Virtual Private Networking Using IPSec and L2TP Connections
238
ProSafe Wireless-N 8-Port Gigabit VPN Firewall FVS318N
You can use the Mode Config feature in combination with an IPv6 IKE policy to assign IPv4
addresses to clients, but you cannot assign IPv6 addresses to clients.
Mode Config Operation
After the IKE Phase 1 negotiation is complete, the VPN connection initiator (which is the
remote user with a VPN client) requests the IP configuration settings such as the IP address,
subnet mask, WINS server, and DNS address from the wireless VPN firewall. The Mode
Config feature allocates an IP address from the configured IP address pool and activates a
temporary IPSec policy, using the information that is specified in the Traffic Tunnel Security
Level section of the Mode Config record (on the Add Mode Config Record screen that is
shown in Figure 144 on page 239).
Note: After configuring a Mode Config record, you need to manually
configure an IKE policy and select the newly created Mode Config
record from the Select Mode Config Record drop-down list (see
Configure Mode Config Operation on the Wireless VPN Firewall on
page 238). You do not need to make changes to any VPN policy.
Note: An IP address that is allocated to a VPN client is released only after
the VPN client has gracefully disconnected or after the SA liftetime
for the connection has timed out.
Configure Mode Config Operation on the Wireless VPN Firewall
To configure Mode Config on the wireless VPN firewall, first create a Mode Config record,
and then select the Mode Config record for an IKE policy.
To configure Mode Config on the wireless VPN firewall:
1. Select VPN > IPSec VPN > Mode Config. The Mode Config screen displays:
Figure 143.