
normal function.
Figure 5-2 Gateway on alias IP network
(2) Gateway on WAN side
A working topology is suggested as below.
Figure 5-3 Gateway on WAN side
Appendix 5 IPSec FQDN support
ZyWALL A-------------Router C (with NAT) ------------ZyWALL B
(WAN) (WAN) (LAN) (WAN)
If ZyWALL A wants to build a VPN tunnel with ZyWALL B by passing through
Router C with NAT, A can not see B. It has to secure gateway as C. However, ZyWALL
B will send it packet with its own IP and its ID to ZyWALL A. The IP will be NATed by
Router C, but the ID will remain as ZyWALL B sent.
In FQDN design, all three types, IP, DNS, E-Mail, can set ID content. For ID type is
DNS or E-mail, the behavior is simple. ZyWALL A and ZyWALL B only checks the ID
Comentarios a estos manuales