Quick Reference Guide

ProSafe VPN Firewall 200 FVX538 Reference Manual
Network Planning for Dual WAN Ports B-11
v1.0, January 2010
Load balancing for the dual gateway WAN port case is the same as the single gateway WAN
port case when specifying the IP address of the VPN tunnel end point. Each IP address is
either fixed or dynamic based on the ISP: fully-qualified domain names must be used when the
IP address is dynamic and are optional when the IP address is static.
VPN Road Warrior (Client-to-Gateway)
The following situations exemplify the requirements for a remote PC client with no firewall to
establish a VPN tunnel with a gateway VPN firewall:
Single gateway WAN port
Redundant dual gateway WAN ports for increased reliability (before and after rollover)
Dual gateway WAN ports used for load balancing
VPN Road Warrior: Single Gateway WAN Port (Reference Case)
In the case of the single WAN port on the gateway VPN firewall, the remote PC client initiates the
VPN tunnel because the IP address of the remote PC client is not known in advance. The gateway
WAN port must act as the responder.
Figure B-8
Figure B-9