ZyXEL Communications ZYWALL 70 - V4.04 Betriebsanweisung Seite 112

  • Herunterladen
  • Zu meinen Handbüchern hinzufügen
  • Drucken
  • Seite
    / 112
  • Inhaltsverzeichnis
  • LESEZEICHEN
  • Bewertet. / 5. Basierend auf Kundenbewertungen
Seitenansicht 111
(2) Process runtime policy sent from remote gateway during IKE negotiation
Policies under
Static IKE rule
(configuration)
Policies under
Dynamic IKE rule
(configuration)
Runtime policies
(IKE negotiation)
Policies under
Static IKE rule
(configuration)
Compare Not compare Not compare
Policies under
Dynamic IKE rule
(configuration)
Not compare Not compare Not compare
Runtime policies
(IKE negotiation)
Compare Not compare Compare
Note:
(1) “Compare” means ZyWALL will compare policies in row with policies in
column. E.g. ZyWALL will compare “Policies under Static IKE rule” with other
“Policies under Static IKE rule”. On the other hand, a policy under dynamic rule
will not compare with other policies. During IKE negotiation, with peer policy
information, ZyWALL can use the result runtime policy to compare with policies
under static and dynamic IKE rules.
(2) Policies under Static/Dynamic IKE rule are rules in Romfile.
(3) Runtime policies are policies received from remote gateway. This remote
gateway acts as initiator and sends IKE request to ZyWALL. It matches one
policy under Dynamic IKE rule. ZyWALL will check whether the received policy
conflict with other policies.
(4) IP address 0.0.0.0 under Static IKE rule means “Any Address”. So it will overlap
with all IP address.
(5) Since “Remote Network” of Network Policy under Dynamic IKE rule can only
be determined when tunnel negotiation, ZyWALL skip conflict checking when
configuration. It is only compared during IKE negotiation.
Seitenansicht 111
1 2 ... 107 108 109 110 111 112

Kommentare zu diesen Handbüchern

Keine Kommentare