NETGEAR FVX538NA Network Card User Manual


 
ProSafe VPN Firewall 200 FVX538 Reference Manual
C-20 Network Planning for Dual WAN Ports
v1.0, August 2006
VPN Telecommuter: Dual Gateway WAN Ports for Load Balancing
In the case of the dual WAN ports on the gateway VPN firewall (Figure C-20), the remote PC
client initiates the VPN tunnel with the appropriate gateway WAN port (i.e., port WAN1 or WAN2
as necessary to balance the loads of the two gateway WAN ports) because the IP address of the
remote NAT router is not known in advance. The chosen gateway WAN port must act as the
responder.
The IP addresses of the gateway WAN ports can be either fixed or dynamic. If an IP address is
dynamic, a fully-qualified domain name must be used. If an IP address is fixed, a fully-qualified
domain name is optional.
Figure C-20
Gateway A
bzrouter2.dyndns.org
10.5.6.0/24
10.5.6.1
WAN1 IP
WAN IP
LAN IP
Client B
0.0.0.0
VPNRouter
(atemployer's
mainoffice)
Telecommuter Example
(Dual WAN Ports, Load Balancing)
NAT Router B
NATRouter
(attelecommuter's
homeoffice)
RemotePC
(runningNETGEAR
ProSafeVPNClient)
Fully-QualifiedDomainNames(FQDN)
-optionalforFixedIPaddresses
-requiredforDynamicIPaddresses
WAN2 IP
bzrouter1.dyndns.org