Netgear DGND3300v2 User Manual - Page 154

Using a Fully Qualified Domain Name FQDN, VPNC Example, Network Interface Addressing - custom firmware

Page 154 highlights

N300 Wireless Dual Band ADSL2+ Modem Router DGND3300v2 User Manual Verify that the firmware is up to date, and that you have all the addresses and parameters to be set on both sides. Check that there are no firewall restrictions. 10.506.0/24 172.23.9.0/24 Gateway A (DGND3300v2) Gateway B LAN IP 10.5.6.1 Internet WAN IP example.org (FQDN) WAN IP example2.org (FQDN) LAN IP 172.23.9.1 Figure 72. VPNC Example, Network Interface Addressing Table 9. N300 Wireless Modem Router with FQDN to Gateway B Profile Summary VPN Consortium Scenario Scenario 1 Type of VPN LAN-to-LAN or gateway-to-gateway (not PC/client-to-gateway) Security scheme: IKE with pre-shared secret/key (not certificate based) IP addressing: NETGEAR-Gateway A Fully qualified domain name (FQDN) NETGEAR-Gateway B FQDN Using a Fully Qualified Domain Name (FQDN) Many ISPs provide connectivity to their customers using dynamic instead of static IP addressing. This means that a user's IP address does not remain constant over time, which presents a challenge for gateways attempting to establish VPN connectivity. A Dynamic DNS (DDNS) service allows a user whose public IP address is dynamically assigned to be located by a host or domain name. It provides a central public database where information (such as email addresses, host names, and IP addresses) can be stored and retrieved. Now, a gateway can be configured to use a third-party service instead of a permanent and unchanging IP address to establish bidirectional VPN connectivity. To use DDNS, you must register with a DDNS service provider. Some DDNS service providers include: • DynDNS: www.dyndns.org • TZO.com: netgear.tzo.com • ngDDNS: ngddns.iego.net In this example, Gateway A is configured using a sample FQDN provided by a DDNS service provider. In this case we established the hostname dgnd3300v2.dyndns.org for Gateway A using the DynDNS service. Gateway B uses the DDNS service provider when establishing a VPN tunnel. 154 | Appendix C. NETGEAR VPN Configuration

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177

154
|
Appendix C.
NETGEAR VPN Configuration
N300 Wireless Dual Band ADSL2+ Modem Router DGND3300v2 User Manual
Verify that the firmware is up to date, and that you have all the addresses and parameters to
be set on both sides. Check that there are no firewall restrictions.
Figure 72. VPNC Example, Network Interface Addressing
Using a Fully Qualified Domain Name (FQDN)
Many ISPs provide connectivity to their customers using dynamic instead of static IP
addressing. This means that a user’s IP address does not remain constant over time, which
presents a challenge for gateways attempting to establish VPN connectivity.
A Dynamic DNS (DDNS) service allows a user whose public IP address is dynamically
assigned to be located by a host or domain name. It provides a central public database where
information (such as email addresses, host names, and IP addresses) can be stored and
retrieved. Now, a gateway can be configured to use a third-party service instead of a
permanent and unchanging IP address to establish bidirectional VPN connectivity.
To use DDNS, you must register with a DDNS service provider. Some DDNS service
providers include:
DynDNS: www.dyndns.org
TZO.com: netgear.tzo.com
ngDDNS: ngddns.iego.net
In this example, Gateway A is configured using a sample FQDN provided by a DDNS service
provider. In this case we established the hostname dgnd3300v2.dyndns.org for Gateway A
using the DynDNS service. Gateway B uses the DDNS service provider when establishing a
VPN tunnel.
Table 9.
N300 Wireless Modem Router with FQDN to Gateway B Profile Summary
VPN Consortium Scenario
Scenario 1
Type of VPN
LAN-to-LAN or gateway-to-gateway (not PC/client-to-gateway)
Security scheme:
IKE with pre-shared secret/key (not certificate based)
IP addressing:
NETGEAR-Gateway A
Fully qualified domain name (FQDN)
NETGEAR-Gateway B
FQDN
Gateway A
WAN IP
Internet
10.506.0/24
(DGND3300v2)
LAN IP
10.5.6.1
example.org
WAN IP
example2.org
Gateway B
LAN IP
172.23.9.1
172.23.9.0/24
(FQDN)
(FQDN)