Netgear FVS338 FVS338 Reference Manual - Page 95

Virtual Private Networking, Dual WAN Port Systems, Table 5-1. - ike policy local fqdn

Page 95 highlights

Chapter 5 Virtual Private Networking This chapter describes how to use the Virtual Private Networking (VPN) features of the VPN firewall. VPN tunnels provide secure, encrypted communications between your local network and a remote network or computer. Tip: When using dual WAN port networks, use the VPN Wizard to configure the basic parameters and then edit the VPN and IKE Policy screens for the various VPN scenarios. Dual WAN Port Systems The dual WAN ports in the VPN firewall can be configured for rollover mode for increased system reliability by specifying the Broadband connection with the Dialup connection as backup. This WAN mode choice then impacts how the VPN features must be configured. Table 5-1. IP Addressing Requirements for VPN in Dual WAN Port Systems Configuration and WAN IP address Rollover Modea VPN Road Warrior (client-to-gateway) VPN Gateway-to-Gateway VPN Telecommuter (client-to-gateway through a NAT router) Fixed Dynamic Fixed Dynamic Fixed Dynamic FQDN required FQDN required FQDN required FQDN required FQDN required FQDN required a. All tunnels must be re-established after a rollover using the new WAN IP address. Dedicated Mode Allowed (FQDN optional) FQDN required Allowed (FQDN optional) FQDN required Allowed (FQDN optional) FQDN required The use of fully qualified domain names is mandatory when the WAN ports are in rollover mode ("Configuring the WAN Mode" on page 2-15); also required for the VPN tunnels to fail over. When using rollover mode, you must configure a Dynamic DNS service (see "Configuring Dynamic DNS (If Needed)" on page 2-16 to select and configure the Dynamic DNS service). Virtual Private Networking 5-1 v1.0, March 2008

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198

Virtual Private Networking
5-1
v1.0, March 2008
Chapter 5
Virtual Private Networking
This chapter describes how to use the Virtual Private Networking (VPN) features of the VPN
firewall. VPN tunnels provide secure, encrypted communications between your local network and
a remote network or computer.
Dual WAN Port Systems
The dual WAN ports in the VPN firewall can be configured for rollover mode for increased system
reliability by specifying the Broadband connection with the Dialup connection as backup. This
WAN mode choice then impacts how the VPN features must be configured.
The use of fully qualified domain names is mandatory when the WAN ports are in rollover mode
(
“Configuring the WAN Mode” on page 2-15
); also required for the VPN tunnels to fail over.
When using rollover mode, you must configure a Dynamic DNS service (see
“Configuring
Dynamic DNS (If Needed)” on page 2-16
to select and configure the Dynamic DNS service).
Tip:
When using dual WAN port networks, use the VPN Wizard to configure the basic
parameters and then edit the VPN and IKE Policy screens for the various VPN
scenarios.
Table 5-1.
IP Addressing Requirements for VPN in Dual WAN Port Systems
Configuration and WAN IP address
Rollover Mode
a
a. All tunnels must be re-established after a rollover using the new WAN IP address.
Dedicated Mode
VPN Road Warrior
(client-to-gateway)
Fixed
FQDN required
Allowed (FQDN optional)
Dynamic
FQDN required
FQDN required
VPN Gateway-to-Gateway
Fixed
FQDN required
Allowed (FQDN optional)
Dynamic
FQDN required
FQDN required
VPN Telecommuter
(client-to-gateway through a
NAT router)
Fixed
FQDN required
Allowed (FQDN optional)
Dynamic
FQDN required
FQDN required