Netgear FWG114P FWG114P Reference Manual - Page 137

IP Address

Page 137 highlights

Reference Manual for the ProSafe Wireless 802.11g Firewall/Print Server Model FWG114P - From the Remote VPN Endpoint Address Type drop-down box, select IP Address. - Type 0.0.0.0 as the Address Data of the client because we are assuming the remote PC will have a dynamically assigned IP address. This will also be entered in the VPN Client Internal Network IP Address field, as seen in "My Identity" on page 8-40. - Type 86400 in the SA Life Time (Seconds) field. - Type 0 in the SA Life Time (Kbytes) field. - Check the IPSec PFS check box to enable Perfect Forward Secrecy. This will also be entered in the VPN Client Security Policy Enable Perfect Forward Secrecy check box, as seen in "Security Policy" on page 8-41. - From the PFS Key Group drop-down box, select Group 2 (1024 Bit). This will also be entered in the VPN Client Security Policy PFS Key Group drop-down selection box, as seen in "Security Policy" on page 8-41. - From the Traffic Selector Local IP drop-down box, select Subnet addresses. This will also be entered in the VPN Client Connection Remote Party Identity and Addressing ID Type field, as seen in "Security Policy Editor New Connection" on page 8-39. Note: Selecting ANY for the Traffic Selectors means all traffic goes through the IPSec tunnel and prevents access to the Internet. - Type the starting LAN IP Address of the FWG114P in the Local IP Start IP Address field. For this example, we used 192.168.0.0 which is the default LAN IP address of the FWG114P. This will also be entered in the VPN Client Connection Remote Party Identity and Addressing Subnet field, as seen in "Security Policy Editor New Connection" on page 8-39. - Type the LAN Subnet Mask of the FWG114P (255.255.255.0 in our example) in the Local IP Subnet Mask field. This will also be entered in the VPN Client Connection Remote Party Identity and Addressing Mask field, as seen in "Security Policy Editor New Connection" on page 8-39. - From the Traffic Selector Remote IP drop-down box, select Single addresses. - Type 0.0.0.0 as the start IP Address of the in the Remote IP Start IP Address field because we are assuming the remote PC will have a dynamically assigned IP address. This will also be entered in the VPN Client My Identity Internal Network IP Address field, as seen in "My Identity" on page 8-40. - Select the Enable Encryption check box. This will also be selected in the VPN Client Security Policy Key Exchange (Phase 2) Encapsulation Protocol (ESP) check box, as seen in "Connection Security Policy Key Exchange (Phase 2)" on page 8-43. - From the ESP Configuration Encryption Algorithm drop-down box, select 3DES. This will also be entered in the VPN Client Security Policy Key Exchange (Phase 2) Encrypt Alg field, as seen in "Connection Security Policy Key Exchange (Phase 2)" on page 8-43. Virtual Private Networking March 2004, 202-10027-01 8-37

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248
  • 249
  • 250
  • 251
  • 252
  • 253
  • 254
  • 255
  • 256
  • 257
  • 258
  • 259
  • 260
  • 261
  • 262
  • 263
  • 264
  • 265
  • 266
  • 267
  • 268
  • 269
  • 270
  • 271
  • 272
  • 273
  • 274
  • 275
  • 276
  • 277
  • 278
  • 279
  • 280

Reference Manual for the ProSafe Wireless 802.11g
Firewall/Print Server Model FWG114P
Virtual Private Networking
8-37
March 2004, 202-10027-01
From the Remote VPN Endpoint Address Type drop-down box, select
IP Address
.
Type
0.0.0.0
as the Address Data of the client because we are assuming the remote PC will
have a dynamically assigned IP address. This will also be entered in the VPN Client
Internal Network IP Address field, as seen in
“My Identity” on page 8-40
.
Type
86400
in the SA Life Time (Seconds) field.
Type
0
in the SA Life Time (Kbytes) field.
Check the
IPSec PFS
check box to enable Perfect Forward Secrecy. This will also be
entered in the VPN Client Security Policy Enable Perfect Forward Secrecy check box, as
seen in
“Security Policy” on page 8-41
.
From the PFS Key Group drop-down box, select
Group 2 (1024 Bit)
. This will also be
entered in the VPN Client Security Policy PFS Key Group drop-down selection box, as
seen in
“Security Policy” on page 8-41
.
From the Traffic Selector Local IP drop-down box, select
Subnet addresses
. This will
also be entered in the VPN Client Connection Remote Party Identity and Addressing ID
Type field, as seen in
“Security Policy Editor New Connection” on page 8-39
.
Note:
Selecting ANY for the Traffic Selectors means all traffic goes through the IPSec
tunnel and prevents access to the Internet.
Type the starting LAN IP Address of the FWG114P in the Local IP Start IP Address field.
For this example, we used
192.168.0.0
which is the default LAN IP address of the
FWG114P
.
This will also be entered in the VPN Client Connection Remote Party Identity
and Addressing Subnet field, as seen in
“Security Policy Editor New Connection” on page
8-39
.
Type the LAN Subnet Mask of the FWG114P (
255.255.255.0
in our example) in the Local
IP Subnet Mask field. This will also be entered in the VPN Client Connection Remote
Party Identity and Addressing Mask field, as seen in
“Security Policy Editor New
Connection” on page 8-39
.
From the Traffic Selector Remote IP drop-down box, select
Single addresses
.
Type
0.0.0.0
as the start IP Address of the in the Remote IP Start IP Address field because
we are assuming the remote PC will have a dynamically assigned IP address. This will
also be entered in the VPN Client My Identity Internal Network IP Address field, as seen
in
“My Identity” on page 8-40
.
Select the
Enable Encryption
check box. This will also be selected in the VPN Client
Security Policy Key Exchange (Phase 2) Encapsulation Protocol (ESP) check box, as seen
in
“Connection Security Policy Key Exchange (Phase 2)” on page 8-43
.
From the ESP Configuration Encryption Algorithm drop-down box, select
3DES
. This
will also be entered in the VPN Client Security Policy Key Exchange (Phase 2) Encrypt
Alg field, as seen in
“Connection Security Policy Key Exchange (Phase 2)” on page 8-43
.