[fw-wiz] Site-to-Site VPN Gateway behind NAT device

From: Nick Brandson (nickbrandson_at_yahoo.com)
Date: 03/23/05

  • Next message: Shimon Silberschlag: "[fw-wiz] Screening Router as a firewall"
    To: firewall-wizards <firewall-wizards@honor.icsalabs.com>
    Date: Tue, 22 Mar 2005 22:33:24 -0800 (PST)
    
    

    Dear guru,

    Does anyone try build site-to-site VPN with one
    gateway behind a NAT device (like a router or a load
    balancer)?

    Both gateways are using NGAI R55 on SecurePlatform.
    Want to use a load balancer for two ISPs link. The
    primary link can be transparently go thru the LB
    device, the secondary link needs to be NATted to the
    Firewall. From the Firewall point of view, only one
    connection to the device. The device will make the
    decisions. We do NOT turn on the ISP redundancy in
    CP.

    what we need to set up in the peer gateway in order to
    identify the changes when ISP link failover.

    Do we need to set up two Firewall Objects in the peer
    gateway?

    Any ideas/input will be much appreciated.

    Thanks a million,
    Nick

                    
    __________________________________
    Do you Yahoo!?
    Yahoo! Small Business - Try our new resources site!
    http://smallbusiness.yahoo.com/resources/
    _______________________________________________
    firewall-wizards mailing list
    firewall-wizards@honor.icsalabs.com
    http://honor.icsalabs.com/mailman/listinfo/firewall-wizards


  • Next message: Shimon Silberschlag: "[fw-wiz] Screening Router as a firewall"

    Relevant Pages

    • Re: Another Secure FTP thread -- Protection Levels
      ... gateway or proxy system to act as an FTP relay ... firewall) to the remote system. ... He would need to establish his FTP ... connections from the gateway to the remote system while blocking FTP ...
      (comp.protocols.kermit.misc)
    • Re: Another Secure FTP thread -- Protection Levels
      ... through your firewall that is not authorized. ... FTP either restrict what commands can be sent or logging each command ... gateway or proxy system to act as an FTP relay ... between his system and the remote system. ...
      (comp.protocols.kermit.misc)
    • Re: Another Secure FTP thread -- Protection Levels
      ... gateway or proxy system to act as an FTP relay ... between his system and the remote system. ... There would then be two FTP ... firewall) to the remote system. ...
      (comp.protocols.kermit.misc)
    • Re: Routing problems
      ... >definition of a default gateway, ... local, or reachable through QWorst, and QWorst knows how to distribute ... >central routing point for all clients on the .1 subnet to access any of the ... I mentioned that the firewall has very tight security, ...
      (comp.os.linux.networking)
    • Re: RRAS - Works on internal network, not past DMZ
      ... > VPN Users would connect directly to the Public interface of the RRAS box. ... The Firewall would need some additional configuration if you ... On the network connections configuration of the RRAS box, ... but the 'multiple gateway' error message has me spooked. ...
      (microsoft.public.windows.server.networking)