ZyWALL 5 Support Notes
All contents copyright (c) 2006 ZyXEL Communications Corporation.
294
Intel VPN, v. 6.90
FreeS/WAN for Linux
SSH Remote ISAKMP Testing Page, (http://isakmp-test.ssh.fi/cgi-bin/nph-isakmp-test)
Windows 2000, Windows XP IPSec
K22. Will ZyXEL support Secure Remote Management?
Yes, we will support it and we are working on it currently.
K23. Does ZyWALL VPN support NetBIOS broadcast?
Yes, the ZyWALL does support NetBIOS broadcast over VPN.
K24. Is the host behind NAT allowed to use IPSec?
NAT Condition Supported IPSec Protocol
VPN Gateway embedded NAT AH tunnel mode, ESP tunnel mode
VPN client/gateway behind NAT
*
ESP tunnel mode
NAT in Transport mode None
* The NAT router must support IPSec pass through. For example, for ZyWALL NAT routers, IPSec pass
through is supported since ZyNOS 3.21. The default port and the client IP have to be specified in NAT
menu Server Setup.
K25. How do I configure ZyWALL with NAT for internal servers?
Generally, without IPSec, to configure an internal server for outside access, we need to configure the
server private IP and its service port in NAT Server Table.
However, if both NAT and IPSec is enabled in ZyWALL, the edit of the table is necessary only if the
connection is a non-secure connections. For secure connections, none NAT server settings are required
since private IP is reachable in the VPN case.
For example:
host----ZyWALL(NAT)----ADSL Modem----Internet----Secure host
\
\
Non-secure host