Netgear UTM9S – ProSECURE Unified Threat Management (UTM) Appliance with DSL and Wireless modules 参照マニュアル

ページ / 631
Virtual Private Networking Using IPSec Connections
239
 ProSecure Unified Threat Management (UTM) Appliance
Use the IPSec VPN Wizard for Client and Gateway 
Configurations
You can use the IPSec VPN Wizard to configure multiple gateway or client VPN tunnel 
policies.
The following section provides wizard and NETGEAR ProSafe VPN Client software 
configuration procedures for the following scenarios:
•     
Using the wizard to configure a VPN tunnel between two VPN gateways
•     
Using the wizard to configure a VPN tunnel between a VPN gateway and a VPN client
Configuring a VPN tunnel connection requires that you specify all settings on both sides of 
the VPN tunnel to match or mirror each other precisely, which can be a daunting task. The 
VPN Wizard efficiently guides you through the setup procedure with a series of questions that 
determine the IPSec keys and VPN policies it sets up. The VPN Wizard also configures the 
settings for the network connection: security association (SA), traffic selectors, authentication 
algorithm, and encryption. The settings that are used by the VPN Wizard are based on the 
recommendations of the VPN Consortium (VPNC), an organization that promotes 
multivendor VPN interoperability.
Create Gateway-to-Gateway VPN Tunnels with the Wizard
Figure 136. 
VPN Gateway-to-Gateway
(gateway to gateway)
Fixed
FQDN required
FQDN Allowed (optional)
Dynamic
FQDN required
FQDN required
VPN Telecommuter
(client to gateway through a 
NAT router)
Fixed
FQDN required
FQDN Allowed (optional)
Dynamic
FQDN required
FQDN required
a. After a rollover, all tunnels need to be reestablished using the new WAN IP address.
Table 54.  IP addressing for VPNs in dual WAN port systems (continued)
Configuration and WAN IP address
Rollover mode
a
Load balancing mode