Specifications
5
ProSafe Gigabit Quad WAN SSL VPN Firewall SRX5308
Set Up IP/MAC Bindings . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .128
Configure Port Triggering . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .130
Configure Universal Plug and Play. . . . . . . . . . . . . . . . . . . . . . . . . . . . . .132
Chapter 5 Virtual Private Networking
Using IPSec Connections
Considerations for Multi-WAN Port Systems . . . . . . . . . . . . . . . . . . . . . .134
Use the IPSec VPN Wizard for Client and Gateway Configurations . . . .136
Create Gateway-to-Gateway VPN Tunnels with the Wizard . . . . . . . .136
Create a Client to Gateway VPN Tunnel . . . . . . . . . . . . . . . . . . . . . . .140
Test the Connection and View Connection and Status Information . . . . .155
Test the NETGEAR VPN Client Connection. . . . . . . . . . . . . . . . . . . . .155
NETGEAR VPN Client Status and Log Information . . . . . . . . . . . . . . .156
View the VPN Firewall IPSec VPN Connection Status. . . . . . . . . . . . .157
View the VPN Firewall IPSec VPN Logs . . . . . . . . . . . . . . . . . . . . . . .158
Manage IPSec VPN Policies . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .159
Configure IKE Policies . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .159
Configure VPN Policies . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .165
Configure Extended Authentication (XAUTH) . . . . . . . . . . . . . . . . . . . . .172
Configure XAUTH for VPN Clients . . . . . . . . . . . . . . . . . . . . . . . . . . . .173
User Database Configuration . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .174
RADIUS Client Configuration . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .174
Assign IP Addresses to Remote Users (Mode Config). . . . . . . . . . . . . . .176
Mode Config Operation. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .176
Configure Mode Config Operation on the VPN Firewall . . . . . . . . . . . .177
Configure the NETGEAR VPN Client for Mode Config Operation . . . .183
Test the Mode Config Connection . . . . . . . . . . . . . . . . . . . . . . . . . . . .190
Modify or Delete a Mode Config Record. . . . . . . . . . . . . . . . . . . . . . . .191
Configure Keep-alives and Dead Peer Detection. . . . . . . . . . . . . . . . . . .191
Configure Keep-alives . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .192
Configure Dead Peer Detection . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .193
Configure NetBIOS Bridging with IPSec VPN . . . . . . . . . . . . . . . . . . . . .194
Chapter 6 Virtual Private Networking
Using SSL Connections
SSL VPN Portal Options. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .196
Overview of the SSL Configuration Process . . . . . . . . . . . . . . . . . . . . . .197
Create the Portal Layout. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .198
Configure Domains, Groups, and Users. . . . . . . . . . . . . . . . . . . . . . . . . .202
Configure Applications for Port Forwarding . . . . . . . . . . . . . . . . . . . . . . .202
Add Servers and Port Numbers . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .202
Add a New Host Name . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .204
Configure the SSL VPN Client . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .205
Configure the Client IP Address Range . . . . . . . . . . . . . . . . . . . . . . . .205
Add Routes for VPN Tunnel Clients . . . . . . . . . . . . . . . . . . . . . . . . . . .207
Use Network Resource Objects to Simplify Policies . . . . . . . . . . . . . . . .208
Add New Network Resources . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .208