NETGEAR SRX5308 Reference Manual page 140

Prosafe gigabit quad wan ssl vpn firewall
Hide thumbs Also See for SRX5308:
Table of Contents

Advertisement

ProSafe Gigabit Quad WAN SSL VPN Firewall SRX5308
Table 29. IPSec VPN Wizard settings for a gateway-to-gateway tunnel (continued)
Setting
What is the Local WAN's IP
Address or Internet Name?
Secure Connection Remote Accessibility
What is the remote LAN IP
Address?
What is the remote LAN Subnet
Mask?
a. Both local and remote endpoints should be defined as either FQDNs or IP addresses. A combination of
an IP address and an FQDN is not supported.
Tip:
To ensure that tunnels stay active, after completing the wizard, manually
edit the VPN policy to enable keep-alive, which periodically sends ping
packets to the host on the peer side of the network to keep the tunnel
alive. For more information, see
Tip:
For DHCP WAN configurations, first set up the tunnel with IP addresses.
After you have validated the connection, you can use the wizard to
create new policies using the FQDN for the WAN addresses.
3.
Click Apply to save your settings. The IPSec VPN policy is now added to the List of VPN
Policies table on the VPN Policies screen. By default, the VPN policy is enabled.
Figure 79.
4.
Configure a VPN policy on the remote gateway that allows connection to the VPN firewall.
5.
Activate the IPSec VPN connection:
a. Select VPN > Connection Status. The VPN Connection Status submenu tabs
display, with the IPSec VPN Connection Status screen in view.
Virtual Private Networking Using IPSec Connections
Description
When you select the Gateway radio button in the About VPN Wizard
section of the screen, the IP address of the VPN firewall's active WAN
interface is automatically entered.
Enter the LAN IP address of the remote gateway.
Note:
The remote LAN IP address needs to be in a different subnet than
the local LAN IP address. For example, if the local subnet is 192.168.1.x,
then the remote subnet could be 192.168.10.x. but could not be
192.168.1.x. If this information is incorrect, the tunnel will fail to connect.
Enter the LAN subnet mask of the remote gateway.
Configure Keep-Alives
140
on page 194.

Hide quick links:

Advertisement

Table of Contents
loading

Table of Contents