Netgear FVX538v2 FVX538v2 Reference Manual - Page 34

Auto-Rollover Mode, WAN Failure Detection Method, Load Balancing Mode, Classical Routing, Viewing

Page 34 highlights

ProSafe VPN Firewall 200 FVX538 Reference Manual The VPN firewall supports the following modes: • Auto-Rollover Mode. In this mode, the selected WAN interface is made primary and the other is the rollover link. As long as the primary link is up, all traffic is sent over the primary link. Once the primary WAN interface goes down, the rollover link is brought up to send the traffic. Traffic will automatically roll back to the original primary link once the original primary link is back up and running again. If you want to use a redundant ISP link for backup purposes, select the WAN port that will act as the primary link for this mode. Ensure that the backup WAN port has also been configured and that you configure the WAN Failure Detection Method to support Auto-Rollover. • Load Balancing Mode. In this mode the VPN firewall distributes the outbound traffic equally among the WAN interfaces that are functional. Note: Scenarios could arise when load balancing needs to be bypassed for certain traffic or applications. Here the traffic needs to go on a specific WAN interface. This is done with the protocol binding rules of that WAN interface. The rule should match the desired traffic. For both alternatives, you must also set up Network Address Translation (NAT): • NAT. NAT is the technology which allows all PCs on your LAN to share a single Internet IP address. From the Internet, there is only a single device (the VPN firewall) and a single IP address. PCs on your LAN can use any private IP address range, and these IP addresses are not visible from the Internet. - The VPN firewall uses NAT to select the correct PC (on your LAN) to receive any incoming data. - If you only have a single Internet IP address, you MUST use NAT. NAT is the default setting. • Classical Routing. In this mode, the VPN firewall performs routing, but without NAT. To gain Internet access, each PC on your LAN must have a valid Internet IP address. If your ISP has allocated many IP addresses to you, and you have assigned one of these addresses to each PC, you can choose Classical Routing. Or, you can use Classical Routing for routing private IP addresses within a campus environment. Otherwise, selecting this method will not allow Internet access through this VPN firewall. To learn the status of the WAN ports, you can view the Router Status screen (see "Viewing the VPN Firewall Configuration and System Status" on page 6-30) or look at the LEDs on the front panel (see "VPN Firewall Front and Rear Panels" on page 1-6). 2-8 Connecting the VPN Firewall to the Internet v1.0, January 2010

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248
  • 249
  • 250

ProSafe VPN Firewall 200 FVX538 Reference Manual
2-8
Connecting the VPN Firewall to the Internet
v1.0, January 2010
The VPN firewall supports the following modes:
Auto-Rollover Mode
. In this mode, the selected WAN interface is made primary and the other
is the rollover link. As long as the primary link is up, all traffic is sent over the primary link.
Once the primary WAN interface goes down, the rollover link is brought up to send the traffic.
Traffic will automatically roll back to the original primary link once the original primary link
is back up and running again.
If you want to use a redundant ISP link for backup purposes, select the WAN port that will act
as the primary link for this mode. Ensure that the backup WAN port has also been configured
and that you configure the
WAN Failure Detection Method
to support Auto-Rollover.
Load Balancing Mode
. In this mode the VPN firewall distributes the outbound traffic equally
among the WAN interfaces that are functional.
For both alternatives, you must also set up Network Address Translation (NAT):
NAT
.
NAT is the technology which allows all PCs on your LAN to share a single Internet IP
address. From the Internet, there is only a single device (the VPN firewall) and a single IP
address. PCs on your LAN can use any private IP address range, and these IP addresses are not
visible from the Internet.
The VPN firewall uses NAT to select the correct PC (on your LAN) to receive any
incoming data.
If you only have a single Internet IP address, you MUST use NAT.
NAT is the default setting.
Classical Routing
.
In this mode, the VPN firewall performs routing, but without NAT. To gain
Internet access, each PC on your LAN must have a valid Internet IP address.
If your ISP has allocated many IP addresses to you, and you have assigned one of these
addresses to each PC, you can choose Classical Routing. Or, you can use Classical Routing for
routing private IP addresses within a campus environment. Otherwise, selecting this method
will not allow Internet access through this VPN firewall.
To learn the status of the WAN ports, you can view the Router Status screen (see
“Viewing the
VPN Firewall Configuration and System Status” on page 6-30
) or look at the LEDs on the front
panel (see
“VPN Firewall Front and Rear Panels” on page 1-6
).
Note:
Scenarios could arise when load balancing needs to be bypassed for certain
traffic or applications. Here the traffic needs to go on a specific WAN
interface. This is done with the protocol binding rules of that WAN interface.
The rule should match the desired traffic.