How To Set Up A Vpn Tunnel Between Winxp And Zwall On A Pc 2 And Winxp On A Windows Xp 2 On A Microsoft Gbk2 (Windows) On A Macbook 2 (Windows 2) On An Ip



Similar documents
Configuring IPsec between a Microsoft Windows XP Professional (1 NIC) and the VPN router

DI-804HV with Windows 2000/XP IPsec VPN Client Configuration Guide

Establishing a VPN tunnel to CNet CWR-854 VPN router using WinXP IPSec client

CREATING AN IKE IPSEC TUNNEL BETWEEN AN INTERNET SECURITY ROUTER AND A WINDOWS 2000/XP PC

OvisLink 8000VPN VPN Guide WL/IP-8000VPN. Version 0.6

Configuring TheGreenBow VPN Client with a TP-LINK VPN Router

Configuring Windows 2000/XP IPsec for Site-to-Site VPN

Windows XP VPN Client Example

Lab 4.4.8a Configure a Cisco GRE over IPSec Tunnel using SDM

Configuration Guide. How to set up the IPSec site-to-site Tunnel between the D-Link DSR Router and the Cisco Firewall. Overview

Astaro Security Gateway V8. Remote Access via L2TP over IPSec Configuring ASG and Client

DFL-210/260, DFL-800/860, DFL-1600/2500 How to setup IPSec VPN connection

Configuring Global Protect SSL VPN with a user-defined port

How to configure VPN function on TP-LINK Routers

Configuring IPSec VPN Tunnel between NetScreen Remote Client and RN300

How To Industrial Networking

VPN Wizard Default Settings and General Information

How to configure VPN function on TP-LINK Routers

Configure VPN between ProSafe VPN Client Software and FVG318

Implementing and Managing Security for Network Communications

Chapter 4 Virtual Private Networking

VPN. VPN For BIPAC 741/743GE

VPN Configuration of ProSafe VPN Lite software and NETGEAR ProSafe Router:

Configuration Guide. How to set up the IPSec site-to-site Tunnel between the D-Link DSR Router and the Sonicwall Firewall.

ZyWALL 5. Internet Security Appliance. Quick Start Guide Version 3.62 (XD.0) May 2004

Laboratory Exercises V: IP Security Protocol (IPSec)

How to Setup PPTP VPN Between a Windows PPTP Client and the DIR-130.

Configuring IPsec VPN with a FortiGate and a Cisco ASA

ISG50 Application Note Version 1.0 June, 2011

If you have questions or find errors in the guide, please, contact us under the following address:

Configure IPSec VPN Tunnels With the Wizard

For paid computer support call

How to setup a VPN on Windows XP in Safari.

Chapter 6 Basic Virtual Private Networking

SSL SSL VPN

Configure an IPSec Tunnel between a Firebox Vclass & a Check Point FireWall-1

VPN L2TP Application. Installation Guide

Configuring an IPSec Tunnel between a Firebox & a Check Point FireWall-1

ZyWALL OTPv2 Support Notes

Netopia TheGreenBow IPSec VPN Client. Configuration Guide.

IPSec Pass through via Gateway to Gateway VPN Connection

SafeWord Domain Login Agent Step-by-Step Guide

Netgear ProSafe VPN firewall (FVS318 or FVM318) to Cisco PIX firewall

Use Shrew Soft VPN Client to connect with IPSec VPN Server on RV130 and RV130W

Internet Protocol Security (IPSec)

Global VPN Client Getting Started Guide

Configuration Guide. How to set up the IPSec site-to-site Tunnel between the D-Link DSR Router and the Fortinet Firewall. Overview

How to access peers with different VPN through IPSec. Tunnel

Apliware firewall. TheGreenBow IPSec VPN Client. Configuration Guide.

Astaro Security Gateway V8. Remote Access via SSL Configuring ASG and Client

Cloud Services ADM. Agent Deployment Guide

UTM - VPN: Configuring a Site to Site VPN Policy using Main Mode (Static IP address on both sites) i...

WatchGuard Mobile User VPN Guide

How to setup PPTP VPN connection with DI-804HV or DI-808HV using Windows PPTP client

Application Note: Integrate Juniper IPSec VPN with Gemalto SA Server. October

IPsec VPN Application Guide REV:

Creating a VPN Using Windows 2003 Server and XP Professional

Configuring a VPN for Dynamic IP Address Connections

Windows Firewall Configuration with Group Policy for SyAM System Client Installation

LAN-Cell to Cisco Tunneling

AirStation VPN Setup Guide WZR-RS-G54

Installation instructions for the supplier VPN solution

Fireware How To Network Configuration

SSL Certificate Based VPN

Chapter 5 Virtual Private Networking Using IPsec

Lab a Configure Remote Access Using Cisco Easy VPN

GNAT Box VPN and VPN Client

Fireware How To VPN. Introduction. Is there anything I need to know before I start? Configuring a BOVPN Gateway

How to Logon with Domain Credentials to a Server in a Workgroup

VPN Consortium Scenario 1: Gateway-to-Gateway with Preshared Secrets

Setting up Hyper-V for 2X VirtualDesktopServer Manual

Micronet SP881. TheGreenBow IPSec VPN Client Configuration Guide.

How To Configure Apple ipad for Cyberoam L2TP

Chapter 8 Virtual Private Networking

VPN Consortium Scenario 1: Gateway-to-Gateway with Preshared Secrets

How to set up as VPN Network

Immotec Systems, Inc. SQL Server 2005 Installation Document

Connecting to the FILTER Virtual Private Network (VPN)

Active Directory Management. Agent Deployment Guide

VPN Quick Configuration Guide. Astaro Security Gateway V8

HOWTO: How to configure IPSEC gateway (office) to gateway

Sophos UTM. Remote Access via PPTP. Configuring UTM and Client

HELP DOCUMENTATION E-SSOM DEPLOYMENT GUIDE

How To Establish IPSec VPN connection between Cyberoam and Mikrotik router

Step-by-Step Guide for Setting Up VPN-based Remote Access in a

ZyXEL ZyWALL P1 firmware V3.64

Configuring the WT-4 for ftp (Ad-hoc Mode)

Configuring SSL VPN on the Cisco ISA500 Security Appliance

HTTP Server Setup for McAfee Endpoint Encryption (Formerly SafeBoot) Table of Contents

Dlink DFL 800/1600 series: Using the built-in MS L2TP/IPSEC VPN client with certificates

Step-by-Step Guide for Setting Up VPN-based Remote Access in a Test Lab

VPN Configuration of ProSafe Client and Netgear ProSafe Router:

Setting up D-Link VPN Client to VPN Routers

Cisco SA 500 Series Security Appliance

7. Configuring IPSec VPNs

ADFS Integration Guidelines

Create a VPN on your ipad, iphone or ipod Touch and SonicWALL NSA UTM firewall - Part 1: SonicWALL NSA Appliance

Setting up Hyper-V for 2X VirtualDesktopServer Manual

Planet CS TheGreenBow IPSec VPN Client. Configuration Guide.

4cast Client Specification and Installation

Transcription:

WINXP VPN to ZyWALL Tunneling 1. Setup WINXP VPN 2. Setup ZyWALL VPN This page guides us to setup a VPN connection between the WINXP VPN software and ZyWALL router. There will be several devices we need to setup for this case. They are WINXP VPN software and ZyWALL router. As the figure shown below, the tunnel between PC 2 and ZyWALL ensures the packets flow between them are secure. Because the packets go through the IPSec tunnel are encrypted. To setup this VPN tunnel, the required settings for WINXP and ZyWALL are explained in the following sections. As the red pipe shown in the following figure, the tunneling endpoints are WINXP and ZyWALL. The IP addresses we use in this example are as shown below. PC 1 ZyWALL PC2 192.168.1.33 LAN: 192.168.1.1 WAN: 172.21.1.252 172.21.1.232 1. Setup WINXP VPN - Create a custom MMC console 1. From Windows desktop, click Start, click Run, and in the Open textbox type MMC. Click OK.

2. On the Console window, click Add/Remove Snap-In. 3. In the Add/Remove Snap-In dialog box, click Add. 4. In the Add Standalone Snap-in dialog box, click Computer Management, and then click Add.

5. Verify that Local Computer (default setting) is selected, and click Finish. 6. In the Add Standalone Snap-in dialog box, click Group Policy, and then click Add.

7. Verify that Local Computer (default setting) is selected in the Group Policy Object dialog box, and then click Finish. 8. In the Add Standalone Snap-in dialog box, click Certifications, and then click Add.

9. In the Certificates snap-in dialog box, select Computer account, and click Next. 10. Verify that Local Computer (default setting) is selected, and click Finish.

11. Click Close to close the Add Standalone Snap-in dialog box. 12. Click OK to close the Add/Remove Snap-in dialog box.

- Create IPSec Policy Typically, Windows 2000 gateway is not a member of a domain, so a local IPSec policy is created. If your Windows 2000 gateway is a member of a domain that already exists an local IPSec policy. In this case, you can

create an Organization Unit (OU) in Active Directory to make your WINXP as a member of this OU by assigning the IPSec policy to the Group Policy Object (GPO) of this OU. For more information, please refer to the Assigning IPSec Policy section of Windows 2000 online help. 1. From Windows desktop, click Start, click Run, and in the Open textbox type SECPOL.MSC. Click OK. 2. Choose Security Settings in the left site, and right click IP Security Policies on Local Machine, and then click Create IP Security Policy. 3. Click Next, and type a name for your policy. For example: WINXP to ZyWALL.

4. Uncheck Active the default response rule check box, and click Next. 5. Keep the Edit properties check box selected and click Finish.

5. A dialog window will bring up for you to configure two filter rules for this policy. Note: The IPSec policy is created with default IKE main mode (phase 1) on the General tab. Please check details by clicking the Advanced on this tab. 6. click General, and click Advanced

7. In Key Exchange Settings, click Methods 8. In Key Exchange Security Methods, click Edit, then you can choose IKE Security Algorithms in this step, after you ve done it, click OK

The IPSec tunnel consists of two rules, each of which specifies a tunnel endpoint. Because there are two endpoints so we need two filter rules. One is for the direction from PC 1 to PC 2 (endpoint is ZyWALL), and the other is from PC 2 to PC 1 (endpoint is WINXP). In each rule, a source IP and destination IP for local and remote VPN clients (PC 1 or PC 2) are required. See the guides below. - Build a Filter List from PC 1 to PC 2 1. In WINXP to ZyWALL Properties, uncheck Use Add Wizard check box, and click Add to create a new rule.

2. On the IP Filter List tab, click Add.

3. Type a name for the filter list (e.g., WINXP to ZyWALL), uncheck Use Add Wizard check box, and click Add. 4. In the Source address, choose A specific IP Address, and enter the IP address of PC 2 5. In the Destination address, choose A specific IP Address, and enter the IP address of PC 1

6. Uncheck Mirror check box. 7. On the Protocol tab, leave the protocol type to Any, because IPSec tunnels do not support protocol-specific or port specific filters.

8. On the Description tab, you can give a name for this filter list. The filter name is displayed in the IPSec monitor when the tunnel is active. 9. Click OK to close the windows.

- Build a Filter List from PC 2 to PC 1 1. On the IP Filter List tab, click Add.

2. Type a name for the filter list (e.g., ZyWALL to WINXP), uncheck Use Add Wizard check box, and click Add. 3. In the Source address, choose A specific IP Address, and enter the IP address of PC 1 4. In the Destination address, choose A specific IP Address, and enter the IP address of PC 2

5. Uncheck Mirror check box 6. On the Protocol tab, leave the protocol type to Any, because IPSec tunnels do not support protocol-specific or port specific filters.

7. On the Description tab, you can give a name for this filter list. The filter name is displayed in the IPSec monitor when the tunnel is active. 8. Click OK and Close to close the windows.

- Configure a Rule for PC 1 to PC 2 tunnel 1. Select the first filter list you created above from the IP Filter List. For example, WINXP to ZyWALL.

2. Click Tunnel Setting tab, enter the remote endpoint. For this filter list, the remote IPSec endpoint is ZyWALL.

3. Click Connection Type tab, click All network connections (or click LAN connections if your WINXP does not connect to ISP but LAN). In our example, we choose All network connections. 4. Click Filter Action tab, uncheck Use Add Wizard check box, and click Add.

5. Leave Negotiate security as checked, and uncheck Accept unsecured communication, but always respond using IPSec check box. You must do this to ensure secure connections.

6. Click Add and select Custom (for expert users) if you want to define specific algorithms and session key lifetimes). Please make sure the settings match whatever we will configure in ZyWALL later. 7. Click OK. On the General tab, give a name to the filter action. For example, WINXP to ZyWALL, and click OK.

8. Select the filter action you just created.

9. On the Authentication Methods tab, click Add to select Use this string to protect the key exchange (pre-shared key) option. And enter the string 12345678 in the text box. 10. Click Close.

See the finished screen shot. - Configure a Rule for PC 2 to PC 1 tunnel

1. In the IPSec policy properties, click Add to create a new rule. 2. Select the second filter list you created above from the IP Filter List. For example, ZyWALL to WINXP.

3. Click Tunnel Setting tab, enter the remote endpoint. For this filter list, the remote IPSec endpoint is WINXP.

4. Click Connection Type tab, click All network connections (or click LAN connections if your WINXP does not connect to ISP but LAN). In our example, we choose All network connections. 5. Click Filter Action tab, select the filter action you created.

6. On the Authentication Method tab, configure the same settings as done in the first rule.

7. Click Close. 8. Enable both rules you created in the policy properties and click Close.

Figure 5: See the finished screen shot - Assign Your New IPSec Policy to Your Windows XP 1. In the IP Security Policies on Local Machine MMC snap-in, right click your new policy, and click Assign. 2. A green arrow will appear in the folder icon next to your policy. See the screen shot below.

For more information about configure WINXP IPSec, please refer to the following web site. 1. http://www.microsoft.com/windowsxp/techinfo/planning/security/ipsecsteps.asp 2. http://support.microsoft.com/support/kb/articles/q252/7/35.asp 2. Setup ZyWALL VPN 1. Using a web browser, login ZyWALL by giving the LAN IP address of ZyWALL in URL field. Default LAN IP is 192.168.1.1, default password to login web configurator is 1234. 2. Go to SECURITY->VPN->Press Add button 3. check Active check box and give a name to this policy. 4. Select IPSec Keying Mode to IKE and Negotiation Mode to Main, as we configured in WINXP. 5. Source IP Address Start and Source IP Address End are PC 2 IP in this example. (the secure host behind ZyWALL) 6. Destination IP Address Start and Destination IP Address End are PC 1 in this example. (the secure WINXP PC) Note: You may assign a range of Source/Destination IP addresses for multiple VPN sessions. 7. My IP Addr is the WAN IP of ZyWALL. 8. Secure Gateway IP Addr is the remote WINXP's IP, that is PC 1 in this example. 9. Select Encapsulation Mode to Tunnel. 10. Check the ESP check box. (AH can not be used in SUA/NAT case) 11. Select Encryption Algorithm to DES and Authentication Algorithm to MD5, as we configured in WINXP. 12. Enter the key string 12345678 in the Preshared Key text box, and click Apply.

See the VPN rule screen shot