NETGEAR FVX538 Network Card User Manual


 
Network Planning Guide for ProSafe VPN Firewall Router FVX538
2-14 Network Planning
October 2004
Figure 2-18: Single gateway WAN port case for VPN telecommuter
The IP address of the gateway WAN port can be either fixed or dynamic. If the IP address is
dynamic, a fully-qualified domain name must be used. If the IP address is fixed, a fully-qualified
domain name is optional.
VPN Telecommuter: Dual Gateway WAN Ports for Improved System Reliability
In the case of the dual WAN ports on the gateway VPN router (Figure 2-19), the remote PC client
initiates the VPN tunnel with the active gateway WAN port (port WAN1 in this example) because
the IP address of the remote NAT router is not known in advance. The gateway WAN port must act
as the responder.
Figure 2-19: Dual gateway WAN ports, before failover, for VPN telecommuter
The IP addresses of the gateway WAN ports can be either fixed or dynamic, but a fully-qualified
domain name must always be used because the active WAN port could be either WAN1 or WAN2
(i.e., the IP address of the active WAN port is not known in advance).
Gateway A
bzrouter.dyndns.org
10.5.6.0/24
10.5.6.1
WAN IP
WAN IP
LAN IP
Client B
FQDN 0.0.0.0
VPNRouter
(atemployer's
mainoffice)
Telecommuter Example (Single WAN Port)
NAT Router B
NAT Router
(attelecommuter's
homeoffice)
RemotePC
(runningNETGEAR
ProSafeVPNClient)
Fully-QualifiedDomainNames (FQDN)
-optional forFixedIP addresses
-required forDynamicIP addresses
Gateway A
WAN2 port inactive
10.5.6.0/24
10.5.6.1
WAN1 IP
WAN IP
LAN IP
Client B
0.0.0.0
VPNRouter
(atemployer's
mainoffice)
Telecommuter Example
(Dual WAN Ports, Before Failover)
NAT Router B
NAT Router
(attelecommuter's
homeoffice)
RemotePC
(runningNETGEAR
ProSafeVPNClient)
Fully-QualifiedDomainNames (FQDN)
-required forFixedIP addresses
-required forDynamicIP addresses
WAN2 IP (N/A)
bzrouter1.dyndns.org
X
X