ProSafe Wireless-N 8-Port Gigabit VPN Firewall FVS318N

Assign IPv4 Addresses to Remote Users (Mode Config)

Mode Config Operation

Configure Mode Config Operation on the Wireless VPN Firewall

Configure the ProSafe VPN Client for Mode Config Operation

Test the Mode Config Connection

Modify or Delete a Mode Config Record

To simplify the process of connecting remote VPN clients to the wireless VPN firewall, use the Mode Config feature to automatically assign IPv4 addresses to remote users, including a network access IP address, subnet mask, WINS server, and DNS address. Remote users are given IP addresses available in a secured network space so that remote users appear as seamless extensions of the network.

You can use the Mode Config feature in combination with an IPv6 IKE policy to assign IPv4 addresses to clients, but you cannot assign IPv6 addresses to clients.

Mode Config Operation

After the IKE Phase 1 negotiation is complete, the VPN connection initiator (which is the remote user with a VPN client) requests the IP configuration settings such as the IP address, subnet mask, WINS server, and DNS address from the wireless VPN firewall. The Mode Config feature allocates an IP address from the configured IP address pool and activates a temporary IPSec policy, using the information that is specified in the Traffic Tunnel Security Level section of the Mode Config record (on the Add Mode Config Record screen that is shown in Figure 146 on page 245).

Note: After configuring a Mode Config record, you need to manually configure an IKE policy and select the newly created Mode Config record from the Select Mode Config Record drop-down list (see

Configure Mode Config Operation on the Wireless VPN Firewall on

page 244). You do not need to change any VPN policy.

Note: An IP address that is allocated to a VPN client is released only after the VPN client has gracefully disconnected or after the SA liftetime for the connection has timed out.

Virtual Private Networking Using IPSec and L2TP Connections

243

Page 243
Image 243
NETGEAR FVS318N manual Assign IPv4 Addresses to Remote Users Mode Config, Mode Config Operation, 243