ProSecure Unified Threat Management (UTM) Appliance

balancing mode if the IP addresses are static, but mandatory if the WAN IP addresses are dynamic. See Virtual Private Networks on page 629 for more information about the IP addressing requirements for VPNs in the dual WAN modes.

For information about how to select and configure a Dynamic DNS service for resolving FQDNs, see Configure Dynamic DNS on page 91. For information about WAN mode configuration, see Configure the WAN Mode on page 80.

The following diagrams and table show how the WAN mode selection relates to VPN configuration.

WAN auto-rollover: FQDN required for VPN

Multiple WAN Port Model

Rest of

 

UTM

 

UTM

UTM

 

WAN port

 

rollover

 

 

functions

 

functions

 

control

 

 

 

 

 

Figure 149.

WAN load balancing: FQDN optional for VPN

Multiple WAN Port Model

Rest of

 

UTM

 

Load

 

UTM

 

WAN port

 

balancing

 

 

functions

 

functions

 

control

 

 

 

 

 

 

 

Figure 150.

WAN 1 port

 

Internet

WAN 2 port

 

 

 

Same FQDN required for both WAN ports

WAN 1 port

 

Internet

WAN 2 port

 

 

 

FQDN required for dynamic IP addresses FQDN optional for static IP addresses

The following table summarizes the WAN addressing requirements (FQDN or IP address) for a VPN tunnel in either dual WAN mode.

Table 60. IP addressing for VPNs in dual WAN port systems

Configuration and WAN IP address

Rollover modea

Load balancing mode

 

 

 

 

VPN Road Warrior

Fixed

FQDN required

FQDN Allowed (optional)

(client to gateway)

 

 

 

Dynamic

FQDN required

FQDN required

 

 

 

 

 

VPN Gateway-to-Gateway

Fixed

FQDN required

FQDN Allowed (optional)

(gateway to gateway)

 

 

 

Dynamic

FQDN required

FQDN required

 

 

 

 

 

VPN Telecommuter

Fixed

FQDN required

FQDN Allowed (optional)

(client to gateway through a

 

 

 

Dynamic

FQDN required

FQDN required

NAT router)

 

 

 

 

a. After a rollover, all tunnels need to be reestablished using the new WAN IP address.

Virtual Private Networking Using IPSec, PPTP, or L2TP Connections

265

Page 265
Image 265
NETGEAR STM150EW-100NAS, UTM5EW-100NAS manual IP addressing for VPNs in dual WAN port systems, 265