![background image](/i/zyxel/144895/zyxel-zywall-2-ee/h/zyxel-zywall-2-ee-513.png)
ZyWALL 2 Series User’s Guide
VPN/IPSec Setup
37-7
Table 37-2 Menu 27.1.1: IPSec Setup
FIELD DESCRIPTION
EXAMPLE
NAT Traversal Select this check box to enable NAT traversal. NAT traversal allows you to
set up a VPN connection when there are NAT routers between the two
IPSec routers.
The remote IPSec router must also have NAT traversal enabled. You can
use NAT traversal with
ESP
protocol using
Transport
or
Tunnel
mode,
but not with
AH
protocol nor with
Manual
key management.
In order for an IPSec router behind a NAT router to receive an initiating
IPSec packet, set the NAT router to forward UDP port 500 to the IPSec
router behind the NAT router.
No
Local ID type
Press [SPACE BAR] to choose
IP
,
DNS
, or
and press [ENTER].
Select
IP
to identify this ZyWALL by its IP address.
Select
DNS
to identify this ZyWALL by a domain name.
Select
to identify this ZyWALL by an e-mail address.
Content
When you select
IP
in the
Local ID type
field, type the IP address of your
computer in the local
Content
field. The ZyWALL automatically uses the IP
address in the
My IP Address
field (refer to the My IP Address field
description) if you configure the local
Content
field to
0.0.0.0
or leave it
blank.
It is recommended that you type an IP address other than
0.0.0.0
in the
local
Content
field or use the
DNS
or
ID type in the following
situations.
When there is a NAT router between the two IPSec routers.
When you want the remote IPSec router to be able to distinguish
between VPN connection requests that come in from IPSec
routers with dynamic WAN IP addresses.
When you select
DNS
or
in the
Local ID type
field, type a domain
name or e-mail address by which to identify this ZyWALL in the local
Content field. Use up to 31 ASCII characters including spaces, although
trailing spaces are truncated. The domain name or e-mail address is for
identification purposes only and can be any string.
My IP Addr
Enter the IP address of your ZyWALL. The ZyWALL uses its current WAN
IP address (static or dynamic) in setting up the VPN tunnel if you leave this
field as 0.0.0.0.
The VPN tunnel has to be rebuilt if this IP address changes.
0.0.0.0