142
• If a ZyNOS-based USG’s remote network setting overlaps with its local network settings, set ipsec
swSkipOverlapIp to on to send traffic destined to A’s local network to A’s local network instead of
through the VPN tunnel.
3.4 USG IPSec VPN Client Configuration Provisioning
VPN configuration provisioning gives USG IPSec VPN Client users VPN rule settings
automatically.
Figure 31 IPSec VPN Configuration Provisioning Process
1 User Charlotte with the USG IPSec VPN Client sends her user name and password to the
USG.
2 The USG sends the settings for the matching VPN rule.
3.4.1 Overview of What to Do
1 Create a VPN rule on the USG using the VPN Configuration Provisioning wizard.
2 Configure a username and password for the rule on the USG.
3 On a computer, use the USG IPSec VPN Client to get the VPN rule configuration.
Now user Charlotte can access the network behind the USG through the VPN tunnel.
Figure 32 USG IPSec VPN Client with VPN Tunnel Connected
3.4.2 Configuration S
teps
1 In the USG Quick Setup wizard, use the VPN Settings for Configuration Provisioning
wizard to create a VPN rule that can be used with the USG IPSec VPN Client.