Chapter 5:
Virtual Private Networking Using IPsec
|
71
ProSafe Dual WAN Gigabit Firewall with SSL & IPsec VPN FVS336Gv2 Reference Manual
The following diagrams and table show how the WAN mode selection relates to VPN
configuration.
Figure 5-4
The following table summarizes the WAN addressing requirements (FQDN or IP address) for
your VPN tunnel in either dual WAN mode.
Table 5-5.
IP Addressing for VPNs in Dual WAN Port Systems
Configuration and WAN IP address
Rollover Mode
1
1 All tunnels must be re-established after a rollover using the new WAN IP address.
Load Balancing Mode
VPN Road Warrior
(client-to-gateway)
Fixed
FQDN required
FQDN Allowed (optional)
Dynamic
FQDN required
FQDN required
VPN
Gateway-to-Gateway
Fixed
FQDN required
FQDN Allowed (optional)
Dynamic
FQDN required
FQDN required
VPN Telecommuter
(client-to-gateway
through a NAT router)
Fixed
FQDN required
FQDN Allowed (optional)
Dynamic
FQDN required
FQDN required
Rest of
Firewall
Functions
Firewall
WAN Port
Functions
Firewall
Rollover
Control
Firewall
WAN 1 Port
WAN 2 Port
Internet
Same FQDN required for both WAN ports
WAN Auto-Rollover: FQDN Required for VPN
Rest of
Firewall
Functions
Firewall
WAN Port
Functions
Load
Balancing
Control
Firewall
WAN 1 Port
WAN 2 Port
Internet
FQDN required for dynamic IP addresses
WAN Load Balancing: FQDN Optional for VPN
FQDN optional for static IP addresses