/ZyWALL_IPSec_VPN_Client/software/ZyWALL IPSec VPN Client
_2.0.204.61.07. zip
(2) ZyXEL VPN client build VPN tunnel with DUT using NAT traversal.
(3) After phrase1 SA lifetime expires, can not build tunnel between them
successfully.
12. [BUG FIX] SPR ID: 090305574
Symptom:
PC1 gets request timeout when doing nslookup using ZyWALL A as the DNS
proxy.
Topology:
PC1----(L)ZyWALL-------A(W)tunnel------(W)ZyWALL B(L)---DNS Server
Condition:
(1) Build VPN tunnel between ZyWALL A and ZyWALL B.
(2) Configure ZyWALL A as DNS Server of PC1.
(3) On ZyWALL A, edit web eWC/DNS, add a new NS record before the first
record. (Domain Zone = *, Private DNS Server = IP of "DNS Server").
(4) On "DNS Server", add an Address Record.
Kommentare zu diesen Handbüchern