NETGEAR FVX538v1 - ProSafe VPN Firewall Dual WAN Planning Manual page 25

Prosafe vpn firewall router
Hide thumbs Also See for FVX538v1 - ProSafe VPN Firewall Dual WAN:
Table of Contents

Advertisement

After a failover of the gateway WAN port
port becomes the active port (port WAN2 in this example) and the remote PC must re-establish the
VPN tunnel. The gateway WAN port must act as the responder.
Telecommuter Example
10.5.6.0/24
(Dual WAN Ports, After Failover)
Gateway A
LAN IP
10.5.6.1
VPN Router
(at employer's
main office)
Figure 2-20: Dual gateway WAN ports, after failover, for VPN telecommuter
The purpose of the fully-qualified domain name is this case is to toggle the domain name of the
gateway router between the IP addresses of the active WAN port (i.e., WAN1 and WAN2) so that
the remote PC client can determine the gateway IP address to establish or re-establish a VPN
tunnel.
VPN Telecommuter: Dual Gateway WAN Ports for Load Balancing
In the case of the dual WAN ports on the gateway VPN router
initiates the VPN tunnel with the appropriate gateway WAN port (i.e., port WAN1 or WAN2 as
necessary to balance the loads of the two gateway WAN ports) because the IP address of the
remote NAT router is not known in advance. The chosen gateway WAN port must act as the
responder.
Telecommuter Example
10.5.6.0/24
(Dual WAN Ports, Load Balancing)
Gateway A
LAN IP
10.5.6.1
VPN Router
(at employer's
main office)
Figure 2-21: Dual gateway WAN ports (load balancing case) for VPN telecommuter
Network Planning
Network Planning Guide for ProSafe VPN Firewall Router FVX538
(Figure
2-20), the previously inactive gateway WAN
WAN1 IP (N/A)
WAN1 port inactive
X
X
bzrouter2.dyndns.org
WAN2 IP
Fully-Qualified Domain Names (FQDN)
- required for Fixed IP addresses
- required for Dynamic IP addresses
Remote PC must re-establish VPN tunnel after a failover
WAN1 IP
bzrouter1.dyndns.org
bzrouter2.dyndns.org
WAN2 IP
Fully-Qualified Domain Names (FQDN)
- optional for Fixed IP addresses
- required for Dynamic IP addresses
October 2004
NAT Router B
WAN IP
0.0.0.0
NAT Router
(at telecommuter's
home office)
(Figure
2-21), the remote PC client
NAT Router B
WAN IP
0.0.0.0
NAT Router
(at telecommuter's
home office)
Client B
Remote PC
(running NETGEAR
ProSafe VPN Client)
Client B
Remote PC
(running NETGEAR
ProSafe VPN Client)
2-15

Advertisement

Table of Contents
loading

This manual is also suitable for:

Fvx538v2 - prosafe vpn firewall dual wanProsafe fvx538

Table of Contents