Netgear FVX538 FVX538 Reference Manual - Page 204
VPN Road Warrior: Single Gateway WAN Port Reference Case
UPC - 606449037234
View all Netgear FVX538 manuals
Add to My Manuals
Save this manual to your list of manuals |
Page 204 highlights
ProSafe VPN Firewall 200 FVX538 Reference Manual VPN Road Warrior: Single Gateway WAN Port (Reference Case) In the case of the single WAN port on the gateway VPN firewall (Figure C-9), the remote PC client initiates the VPN tunnel because the IP address of the remote PC client is not known in advance. The gateway WAN port must act as the responder. 10.5.6.0/24 Road Warrior Example (Single WAN Port) Client B LAN IP 10.5.6.1 Gateway A VPN Router (at employer's main office) WAN IP FQDN bzrouter.dyndns.org Fully-Qualified Domain Names (FQDN) - optional for Fixed IP addresses - required for Dynamic IP addresses WAN IP 0.0.0.0 Remote PC (running NETGEAR ProSafe VPN Client) Figure C-9 The IP address of the gateway WAN port can be either fixed or dynamic. If the IP address is dynamic, a fully-qualified domain name must be used. If the IP address is fixed, a fully-qualified domain name is optional. VPN Road Warrior: Dual Gateway WAN Ports for Improved Reliability In the case of the dual WAN ports on the gateway VPN firewall (Figure C-10), the remote PC client initiates the VPN tunnel with the active gateway WAN port (port WAN1 in this example) because the IP address of the remote PC client is not known in advance. The gateway WAN port must act as a responder. 10.5.6.0/24 Road Warrior Example (Dual WAN Ports, Before Rollover) LAN IP 10.5.6.1 Gateway A VPN Router (at employer's main office) WAN1 IP bzrouter.dyndns.org X WAN2 port inactive X WAN2 IP (N/A) Fully-Qualified Domain Names (FQDN) - required for Fixed IP addresses - required for Dynamic IP addresses WAN IP 0.0.0.0 Client B Remote PC (running NETGEAR ProSafe VPN Client) Figure C-10 C-12 Network Planning for Dual WAN Ports v1.0, August 2006