Figure 3-8 – NETGEAR ProSafe FVS124G User Manual

Page 37

Advertising
background image

Reference Manual for the ProSafe VPN Firewall 25 with 4 Gigabit LAN and Dual WAN Ports

Network Planning

3-7

202-10085-01, March 2005

Figure 3-8: Single gateway WAN port case for VPN road warrior

The IP address of the gateway WAN port can be either fixed or dynamic. If the IP address is
dynamic, a fully-qualified domain name must be used. If the IP address is fixed, a fully-qualified
domain name is optional.

VPN Road Warrior: Dual Gateway WAN Ports for Improved Reliability

In the case of the dual WAN ports on the gateway VPN firewall (

Figure 3-9

), the remote PC client

initiates the VPN tunnel with the active gateway WAN port (port WAN1 in this example) because
the IP address of the remote PC client is not known in advance. The gateway WAN port must act
as a responder.

Figure 3-9: Dual gateway WAN ports, before rollover, for VPN road warrior

The IP addresses of the gateway WAN ports can be either fixed or dynamic, but a fully-qualified
domain name must always be used because the active WAN port could be either WAN1 or WAN2
(i.e., the IP address of the active WAN port is not known in advance).

Gateway A

bzrouter.dyndns.org

10.5.6.0/24

10.5.6.1

WAN IP

WAN IP

LAN IP

Client B

FQDN

0.0.0.0

VPN Router
(at employer's
main office)

Road Warrior Example (Single WAN Port)

Remote PC
(running NETGEAR
ProSafe VPN Client)

Fully-Qualified Domain Names (FQDN)
- optional for Fixed IP addresses
- required for Dynamic IP addresses

Gateway A

bzrouter.dyndns.org

10.5.6.0/24

10.5.6.1

WAN1 IP

WAN IP

LAN IP

Client B

0.0.0.0

VPN Router
(at employer's
main office)

Road Warrior Example

(Dual WAN Ports, Before Rollover)

Remote PC
(running NETGEAR
ProSafe VPN Client)

Fully-Qualified Domain Names (FQDN)
- required for Fixed IP addresses
- required for Dynamic IP addresses

WAN2 port inactive

WAN2 IP (N/A)

X

X

Advertising