NETGEAR ProSafe FVS336Gv2 Reference Manual page 184

Prosafe dual wan gigabit firewall with ssl & ipsec vpn
Hide thumbs Also See for ProSafe FVS336Gv2:
Table of Contents

Advertisement

ProSafe Dual WAN Gigabit Firewall with SSL & IPsec VPN FVS336Gv2 Reference Manual
After a rollover of the gateway WAN port, the previously inactive gateway WAN port becomes
the active port (port WAN2 in this example) and the remote PC client must re-establish the
VPN tunnel. The gateway WAN port must act as the responder.
Figure B-11 Road Warrior, Dual WAN Ports, Rollover
The purpose of the fully-qualified domain name in this case is to toggle the domain name of
the gateway firewall between the IP addresses of the active WAN port (i.e., WAN1 and
WAN2) so that the remote PC client can determine the gateway IP address to establish or
re-establish a VPN tunnel.
VPN Road Warrior: Dual Gateway WAN Ports for Load Balancing
In the case of the dual WAN ports on the gateway VPN firewall, the remote PC initiates the
VPN tunnel with the appropriate gateway WAN port (that is, port WAN1 or WAN2 as
necessary to balance the loads of the two gateway WAN ports) because the IP address of the
remote PC is not known in advance. The chosen gateway WAN port must act as the
responder.
Figure B-12 Road Warrior, Dual WAN Ports, Load Balancing
The IP addresses of the gateway WAN ports can be either fixed or dynamic. If an IP address
is dynamic, a fully-qualified domain name must be used. If an IP address is fixed, a
fully-qualified domain name is optional.
184 |
Appendix B: Network Planning for Dual WAN Ports

Advertisement

Table of Contents
loading

Table of Contents