Netgear SSL312 SSL312 User Manual - Page 20

Routing, Disable Ethernet Port 2. - prosafe performance

Page 20 highlights

NETGEAR ProSafe SSL VPN Concentrator 25 SSL312 Reference Manual services are decrypted by the SSL VPN Concentrator and relayed to the appropriate corporate network servers. . Firewall/Router IP Address 192.168.1.254 Corporate Server IP Address 192.168.1.3 LAN Subnet 192.168.1.0/24 SSL312 IP Address 192.168.1.1 Figure 2-1 Single arm mode has the advantage of being protected by your firewall. In later steps, you will use the following settings when configuring for single arm operation. • Assign Ethernet Port 1 an IP address on your local network. • Disable Ethernet Port 2. • Disable Routing Mode. • Define a default route to the firewall. • If your firewall performs NAT, you must configure the firewall to forward incoming HTTPS traffic to the IP address of Ethernet Port 1. Note: NETGEAR recommends single arm operation for most networks. Routing In the routing, or two port, topology, the SSL VPN Concentrator is connected in parallel with your existing firewall. Ethernet Port 1 is connected to the untrusted side of your firewall, while Ethernet Port 2 connects to your corporate network. 2-2 Installing the SSL312 v2.1, November 2008

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124

NETGEAR ProSafe SSL VPN Concentrator 25 SSL312 Reference Manual
2-2
Installing the SSL312
v2.1, November 2008
services are decrypted by the SSL VPN Concentrator and relayed to the appropriate corporate
network servers.
.
Single arm mode has the advantage of being protected by your firewall.
In later steps, you will use the following settings when configuring for single arm operation.
Assign Ethernet Port 1 an IP address on your local network.
Disable Ethernet Port 2.
Disable Routing Mode.
Define a default route to the firewall.
If your firewall performs NAT, you must configure the firewall to forward incoming HTTPS
traffic to the IP address of Ethernet Port 1.
Routing
In the routing, or two port, topology, the SSL VPN Concentrator is connected in parallel with your
existing firewall. Ethernet Port 1 is connected to the untrusted side of your firewall, while Ethernet
Port 2 connects to your corporate network.
Figure 2-1
Note:
NETGEAR recommends single arm operation for most networks.
Corporate Server
IP Address 192.168.1.3
SSL312 IP Address
192.168.1.1
Firewall/Router
IP Address
192.168.1.254
LAN Subnet
192.168.1.0/24