Quick Reference Guide

Table Of Contents
Chapter 5: Virtual Private Networking Using IPsec | 70
Virtual Private Networking Using IPsec
5
This chapter describes how to use the IPsec virtual private networking (VPN) features of the
ProSafe Dual WAN Gigabit Firewall with SSL & IPsec VPN FVS336Gv2 to provide secure,
encrypted communications between your local network and a remote network or computer.
This chapter contains the following sections:
Considerations for Dual WAN Port Systems” on this page.
“Using the VPN Wizard for Client and Gateway Configurations” on page 72.
“Testing the Connections and Viewing Status Information” on page 80.
“Managing VPN Policies” on page 83.
“Configuring Extended Authentication (XAUTH)” on page 86.
“Assigning IP Addresses to Remote Users (ModeConfig)” on page 90.
“Configuring Keepalives and Dead Peer Detection” on page 95.
“Configuring NetBIOS Bridging with VPN” on page 97.
Considerations for Dual WAN Port Systems
If both of the WAN ports of the VPN firewall are configured, you can enable either
Auto-Rollover mode for increased system reliability or Load Balancing mode for optimum
bandwidth efficiency. This WAN mode choice impacts how the VPN features must be
configured.
The use of fully qualified domain names in VPN policies is mandatory when the WAN ports
are in load balancing or rollover mode; and is also required for the VPN tunnels to fail over.
FQDN is optional when the WAN ports are in load balancing mode if the IP addresses are
static but mandatory if the WAN IP addresses are dynamic.
Refer to <pdf>“Virtual Private Networks (VPNs)” on page B-181 for more on the IP
addressing requirements for VPN in the dual WAN modes. For instructions on how to select
and configure a dynamic DNS service for resolving FQDNs, see “Configuring Dynamic DNS
(Optional)” on page 26. For instructions on WAN mode configuration, see “Configuring the
WAN Mode (Required for Dual WAN)” on page 22.