Netgear SRXN3205 SRXN3205 Reference Manual - Page 109

Creating a VPN Client to SRXN3205 Connection, Configuring the SRXN3205

Page 109 highlights

ProSafe Wireless-N VPN Firewall SRXN3205 Reference Manual Creating a VPN Client to SRXN3205 Connection This section describes how to configure a VPN connection between a Windows PC and the SRXN3205 firewall. Using the SRXN3205's VPN Wizard, we will create VPN client policies (IKE and VPN) that will allow remote PCs to connect from locations in which their IP addresses are unknown in advance. The PCs may be directly connected to the Internet or may be behind NAT routers. Each PC will use Netgear's ProSafe VPN Client software. Since the PC's IP address is assumed to be unknown, the PC must always be the initiator of the connection. This procedure was developed and tested using: • Netgear SRXN3205 ProSafe Wireless-N VPN Firewall • Netgear ProSafe VPN Client • NAT router: Netgear FVX538 Configuring the SRXN3205 1. Start/open the VPN Wizard. 2. Select the VPN Client radio button for type of VPN connection. 3. Give the client connection a name, such as "client". 4. Enter a value for the pre-shared key. 5. Enter the Remote Identifier Information. The default is srxn_remote.com. 6. Enter the Local Identifier information. The default is srxn_local.com 7. Click Apply to create the "client" VPN Client. The VPN Policies screen is displayed showing the VPN Client policy as enabled. 8. Click the IKE Policies tab to display the IKE Policies table and click Edit adjacent to the "client" policy to view the policy details. You can augment user authentication security by enabling the XAUTH server by selecting the Edge Device radio box and then adding users to the user database (see "Extended Authentication (XAUTH) Configuration" on page 6-22 and "User Database Configuration" on page 6-24, respectively). As an alternative to the local user database, you can also choose a RADIUS server. Virtual Private Networking Using IPsec 6-7 v1.0, October 2008

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218

ProSafe Wireless-N VPN Firewall SRXN3205 Reference Manual
Virtual Private Networking Using IPsec
6-7
v1.0, October 2008
Creating a VPN Client to SRXN3205 Connection
This section describes how to configure a VPN connection between a Windows PC and the
SRXN3205 firewall.
Using the SRXN3205's VPN Wizard, we will create VPN client policies (IKE and VPN) that will
allow remote PCs to connect from locations in which their IP addresses are unknown in advance.
The PCs may be directly connected to the Internet or may be behind NAT routers.
Each PC will use Netgear's ProSafe VPN Client software. Since the PC's IP address is assumed to
be unknown, the PC must always be the initiator of the connection.
This procedure was developed and tested using:
Netgear SRXN3205 ProSafe Wireless-N VPN Firewall
Netgear ProSafe VPN Client
NAT router: Netgear FVX538
Configuring the SRXN3205
1.
Start/open the VPN Wizard.
2.
Select the
VPN Client
radio button for type of VPN connection.
3.
Give the client connection a name, such as “client”.
4.
Enter a value for the pre-shared key.
5.
Enter the Remote Identifier Information. The default is srxn_remote.com.
6.
Enter the Local Identifier information. The default is srxn_local.com
7.
Click
Apply
to create the “client” VPN Client. The
VPN Policies
screen is displayed showing
the VPN Client policy as enabled.
8.
Click the
IKE Policies
tab to display the
IKE Policies
table and click
Edit
adjacent to the
“client” policy to view the policy details.
You can augment user authentication security by enabling the XAUTH server by selecting the
Edge Device
radio box and then adding users to the user database (see
“Extended
Authentication (XAUTH) Configuration” on page 6-22
and
“User Database Configuration” on
page 6-24
, respectively). As an alternative to the local user database, you can also choose a
RADIUS server.