Quick Reference Guide

Table Of Contents
Appendix B: Network Planning for Dual WAN Ports | 183
ProSafe Dual WAN Gigabit Firewall with SSL & IPsec VPN FVS336Gv2 Reference Manual
VPN Road Warrior: Single Gateway WAN Port (Reference Case)
In the case of the single WAN port on the gateway VPN firewall, the remote PC client initiates
the VPN tunnel because the IP address of the remote PC client is not known in advance. The
gateway WAN port must act as the responder.
Figure B-9 Road Warrior, Single WAN Port
The IP address of the gateway WAN port can be either fixed or dynamic. If the IP address is
dynamic, a fully-qualified domain name must be used. If the IP address is fixed, a
fully-qualified domain name is optional.
VPN Road Warrior: Dual Gateway WAN Ports for Improved Reliability
In the case of the dual WAN ports on the gateway VPN firewall, the remote PC client initiates
the VPN tunnel with the active gateway WAN port (port WAN1 in this example) because the
IP address of the remote PC client is not known in advance. The gateway WAN port must act
as a responder.
Figure B-10 Road Warrior, Dual Gateway WAN Ports
The IP addresses of the gateway WAN ports can be either fixed or dynamic, but a
fully-qualified domain name must always be used because the active WAN port could be
either WAN1 or WAN2 (i.e., the IP address of the active WAN port is not known in advance).