L2TP Over IPSec Connection Between The ZyWALL USG And

2y ago
19 Views
2 Downloads
899.45 KB
8 Pages
Last View : 3m ago
Last Download : 3m ago
Upload by : Abram Andresen
Transcription

L2TP over IPSec connection betweenthe ZyWALL USG and iPhoneiPhone 3G is now a very popular handheld device worldwide. It not only allows mobile users tosurf Internet, delivering push email, but also provides secure access to corporate resources bysupporting a variety of virtual private network (VPN) technologies. This document providesstep-by-step instructions for setting up a VPN connection between ZyWALL USG and aniPhone.ZyWALL USG configuration:1. Configure a user account for the iPhone use when connecting. Click theCONFIGURATION Object User/Group User page to create it. This user will bestored in “Local database”.

2. To build up the L2TP over IPSec connection, we have to create the IPSec rule first. ClickCONFIGURATION VPN IPSec VPN VPN Gateway page to create it. There is onepre-configured default rule for L2TP usage.3. Edit the default rule by filling in the following information: (click “Show Advanced Settings”first) VPN Gateway Name Gateway setting: select the local interface as My Address and set the peer side touse Dynamic Address (Peer Gateway Address) Pre-shared Key; this parameter will also be needed when configuring the iPhoneconnection.

4. Configure the Phase 1 proposal. There is a specific combination that is supported by theiPhone (depending on iOS version). Users can check the Appendix for more details.5. After the VPN gateway setting is done, click the CONFIGURATION VPN IPSec VPN VPN Connection page to create it. There is one pre-configured default rule for L2TPusage.

6. Edit the default rule by filling in the following information: (click “Show Advanced Settings”first) Connection Name Select the application scenario as Remote Access (Server Role) and select thepre-configured VPN Gateway rule.7. For L2TP over IPSec, we must use the Transport mode scenario, the VPN is configured asa Peer-to-Peer tunnel. Thus we have to select the WAN IP address as the Local Policy.

8. Configure the Phase 2 proposal. There is a specific combination that is supported by theiPhone (depending on iOS version). Users can check the Appendix for more details.9. After the VPN connection setting is done, click CONFIGURATION VPN L2TP VPN L2TP VPN page to create it. Select the VPN connection rule Assign the IP address pool Select the Allowed user

iPhone configuration :(The description is quoted from Apple iPhone instruction /How To Setup Guide.pdf)1. Go to the network setup screen by clicking Settings General Network VPN.2. Click the L2TP tab and start to configure it. We need to fill in rule Description (e.g.iPhone L2TP), Server address (e.g. www.securityusg.com), Account and Password thatis configured in the USG L2TP allowed user setting.

3. The RSA SecurID option is not used. Secret must match the Pre-Shared Key from theIPSec Phase-1 rule of the ZyWALL USG. Click Save to save the L2TP configuration.4. Back to the VPN page, the tunnel can be activated via the on / off icon5. If the iPhone “Send all traffic” option is ON, user needs to create a policy route todo SNAT for iPhone to forward traffic to Internet via the L2TP tunnel.

Appendix. iPhone L2TP over IPSec test noteThe iPhone L2TP over IPSec VPN has some limitations (currently for iOS3 only).For iPhone with iOS 3.xIKE phase 1—3DES encryption with SHA1 hash method (no md5 support).DH2 is required when using a pre-shared key.IPSec phase 2—3DES or AES128 encryption with MD5 or SHA1 hash method.Summary of supported proposal:iOS 3.XPhase 1Phase 5-noneAES128-SHA1-none

supporting a variety of virtual private network (VPN) technologies. This document provides step-by-step instructions for setting up a VPN connection between ZyWALL USG and an iPhone. ZyWALL USG configuration: 1. Configure a user account for the iPhone use when connecting. Click the CONFIGURATION &g

Related Documents:

ZyWALL USG Series for site-to-site IPSec VPN connections Remote users can securely access company resources with their computers or smartphones via SSL, IPSec and L2TP over IPSec VPN The headquarter ZyWALL USG Series can also establish an IPSec VPN connection with A

Virtual Private Network (VPN) VPN Tunnels (Total) 36 75 95 155 IPSec Tunnels 10 25 35 70 SSL VPN Tunnels 1 5 10 20 PPTP/L2TP Clients 10 25 25 25 GRE 5 10 15 20 Encryption Methods DES, 3DES, AES, Twofish, Blowfish, CAST-128, NULL SSL Encryption Methods RC4-128, 3DES, AES IPSec/PPTP/L2TP Server/ OpenVPN Server Yes Yes Yes Yes IPSec NAT Traversal .

IPsec provides security for transmission of sensitive information over unprotected networks such as the Internet. IPsec acts at the network layer, protectin g and authenticating IP packets between participating IPsec devices (peers). IPsec provides the following network security services. In general, the local security policy dictates the

Cisco VPN Clients AnyConnect, IPsec VPN -Layer 3 Microsoft Windows, Mac OS X (L2TP/IPsec) iPhone SSL "Clientless"—Layer 7 Integrated solution for enhanced remote access Standards-based interoperability Enterprise—Central Site Router, Firewall, and VPN Security Appliance: VPN Tunnel Termination Mobile Extranet Consumer-to-Business .

IP Internet Protocol L2TP Layer 2 Tunnelling Protocol LAC L2TP Access Concentrator LNS L2TP Network Server VPN Virtual Private Network 3. HOW TO USE THIS MANUAL This user manual is intended to assist the customer, who is entitled to use the static IP feature and has activated static IPs, in configuring the Telkom-supported modem (LAC) that

The IPsec VPN traffic will pass through another router that has no knowledge of the VPN. IPsec provides secure transmission of sensitive information over unprotected networks such as the Internet. IPsec acts at the network layer, protecting and authenticating IP packets between participating IPsec devices (peers), such as Cisco routers.

Design Guide Virtual Tunnel Interface (VTI) Design Guide Service and Specialized Topics Voice and Video Enabled IPsec VPN (V3PN) Multicast over IPsec VPN Digital Certification/PKI for IPsec VPNs Enterprise QoS Dynamic Multipoint VPN (DMVPN) Design Guide IPsec Direct Encapsulation Design Guide V3PN: Redundancy and Load Sharing 190897

L2TP/L2TP over IPSec Client/Server Client/Server ZyWALL VPN Firewall Quick Finder. Datasheet ZyWALL VPN2S 3 Application Diagram Multi-WAN applications The VPN2S can adapt to a variety of network environments and enable offices or service providers File Size: 1MB