Page 186 / 240 Scroll up to view Page 181 - 185
ProSafe VPN Firewall 200 FVX538 Reference Manual
A-4
Default Settings and Technical Specifications
v1.0, March 2009
Page 187 / 240
Network Planning for Dual WAN Ports
B-1
v1.0, March 2009
Appendix B
Network Planning for Dual WAN Ports
This appendix describes the factors to consider when planning a network using a firewall that has
dual WAN ports.
What You Will Need to Do Before You Begin
The ProSafe VPN Firewall 200 is a powerful and versatile solution for your networking needs. But
to make the configuration process easier and to understand all of the choices available to you, you
need to think through the following items before you begin:
1.
Plan your network
a.
Determine whether you are going to use one or both WAN ports. For one WAN port, you
may need a fully qualified domain name either for convenience or if you have a dynamic
IP address.
b.
If you are going to use both WAN ports, determine whether you are going to use them in
rollover mode for increased system reliability or load balancing mode for maximum
bandwidth efficiency. See the topics in this appendix for more information. Your decision
has the following implications:
Fully qualified domain name
For rollover mode, you are going to need a fully qualified domain name to implement
features such as exposed hosts and virtual private networks.
For load balancing mode, you may still need a fully qualified domain name either for
convenience or if you have a dynamic IP address.
Protocol binding
For rollover mode, protocol binding does not apply.
For load balancing mode, you need to decide which protocols you want to bind to a
specific WAN port if you are going to take advantage of this option.
You can also add your own service protocols to the list.
3.
Set up your accounts
Page 188 / 240
ProSafe VPN Firewall 200 FVX538 Reference Manual
B-2
Network Planning for Dual WAN Ports
v1.0, March 2009
a.
Have active Internet services such as that provided by cable or DSL broadband accounts
and locate the Internet Service Provider (ISP) configuration information.
In this document, the WAN side of the network is presumed to be provisioned as
shown in
Figure B-1
with two ISPs connected to the VPN firewall through separate
physical facilities.
Each FVX538 WAN port must be configured separately, however, whether you are
using a separate ISP for each WAN port or are having the traffic of both WAN ports
routed through the same ISP.
If your ISPs charge by the amount of bandwidth you use each month, you may want to
consider setting up a traffic meter to keep track of your traffic.
b.
Contact a Dynamic DNS Service and set up your fully qualified domain names if you need
or want them.
3.
Plan your network management approach
The VPN firewall is capable of being managed remotely, but this feature must be enabled
locally after each factory default reset.
You are strongly advised to change the default
password
password to something that is
more secure at the time you enable remote management.
There are a variety of WAN options you can choose when the factory default settings are
not applicable to your installation. These include enabling a WAN port to respond to a
ping and setting MTU size, port speed, and upload bandwidth.
4.
Prepare to physically connect the firewall to cable or DSL modems and a computer.
Instruction for connecting your VPN firewall are in
Installation Guide, FVX538 ProSafe VPN
Firewall 200
.
Figure B-1
FVX538
ISP 1
ISP 2
Internet
WAN port 1
WAN port 2
customer premises
physical facility 1
physical facility 2
route diversity
firewall
Page 189 / 240
ProSafe VPN Firewall 200 FVX538 Reference Manual
Network Planning for Dual WAN Ports
B-3
v1.0, March 2009
Cabling and Computer Hardware Requirements
To use the VPN firewall on your network, each computer must have an installed Ethernet Network
Interface Card (NIC) and an Ethernet cable. If the computer will connect to your network at 100
Mbps, you must use a Category 5 (CAT5) cable such as the one provided with your firewall.
Computer Network Configuration Requirements
The FVX538 includes a built-in Web Configuration Manager. To access the configuration menus
on the FVX538, your must use a Java-enabled Web browser program that supports HTTP uploads
such as Microsoft Internet Explorer or Netscape Navigator. NETGEAR recommends using
Internet Explorer or Netscape Navigator 4.0 or above. Free browser programs are readily available
for Windows, Macintosh, or UNIX/Linux.
For the initial connection to the Internet and configuration of your firewall, you will need to
connect a computer to the firewall that is set to automatically get its TCP/IP configuration from the
firewall via DHCP.
The cable or DSL modem broadband access device must provide a standard 10 Mbps (10BASE-T)
Ethernet interface.
Internet Configuration Requirements
Depending on how your ISPs set up your Internet accounts, you will need one or more of these
configuration parameters to connect your firewall to the Internet:
Host and Domain Names
ISP Login Name and Password
ISP Domain Name Server (DNS) Addresses
Fixed IP Address which is also known as Static IP Address
Where Do I Get the Internet Configuration Parameters?
There are several ways you can gather the required Internet connection information.
Your ISPs provide all the information needed to connect to the Internet. If you cannot locate
this information, you can ask your ISPs to provide it or you can try one of the options below.
Note:
For help with DHCP configuration, please refer to the link in
Appendix D,
“Related Documents
.”
Page 190 / 240
ProSafe VPN Firewall 200 FVX538 Reference Manual
B-4
Network Planning for Dual WAN Ports
v1.0, March 2009
If you have a computer already connected using the active Internet access account, you can
gather the configuration information from that computer.
For Windows 95/98/ME, open the Network control panel, select the TCP/IP entry for the
Ethernet adapter, and click Properties. Record all the settings for each tab page.
For Windows 2000/XP, open the Local Area Network Connection, select the TCP/IP entry
for the Ethernet adapter, and click Properties. Record all the settings for each tab page.
For Macintosh computers, open the TCP/IP or Network control panel. Record all the
settings for each section.
You may also refer to the
FVX538
Resource CD
for the NETGEAR Router ISP Guide which
provides Internet connection information for many ISPs.
Once you locate your Internet configuration parameters, you may want to record them on the page
below.

Rate

4 / 5 based on 1 vote.

Bookmark Our Site

Press Ctrl + D to add this site to your favorites!

Share
Top