ProSecure Unified Threat Management UTM10 or UTM25 Reference Manual

The diagrams and table below show how the WAN mode selection relates to VPN configuration.

WAN Auto-Rollover: FQDN Required for VPN

UTM25

 

 

 

 

 

 

 

 

 

Rest of

 

UTM25

 

UTM25

UTM25

 

WAN Port

 

Rollover

 

 

Functions

 

Functions

 

Control

 

 

 

 

 

Figure 7-1

WAN Load Balancing: FQDN Optional for VPN

UTM25

 

 

 

 

 

 

 

 

 

Rest of

 

UTM25

 

Load

 

UTM25

 

WAN Port

 

Balancing

 

 

Functions

 

Functions

 

Control

 

 

 

 

 

 

 

Figure 7-2

WAN 1 Port

 

Internet

WAN 2 Port

 

 

 

Same FQDN required for both WAN ports

WAN 1 Port

 

Internet

WAN 2 Port

 

 

 

FQDN required for dynamic IP addresses FQDN optional for static IP addresses

Table 7-1summarizes the WAN addressing requirements (FQDN or IP address) for a VPN tunnel in either dual WAN mode.

Table 7-1. IP Addressing for VPNs in Dual WAN Port Systems

Configuration and WAN IP address

Rollover Modea

Load Balancing Mode

 

 

 

 

VPN “Road Warrior”

Fixed

FQDN required

FQDN Allowed (optional)

(client-to-gateway)

 

 

 

Dynamic

FQDN required

FQDN required

 

 

 

 

 

VPN “Gateway-to-Gateway”

Fixed

FQDN required

FQDN Allowed (optional)

 

 

 

 

 

Dynamic

FQDN required

FQDN required

 

 

 

 

VPN “Telecommuter”

Fixed

FQDN required

FQDN Allowed (optional)

(client-to-gateway through a

 

 

 

Dynamic

FQDN required

FQDN required

NAT router)

 

 

 

 

 

 

 

a. All tunnels must be re-established after a rollover using the new WAN IP address.

7-2

Virtual Private Networking Using IPsec Connections

v1.0, September 2009

Page 212
Image 212
NETGEAR UTM25EW-100NAS, UTM25-100NAS, UTM10EW-100NAS manual IP Addressing for VPNs in Dual WAN Port Systems