Virtual Private Networking Using IPSec
and
L2TP Connections
203
ProSAFE Gigabit Quad WAN SSL VPN Firewall SRX5308
The following table summarizes the WAN addressing requirements (FQDN or IP address) for
a VPN tunnel in either dual WAN mode.
Use the IPSec VPN Wizard for Client and Gateway
Configurations
You can use the IPSec VPN Wizard to configure multiple gateway or client VPN tunnel
policies.
The following sections provide wizard and NETGEAR ProSafe VPN Client software
configuration procedures:
•
Create an IPv4 Gateway-to-Gateway VPN Tunnel with the Wizard
on page
204
•
Create an IPv6 Gateway-to-Gateway VPN Tunnel with the Wizard
on page
208
•
Create an IPv4 Client-to-Gateway VPN Tunnel with the Wizard
on page
212
Note:
Although the VPN firewall supports IPv6, the NETGEAR ProSafe
VPN Client supports IPv4 only; a future release of the VPN Client
might support IPv6.
Configuring a VPN tunnel connection requires that you specify all settings on both sides of
the VPN tunnel to match or mirror each other precisely, which can be a daunting task. The
VPN Wizard efficiently guides you through the setup procedure with a series of questions that
determine the IPSec keys and VPN policies it sets up. The VPN Wizard also configures the
settings for the network connection: security association (SA), traffic selectors, authentication
algorithm, and encryption. The settings that the VPN Wizard uses are based on the
recommendations of the VPN Consortium (VPNC), an organization that promotes
multivendor VPN interoperability.
Table 43.
IP addressing for VPNs in dual WAN port systems
Configuration and WAN IP address
Rollover mode
a
a. After a rollover, all tunnels need to be reestablished using the new WAN IP address.
Load balancing mode
VPN Road Warrior
(client to gateway)
Fixed
FQDN required
FQDN Allowed (optional)
Dynamic
FQDN required
FQDN required
VPN Gateway-to-Gateway
(gateway to gateway)
Fixed
FQDN required
FQDN Allowed (optional)
Dynamic
FQDN required
FQDN required
VPN Telecommuter
(client to gateway through a
NAT router)
Fixed
FQDN required
FQDN Allowed (optional)
Dynamic
FQDN required
FQDN required