ProSafe VPN Firewall 200 FVX538 Reference Manual
Virtual Private Networks (VPNs)
When implementing virtual private network (VPN) tunnels, a mechanism must be used for determining the IP addresses of the tunnel end points. The addressing of the firewall’s dual WAN port depends on the configuration being implemented:
Table
Configuration and WAN IP address | Single WAN Port | Dual WAN Port Cases | |||
|
| ||||
(reference case) | Rollovera | Load Balancing | |||
|
| ||||
|
|
|
|
| |
VPN Road Warrior | Fixed | Allowed | FQDN required | Allowed | |
| (FQDN optional) |
| (FQDN optional) | ||
|
|
|
|
| |
| Dynamic | FQDN required | FQDN required | FQDN required | |
|
|
|
|
| |
VPN | Fixed | Allowed | FQDN required | Allowed | |
|
| (FQDN optional) |
| (FQDN optional) | |
|
|
|
|
| |
| Dynamic | FQDN required | FQDN required | FQDN required | |
|
|
|
|
| |
VPN Telecommuter | Fixed | Allowed | FQDN required | Allowed | |
| (FQDN optional) |
| (FQDN optional) | ||
a NAT router) |
|
|
|
| |
Dynamic | FQDN required | FQDN required | FQDN required | ||
| |||||
|
|
|
|
|
a. All tunnels must be
For the single gateway WAN port case, the mechanism is to use a
•Rollover Case for Dual Gateway WAN Ports
Rollover (Figure
Note: Once the gateway router WAN port rolls over, the VPN tunnel collapses and must be
Network Planning for Dual WAN Ports |
v1.0, August 2006