User guide

Branch Office Virtual Private Networks
256 Firebox X Edge e-Series
Related questions
Why do I need a static external address?
To make a VPN connection, each device must know the IP address of the other device. If the address for a
device is dynamic, the IP address can change. If the IP address changes, connections between the devices
cannot be made unless the two devices know how to find each other.
You can use Dynamic DNS if you cannot get a static external IP address. For more information, see About the
Dynamic DNS service.
How do I get a static external IP address?
You get the external IP address for your computer or network from your ISP or a network administrator. Many
ISPs use dynamic IP addresses to make their networks easier to configure and use with many users. Most ISPs
can give you a static IP address as an option.
How do I troubleshoot the connection?
If you can send a ping to the trusted interface of the remote Firebox X Edge and the computers on the remote
network, the VPN tunnel is up. The configuration of the network software or the software applications are
possible causes of other problems.
Why is ping not working?
If you cannot send a ping to the local interface IP address of the remote Firebox X Edge, use these steps:
1. Ping the external address of the remote Firebox X Edge.
For example, at Site A, ping the IP address of Site B. If the ping packet does not come back, make sure
the external network settings of Site B are correct. (Site B must be configured to respond to ping
requests on that interface.) If the settings are correct, make sure that the computers at Site B have
Internet access. If the computers at site B do not have Internet access, speak to your ISP or network
administrator.
2. If you can ping the external address of each Firebox X Edge, try to ping a local address in the remote
network.
From a computer at Site A, ping the internal interface IP address of the remote Firebox X Edge. If the
VPN tunnel is up, the remote Edge sends the ping back. If the ping does not come back, make sure the
local configuration is correct. Make sure that the local DHCP address ranges for the two networks
connected by the VPN tunnel do not use any of the same IP addresses. The two networks connected
by the tunnel must not use the same IP addresses.
How do I set up more than the number of allowed VPN tunnels on my Edge?
The number of VPN tunnels that you can create on your Firebox X Edge e-Series is set by the Edge model you
have. You can purchase a model upgrade for your Edge to make more VPN tunnels. You can purchase a
Firebox X Edge Model Upgrade from a reseller or from the WatchGuard web site:
http://www.watchguard.com/products/purchaseoptions.asp
.