ProSecure Unified Threat Management UTM10 or UTM25 Reference Manual

Figure B-6

Virtual Private Networks (VPNs)

When implementing virtual private network (VPN) tunnels, a mechanism must be used for determining the IP addresses of the tunnel end points. The addressing of the firewall’s dual WAN port depends on the configuration being implemented:

Table B-2. IP addressing requirements for VPNs in dual WAN port systems

 

 

Single WAN Port

Dual WAN Port Configurations

Configuration and WAN IP address

Configurations

 

 

Rollover Modea

Load Balancing Mode

 

 

(Reference Cases)

 

 

 

 

 

“VPN Road Warrior (Client-

Fixed

Allowed

FQDN required

Allowed

to-Gateway)

 

(FQDN optional)

 

(FQDN optional)

 

 

 

 

 

 

Dynamic

FQDN required

FQDN required

FQDN required

 

 

 

 

 

“VPN Gateway-to-Gateway

Fixed

Allowed

FQDN required

Allowed

 

 

(FQDN optional)

 

(FQDN optional)

 

 

 

 

 

 

Dynamic

FQDN required

FQDN required

FQDN required

 

 

 

 

 

“VPN Telecommuter (Client-

Fixed

Allowed

FQDN required

Allowed

to-Gateway Through a NAT

 

(FQDN optional)

 

(FQDN optional)

Router)

 

 

 

 

Dynamic

FQDN required

FQDN required

FQDN required

 

 

 

 

 

 

a. All tunnels must be re-established after a rollover using the new WAN IP address.

Network Planning for Dual WAN Ports (UTM25 Only)

B-9

v1.0, September 2009

Page 431
Image 431
NETGEAR UTM25EW-100NAS manual Virtual Private Networks VPNs, VPN Road Warrior Client, To-Gateway Through a NAT, Router