Netgear SRXN3205 SRXN3205 Reference Manual - Page 140

Adding Routes for VPN Tunnel Clients, Replacing and Deleting Client Routes, Add Routes, Subnet Mask - replacement

Page 140 highlights

ProSafe Wireless-N VPN Firewall SRXN3205 Reference Manual Adding Routes for VPN Tunnel Clients The VPN Tunnel Clients assume that the following networks are located across the VPN over the SSL tunnel: Note: VPN client routs need to be added in split tunnel mode only. • The subnet containing the client IP address (PPP interface), as determined by the class of the address (Class A, B, or C). • Subnets specified in the Configured Client Routes table. If the assigned client IP address range is in a different subnet than the corporate network, or the corporate network has multiple subnets, you must define Client Routes. To add an SSL VPN Tunnel client route, follow these steps: 1. Access the SSL VPN Client tab shown in Figure 7-5. 2. In the Add Routes section, enter the Destination Network IP address of a local area network or subnet. For example, enter 192.168.0.0. 3. Enter the appropriate Subnet Mask. 4. Click Add. The "Operation succeeded" message appears at the top of the tab and the new client route is listed in the Configured Client Routes table. Restart the firewall if VPN tunnel clients are currently connected. Restarting forces clients to reconnect and receive new addresses and routes. Replacing and Deleting Client Routes If the specifications of an existing route need to be changed, follow these steps: 1. Make a new entry with the correct specifications. 2. In the Configured Client Routes table, click the Delete button in the actions column. 3. If an existing route is no longer needed for any reason, you can delete it. 7-12 Virtual Private Networking Using SSL v1.0, October 2008

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218

ProSafe Wireless-N VPN Firewall SRXN3205 Reference Manual
7-12
Virtual Private Networking Using SSL
v1.0, October 2008
Adding Routes for VPN Tunnel Clients
The VPN Tunnel Clients assume that the following networks are located across the VPN over the
SSL tunnel:
The subnet containing the client IP address (PPP interface), as determined by the class of the
address (Class A, B, or C).
Subnets specified in the Configured Client Routes table.
If the assigned client IP address range is in a different subnet than the corporate network, or the
corporate network has multiple subnets, you must define Client Routes.
To add an SSL VPN Tunnel client route, follow these steps:
1.
Access the SSL VPN Client tab shown in
Figure 7-5
.
2.
In the
Add Routes
section, enter the Destination Network IP address of a local area network
or subnet. For example, enter 192.168.0.0.
3.
Enter the appropriate
Subnet Mask
.
4.
Click
Add
.
The “Operation succeeded” message appears at the top of the tab and the new client route is
listed in the Configured Client Routes table.
Restart the firewall if VPN tunnel clients are currently connected. Restarting forces clients to
reconnect and receive new addresses and routes.
Replacing and Deleting Client Routes
If the specifications of an existing route need to be changed, follow these steps:
1.
Make a new entry with the correct specifications.
2.
In the
Configured Client Routes
table, click the
Delete
button in the actions column.
3.
If an existing route is no longer needed for any reason, you can delete it.
Note:
VPN client routs need to be added in split tunnel mode only.