
ZyWALL/USG Series User’s Guide
6
4.2 How to Configure Site-to-site IPSec VPN Where the Peer has a Dynamic IP Address ..................110
4.2.1 Set Up the ZyWALL/USG IPSec VPN Tunnel of Corporate Network (HQ) ........................... 111
4.2.2 Set Up the ZyWALL/USG IPSec VPN Tunnel of Corporate Network (Branch has a Dynamic IP
Address) ...................................................................................................................................113
4.2.3 Test the IPSec VPN Tunnel ...................................................................................................115
4.2.4 What Can Go Wrong? ...........................................................................................................116
4.3 How to Configure Site-to-site IPSec VPN with FortiGate ................................................................117
4.3.1 Set Up the IPSec VPN Tunnel on the ZyWALL/USG ............................................................117
4.3.2 Set Up the IPSec VPN Tunnel on the FortiGate ....................................................................120
4.3.3 Test the IPSec VPN Tunnel ...................................................................................................123
4.3.4 What Can Go Wrong? ...........................................................................................................124
4.4 How to Configure Site-to-site IPSec VPN with Cisco ......................................................................125
4.4.1 Set Up the IPSec VPN Tunnel on the ZyWALL/USG ............................................................125
4.4.2 Set Up the IPSec VPN Tunnel on the Cisco ..........................................................................130
4.4.3 Test the IPSec VPN Tunnel ..................................................................................................132
4.4.4 What Can Go Wrong? ...........................................................................................................133
4.5 How to Configure Site-to-site IPSec VPN with WatchGuard ...........................................................134
4.5.1 Set Up the IPSec VPN Tunnel on the ZyWALL/USG ............................................................134
4.5.2 Set Up the IPSec VPN Tunnel on the WatchGuard ...............................................................137
4.5.3 Test the IPSec VPN Tunnel ...................................................................................................140
4.5.4 What Can Go Wrong? ...........................................................................................................141
4.6 How to Configure Site-to-site IPSec VPN with a SonicWALL router ...............................................142
4.6.1 Set Up the IPSec VPN Tunnel on the ZyWALL/USG ............................................................142
4.6.2 Set Up the IPSec VPN Tunnel on the SonicWALL ................................................................147
4.6.3 Test the IPSec VPN Tunnel ..................................................................................................149
4.6.4 What Can Go Wrong? ...........................................................................................................150
4.7 How to Configure Site-to-site IPSec VPN with Microsoft (MS) Azure .............................................151
4.7.1 Set Up the IPSec VPN Tunnel on the MS Azure ...................................................................152
4.7.2 Set Up the IPSec VPN Tunnel on the ZyWALL/USG ............................................................158
4.7.3 Test the IPSec VPN Tunnel ...................................................................................................161
4.7.4 What Can Go Wrong? ...........................................................................................................162
4.8 How to Set Up Hub-and-Spoke IPSec VPN ....................................................................................163
4.8.1 Set Up the IPSec VPN Tunnel on the ZyWALL/USG by Using VPN Concentrator ...............164
4.8.2 Hub_HQ-to-Branch_A ...........................................................................................................164
4.8.3 Hub_HQ-to-Branch_B ...........................................................................................................166
4.8.4 Hub_HQ Concentrator ...........................................................................................................168
4.8.5 Spoke_Branch_A ...................................................................................................................168
4.8.6 Spoke_Branch_B ...................................................................................................................171
4.8.7 Test the IPSec VPN Tunnel ...................................................................................................174
4.8.8 What Can Go Wrong? ...........................................................................................................176
4.8.9 Set Up the IPSec VPN Tunnel of ZyWALL/USG without Using VPN Concentrator ...............177
4.8.10 Hub_HQ-to-Branch_A .........................................................................................................177
4.8.11 Hub_HQ-to-Branch_B ..........................................................................................................178