Netgear SRX5308 SRX5308 Reference Manual - Page 148

Table 5-2. IPsec VPN Wizard Settings for a Gateway-to-Gateway Tunnel continued, For more information

Page 148 highlights

ProSafe Gigabit Quad WAN SSL VPN Firewall SRX5308 Reference Manual Table 5-2. (IPsec) VPN Wizard Settings for a Gateway-to-Gateway Tunnel (continued) Setting Description (or Subfield and Description) Enable RollOver? If you have configured the VPN firewall to function in WAN autorollover mode (see "Configuring the Auto-Rollover Mode and Failure Detection Method" on page 2-18), select the Enable RollOver? check box. Then, from the corresponding drop-down list, select the backup WAN interface. After an auto-rollover has occurred, the VPN tunnel will be reestablished using the backup WAN interface. End Point Information a What is the Remote WAN's IP Enter the IP address or Internet name (FQDN) of the WAN interface on Address or Internet Name? the remote VPN tunnel endpoint. What is the Local WAN's IP Address or Internet Name? When you select the Gateway radio button in the About VPN Wizard section of the screen, the IP address of the VPN firewall's active WAN interface is automatically entered. Secure Connection Remote Accessibility What is the remote LAN IP Address? What is the remote LAN Subnet Mask? Enter the LAN IP address of the remote gateway. Note: The remote LAN IP address must be in a different subnet than the local LAN IP address. For example, if the local subnet is 192.168.1.x, then the remote subnet could be 192.168.10.x. but could not be 192.168.1.x. If this information is incorrect, the tunnel will fail to connect. Enter the LAN subnet mask of the remote gateway. a. Both local and remote endpoints should be defined as either FQDNs or IP addresses. A combination of an IP address and an FQDN is not supported. . Tip: To ensure that tunnels stay active, after completing the wizard, manually edit the VPN policy to enable keepalive, which periodically sends ping packets to the host on the peer side of the network to keep the tunnel alive. For more information, see "Configuring Keepalives" on page 5-56. . Tip: For DHCP WAN configurations, first set up the tunnel with IP addresses. After you have validated the connection, you can use the wizard to create new policies using the FQDN for the WAN addresses. 5-6 Virtual Private Networking Using IPsec Connections v1.0, April 2010

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248
  • 249
  • 250
  • 251
  • 252
  • 253
  • 254
  • 255
  • 256
  • 257
  • 258
  • 259
  • 260
  • 261
  • 262
  • 263
  • 264
  • 265
  • 266
  • 267
  • 268
  • 269
  • 270
  • 271
  • 272
  • 273
  • 274
  • 275
  • 276
  • 277
  • 278
  • 279
  • 280
  • 281
  • 282
  • 283
  • 284
  • 285
  • 286
  • 287
  • 288
  • 289
  • 290
  • 291
  • 292
  • 293
  • 294
  • 295
  • 296
  • 297
  • 298
  • 299
  • 300
  • 301
  • 302
  • 303
  • 304
  • 305
  • 306
  • 307
  • 308
  • 309
  • 310
  • 311
  • 312
  • 313
  • 314
  • 315
  • 316
  • 317
  • 318
  • 319
  • 320
  • 321
  • 322
  • 323
  • 324
  • 325
  • 326
  • 327
  • 328
  • 329
  • 330
  • 331
  • 332
  • 333
  • 334
  • 335
  • 336
  • 337
  • 338
  • 339
  • 340
  • 341
  • 342
  • 343
  • 344
  • 345
  • 346
  • 347
  • 348
  • 349
  • 350
  • 351
  • 352
  • 353
  • 354
  • 355
  • 356
  • 357
  • 358
  • 359
  • 360
  • 361
  • 362
  • 363
  • 364
  • 365
  • 366
  • 367
  • 368
  • 369
  • 370
  • 371
  • 372
  • 373
  • 374
  • 375
  • 376
  • 377
  • 378
  • 379
  • 380
  • 381
  • 382
  • 383
  • 384

ProSafe Gigabit Quad WAN SSL VPN Firewall SRX5308 Reference Manual
5-6
Virtual Private Networking Using IPsec Connections
v1.0, April 2010
.
.
Enable RollOver?
If you have configured the VPN firewall to function in WAN auto-
rollover mode (see
“Configuring the Auto-Rollover Mode and Failure
Detection Method” on page 2-18
), select the
Enable RollOver?
check
box. Then, from the corresponding drop-down list, select the backup
WAN interface. After an auto-rollover has occurred, the VPN tunnel will
be reestablished using the backup WAN interface.
End Point Information
a
What is the Remote WAN's IP
Address or Internet Name?
Enter the IP address or Internet name (FQDN) of the WAN interface on
the remote VPN tunnel endpoint.
What is the Local WAN's IP
Address or Internet Name?
When you select the Gateway radio button in the About VPN Wizard
section of the screen, the IP address of the VPN firewall’s active WAN
interface is automatically entered.
Secure Connection Remote Accessibility
What is the remote LAN IP
Address?
Enter the LAN IP address of the remote gateway.
Note
: The remote LAN IP address must be in a different subnet than
the local LAN IP address. For example, if the local subnet is
192.168.1.x, then the remote subnet could be 192.168.10.x. but could
not be 192.168.1.x. If this information is incorrect, the tunnel will fail to
connect.
What is the remote LAN
Subnet Mask?
Enter the LAN subnet mask of the remote gateway.
a. Both local and remote endpoints should be defined as either FQDNs or IP addresses. A combination of an IP address and
an FQDN is not supported.
Tip:
To ensure that tunnels stay active, after completing the wizard, manually
edit the VPN policy to enable keepalive, which periodically sends ping
packets to the host on the peer side of the network to keep the tunnel alive.
For more information, see
“Configuring Keepalives” on page 5-56
.
Tip:
For DHCP WAN configurations, first set up the tunnel with IP addresses.
After you have validated the connection, you can use the wizard to create
new policies using the FQDN for the WAN addresses.
Table 5-2. (IPsec) VPN Wizard Settings for a Gateway-to-Gateway Tunnel (continued)
Setting
Description (or Subfield and Description)