Quick Reference Guide

Table Of Contents
Chapter 2: Connecting the VPN Firewall to the Internet | 23
ProSafe Dual WAN Gigabit Firewall with SSL & IPsec VPN FVS336Gv2 Reference Manual
If you only have a single public Internet IP address, you MUST use NAT. (the default
setting).
If your ISP has provided you with multiple public IP addresses, you can use one address
as the primary shared address for Internet access by your PCs, and you can map
incoming traffic on the other public IP addresses to specific PCs on your LAN. This
one-to-one inbound mapping is configured using an inbound firewall rule.
Classical Routing
In classical routing mode, the VPN firewall performs routing, but without NAT. To gain Internet
access, each PC on your LAN must have a valid static Internet IP address.
If your ISP has allocated a number of static IP addresses to you, and you have assigned one
of these addresses to each PC, you can choose classical routing. Or, you can use classical
routing for routing private IP addresses within a campus environment. To learn the status of
the WAN ports, you can view the Router Status screen (see <pdf>“Viewing VPN Firewall
Configuration and System Status” on page 9-154) or look at the LEDs on the front panel (see
“Rear Panel Features” on page 12).
Configuring Auto-Rollover Mode
To use a redundant ISP link for backup purposes, ensure that the backup WAN port has
already been configured. Then select the WAN port that will act as the primary link for this
mode and configure the WAN Failure Detection Method to support Auto-Rollover.
When the VPN firewall is configured in Auto-Rollover mode, it uses the selected WAN Failure
Detection Method to check the connection of the primary link at regular intervals to detect its
routing status. Link failure is detected in one of the following ways:
By sending DNS queries to a DNS server, or
By sending a Ping request to an IP address, or
None (no failure detection is performed).
From each WAN interface, DNS queries or Ping requests are sent to the specified IP
address. If replies are not received, after a specified number of retries, the corresponding
WAN interface is considered down.