(cổng địa phương và từ xa), bạn cũng có thể cấu hình các giao diện đường hầm trong một khu vực an ninh, trong một khu vực đường hầm thông qua các thiết bị NetScreen chỉ đạo giao thông đến và đi từ tunnel1 VPN. Bạn có thể liên kết một đường hầm VPN cho một số cụ thể | Chapter 4 Policy-Based VPNs LAN-to-LAN VPNs Tunnel Interfaces Beyond the VPN tunnel termination points the local and remote gateways you can also configure tunnel interfaces in either a security zone or in a tunnel zone through which the NetScreen device directs traffic to and from the VPN tunnel1. You can bind a VPN tunnel to a specific numbered with IP address netmask or unnumbered without IP address netmask tunnel interface in a security zone. If the tunnel interface is unnumbered it borrows the IP address from the interface of the security zone in which you created it. Tunnel Interfaces Security Zone Interfaces Numbered Numbered or Unnumbered Numbered When a numbered tunnel interface is in a tunnel zone you cannot bind a VPN tunnel to the tunnel interface. You can only bind a tunnel to the tunnel zone. This allows multiple tunnel interfaces to link to a single tunnel or multiple tunnels to link to a single tunnel interface. In such cases you must create a policy-based VPN configuration. When a tunnel interface is in a security zone you must bind a VPN tunnel to the tunnel interface. Doing so allows you to create a routing-based VPN configuration. The tunnel interface can be numbered or unnumbered. If it is unnumbered the tunnel interface borrows the IP address from the security zone interface. Note Only a numbered tunnel interface that is an interface with an IP address and netmask can support policy-based NAT. When a numbered tunnel interface is in a security zone and is the only interface in that zone you do not need to create a security zone interface. In this case the security zone supports VPN traffic via the tunnel interface but no other kind of traffic. Generally assign an IP address to a tunnel interface if you want the interface to support policy-based NAT. For more information about policy-based NAT see Tunnel Zones and Policy-Based NAT on page 202. You can create a numbered tunnel interface in either a tunnel zone or security zone. 1. If you do not .