Network Planning Guide for ProSafe VPN Firewall Router FVX538
Network Planning 2-15
October 2004
After a failover of the gateway WAN port (Figure 2-20), the previously inactive gateway WAN
port becomes the active port (port WAN2 in this example) and the remote PC must re-establish the
VPN tunnel. The gateway WAN port must act as the responder.
Figure 2-20: Dual gateway WAN ports, after failover, for VPN telecommuter
The purpose of the fully-qualified domain name is this case is to toggle the domain name of the
gateway router between the IP addresses of the active WAN port (i.e., WAN1 and WAN2) so that
the remote PC client can determine the gateway IP address to establish or re-establish a VPN
tunnel.
VPN Telecommuter: Dual Gateway WAN Ports for Load Balancing
In the case of the dual WAN ports on the gateway VPN router (Figure 2-21), the remote PC client
initiates the VPN tunnel with the appropriate gateway WAN port (i.e., port WAN1 or WAN2 as
necessary to balance the loads of the two gateway WAN ports) because the IP address of the
remote NAT router is not known in advance. The chosen gateway WAN port must act as the
responder.
Figure 2-21: Dual gateway WAN ports (load balancing case) for VPN telecommuter
Gateway A
bzrouter2.dyndns.org
10.5.6.0/24
10.5.6.1
WAN1 IP (N/A)
WAN IP
LAN IP
Client B
0.0.0.0
VPNRouter
(atemployer's
mainoffice)
Telecommuter Example
(Dual WAN Ports, After Failover)
NAT Router B
NAT Router
(attelecommuter's
homeoffice)
RemotePC
(runningNETGEAR
ProSafeVPNClient)
Fully-QualifiedDomainNames (FQDN)
-required forFixedIP addresses
-required forDynamicIP addresses
WAN2 IP
WAN1 port inactive
RemotePC mustre-establishVPNtunnel aftera failover
XX
Gateway A
bzrouter2.dyndns.org
10.5.6.0/24
10.5.6.1
WAN1 IP
WAN IP
LAN IP
Client B
0.0.0.0
VPNRouter
(atemployer's
mainoffice)
Telecommuter Example
(Dual WAN Ports, Load Balancing)
NAT Router B
NAT Router
(attelecommuter's
homeoffice)
RemotePC
(runningNETGEAR
ProSafeVPNClient)
Fully-QualifiedDomainNames (FQDN)
-optional forFixedIP addresses
-required forDynamicIP addresses
WAN2 IP
bzrouter1.dyndns.org