Vpn Road Warrior: Dual Gateway Wan Ports For Load Balancing - NETGEAR ProSafe FVS124G Reference Manual

Prosafe vpn firewall 25 with 4 gigabit lan and dual wan ports
Hide thumbs Also See for ProSafe FVS124G:
Table of Contents

Advertisement

Reference Manual for the ProSafe VPN Firewall 25 with 4 Gigabit LAN and Dual WAN Ports
After a rollover of the gateway WAN port
port becomes the active port (port WAN2 in this example) and the remote PC client must
re-establish the VPN tunnel. The gateway WAN port must act as the responder.
Road Warrior Example
10.5.6.0/24
(Dual WAN Ports, After Rollover)
LAN IP
10.5.6.1
VPN Router
(at employer's
main office)
Figure 3-10: Dual gateway WAN ports, after rollover, for VPN road warrior
The purpose of the fully-qualified domain name in this case is to toggle the domain name of the
gateway firewall between the IP addresses of the active WAN port (i.e., WAN1 and WAN2) so that
the remote PC client can determine the gateway IP address to establish or re-establish a VPN
tunnel.

VPN Road Warrior: Dual Gateway WAN Ports for Load Balancing

In the case of the dual WAN ports on the gateway VPN firewall
initiates the VPN tunnel with the appropriate gateway WAN port (i.e., port WAN1 or WAN2 as
necessary to balance the loads of the two gateway WAN ports) because the IP address of the
remote PC is not known in advance. The chosen gateway WAN port must act as the responder.
Road Warrior Example
10.5.6.0/24
(Dual WAN Ports, Load Balancing)
LAN IP
10.5.6.1
VPN Router
(at employer's
main office)
Figure 3-11: Dual gateway WAN ports (load balancing case) for VPN road warrior
3-8
(Figure
WAN1 IP (N/A)
Gateway A
WAN1 port inactive
X
bzrouter.dyndns.org
WAN2 IP
Fully-Qualified Domain Names (FQDN)
- required for Fixed IP addresses
- required for Dynamic IP addresses
Remote PC must re-establish VPN tunnel after a rollover
WAN1 IP
Gateway A
bzrouter1.dyndns.org
bzrouter2.dyndns.org
WAN2 IP
Fully-Qualified Domain Names (FQDN)
- optional for Fixed IP addresses
- required for Dynamic IP addresses
202-10085-01, March 2005
3-10), the previously inactive gateway WAN
WAN IP
X
0.0.0.0
(Figure
WAN IP
0.0.0.0
Client B
Remote PC
(running NETGEAR
ProSafe VPN Client)
3-11), the remote PC
Client B
Remote PC
(running NETGEAR
ProSafe VPN Client)
Network Planning

Advertisement

Table of Contents
loading

This manual is also suitable for:

Fvs124gna

Table of Contents