Reference Manual for the ProSafe VPN Firewall 25 with 4 Gigabit LAN and Dual WAN Ports
3-2 Network Planning
202-10085-01, March 2005

The Rollover Case for Firewalls With Dual WAN Ports

Rollover (Figure 3-1) for the dual WAN port case is different from the single gateway WAN port
case when specifying the IP address. Only one WAN port is active at a time and when it rolls over,
the IP address of the active WAN port always changes. Hence, the use of a fully-qualified domain
name is always required, even when the IP address of each WAN port is fixed.
Figure 3-1: Dual WAN ports before and af ter rollover
Features such as multiple exposed hosts are not supported when using dual WAN port rollover
because the IP addresses of each WAN port must be in the identical range of fixed addresses.

The Load Balancing Case for Firewalls With Dual WAN Ports

Load balancing (Figure 3-2) for the dual WAN port case is similar to the single WAN port case
when specifying the IP address. Each IP address is either fixed or dynamic based on the ISP:
fully-qualified domain names must be used when the IP address is dynamic and are optional when
the IP address is static.
Figure 3-2: Dual WAN ports for load balancing
Note: Once the gateway firewall WAN port rolls over, the VPN tunnel collapses and
must be re-established using the new WAN IP address.
Router
WAN1 port active
WAN1 IP
Dual WAN Ports (Before Rollover)
WAN2 IP (N/A)
WAN2 port inactive
Router
WAN1 port inactive
WAN1 IP (N/A)
Dual WAN Ports (After Rollover)
WAN2 IP
WAN2 port active
IP address of active WAN port changes after a rollover:
o use of fully-qualified domain names always required
o features requiring fixed IP address blocks not supported
XX
XX
Router
netgear1.dyndns.org
WAN1 IP
Dual WAN Ports (Load Balancing)
WAN2 IP
netgear2.dyndns.org
Use of fully-qualified domain names for IP addresses of WAN ports:
o required for dynamic IP addresses
o optional for fixed IP addresses