Quick Reference Guide

Table Of Contents
94 | Chapter 5: Virtual Private Networking Using IPsec
ProSafe Dual WAN Gigabit Firewall with SSL & IPsec VPN FVS336Gv2 Reference Manual
Note: If RADIUS-PAP is selected, the VPN firewall first checks the User
Database to see if the user credentials are available. If the user
account is not present, the VPN firewalll then connects to the
RADIUS server.
12. Click Apply. The new policy will appear in the List of IKE Policies table.
Configuring the ProSafe VPN Client for ModeConfig
From a client PC running NETGEAR ProSafe VPN Client software, configure the remote
VPN client connection.
To configure the client PC:
1. Right-click the VPN client icon in the Windows toolbar. In the upper left of the Policy
Editor window, click the New Policy editor icon.
a. Give the connection a descriptive name such as “modecfg_test”. (This name will only
be used internally).
b. In the ID Type field, choose IP Subnet.
c. Enter the IP Subnet and Mask of the VPN firewall (this is the LAN network IP
address of the gateway).
d. Check the Connect using radio button and choose Secure Gateway Tunnel from
the drop-down list.
e. From the ID Type drop-down list, choose Domain Name and enter the FQDN of the
VPN firewall; in this example it is “local_id.com”.
f. Choose Gateway IP Address from the second drop-down list and enter the WAN IP
address of the VPN firewall; in this example it is “172.21.4.1”.
2. From the left side of the menu, click My Identity and enter the following information:
a. Click Pre-Shared Key and enter the key you configured in the VPN firewall’s Add IKE
Policy screen.
b. From the Select Certificate drop-down list, choose None.
c. In the ID Type feild, choose Domain Name and create an identifier based on the
name of the IKE policy you created; for example “salesperson11.remote_id.com”.
d. Under Virtual Adapter drop-down list, choose Preferred. The Internal Network IP
Address should be 0.0.0.0.
Note: If no box is displayed for Internal Network IP Address, go to
Options/Global Policy Settings, and check the box for “Allow to
Specify Internal Network Address.”