ProSecure Unified Threat Management (UTM) Appliance Reference Manual

Figure B-6

Virtual Private Networks (VPNs)

When implementing virtual private network (VPN) tunnels, a mechanism must be used for determining the IP addresses of the tunnel end points. The addressing of the firewall’s dual WAN port depends on the configuration being implemented:

Table B-2. IP addressing requirements for VPNs in dual WAN port systems

 

 

Single WAN Port

Dual WAN Port Configurations

Configuration and WAN IP address

Configurations

 

 

Rollover Modea

Load Balancing Mode

 

 

(Reference Cases)

 

 

 

 

 

“VPN Road Warrior (Client-

Fixed

Allowed

FQDN required

Allowed

to-Gateway)

 

(FQDN optional)

 

(FQDN optional)

 

 

 

 

 

 

Dynamic

FQDN required

FQDN required

FQDN required

 

 

 

 

 

“VPN Gateway-to-Gateway

Fixed

Allowed

FQDN required

Allowed

 

 

(FQDN optional)

 

(FQDN optional)

 

 

 

 

 

 

Dynamic

FQDN required

FQDN required

FQDN required

 

 

 

 

 

“VPN Telecommuter (Client-

Fixed

Allowed

FQDN required

Allowed

to-Gateway Through a NAT

 

(FQDN optional)

 

(FQDN optional)

Router)

 

 

 

 

Dynamic

FQDN required

FQDN required

FQDN required

 

 

 

 

 

 

a. All tunnels must be re-established after a rollover using the new WAN IP address.

Network Planning for Dual WAN Ports (Dual-WAN Port Models Only)

B-9

v1.0, January 2010

Page 435
Image 435
NETGEAR UTM5-100NAS manual Virtual Private Networks VPNs, VPN Road Warrior Client, To-Gateway Through a NAT, Router