Virtual Private Networking Using IPSec and L2TP Connections
197
ProSafe Gigabit Quad WAN SSL VPN Firewall SRX5308
The following diagrams and table show how the WAN mode selection relates to VPN configuration.
Figure 119.
Figure 120.
The following table summarizes the WAN addressing requirements (FQDN or IP address) for a VPN tunnel in either dual WAN mode.
Table 42. IP addressing for VPNs in dual WAN port systems
Configuration and WAN IP address Rollover modea
a. After a rollover, all tunnels need to be reestablished using the new WAN IP address.
Load balancing mode
VPN Road Warrior
(client to gateway) Fixed FQDN required FQDN Allowed (optional)
Dynamic FQDN required FQDN required
VPN Gateway-to-Gateway
(gateway to gateway) Fixed FQDN required FQDN Allowed (optional)
Dynamic FQDN required FQDN required
VPN Telecommuter
(client to gateway through a
NAT router)
Fixed FQDN required FQDN Allowed (optional)
Dynamic FQDN required FQDN required
Rest of
VPN firewall
functions
VPN firewall
WAN port
functions
VPN firewall
rollover
control
Multiple WAN Port Model
WAN 1 port
WAN 2 port Internet
Same FQDN required for both WAN ports
WAN auto-rollover: FQDN required for VPN
Rest of
VPN firewall
functions
VPN firewall
WAN port
functions
Load
balancing
control
Multiple WAN Port Model
WAN 1 port
WAN 2 port Internet
FQDN required for dynamic IP addresses
WAN load balancing: FQDN optional for VPN
FQDN optional for static IP addresses