IPSec site-to-site configuration guide with Zyxel Unified Security Gateway (USG)
1. Login to vipilink portal and create network
1.1 Go to Networks section and create a new network.
1.2 Define the network name.
1.3 Select the region and gateways number.
1.4 Choose the subnet.
1.5 Activate gateways for all users section is active by default. If you want to disable this function - just remove the mark.
2. Create the IPsec tunnel in the Vipilink portal
2.1 Go to Networks section and click on the subnet that you created in Step-1
.
2.2 Click on Gateway and add a Tunnel. Choose IPSec Site-to-Site Tunnel and press to continue.
2.3 Choose between a Single-Tunnel and Dual-Tunnel.
2.4 General Settings
Values
-
Name
-
Public IP
-
Vipilink Side Subnets
-
Pre-Shared Key
-
Remote ID
-
Remote Side Subnets
2.5 Advanced Settings
Values
-
Ike Version
-
Tunnel Lifetime
-
Encryption (Phase 1)
-
Integrity (Phase 1)
-
Diffie-Helman Groups (Phase 1)
-
Ike Lifetime
-
Dead Peer Detection Delay
-
Dead Peer Detection Timeout
-
Encryption (Phase 2)
-
Integrity (Phase 2)
-
Diffie-Helman Groups (Phase 2)
2.6 You can also manage a Network
, Regions
, Access
, Firewall Rules
, Routes Table
, enable Split Tunneling
and Private DNS
.
3. Create the IPsec tunnel on Zyxel USG
3.1 Log in to ZyXel USG interface and go Configuration/VPN/IPSec VPN/VPN Gateway
and add a new VPN Gateway.
3.2 Define the name of VPN Gateway.
3.3 Choose IKE Version.
3.4. In My Address section choose the outgoing interface.
3.5 Put the IP Address of Vipilink Gateway as a Peer Gateway Address.
3.6. Enter the preshared key that you have configured at Vipilink portal.
3.7 Choose Phase 1 Setting.
-
Encryption - AES256
-
Authentication - SHA256
-
DH-Group - 14
-
SA Life Time - 28800
-
Negotiation Mode - Main
4.1 Go to Configuration/VPN/IPSec VPN/VPN Connection
and a new tunnel.
4.2 Enable and add a name to rule.
4.3 Select Site-to-Site and select created VPN Gateway.
4.4 Local Policy should be for you LAN subnet, remote policy - for Vipilink subnet.
4.5 Choose Phase 2 Setting.
-
SA Life Time - 3600
-
Active Protocol - ESP
-
Encapsulation - Tunnel
-
Encryption - AES256
-
Authentication - SHA256
-
Perfect Forward Secrecy (PFS) - DH14
5.1 Verify connectivity.