12.07.2015 Views

WSM User Guide - WatchGuard Technologies

WSM User Guide - WatchGuard Technologies

WSM User Guide - WatchGuard Technologies

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Network Address Translation and VPNsagree on a session key. Group 1 is a 768-bit group, and group 2 is a 1024-bit group. Group 2 is moresecure than group 1, but uses more processor time to make the keys.Network Address Translation and VPNsWith Network address translation (NAT), the source and destination addresses of IP packets are changedas they go through the router or a firewall. If you use NAT between two VPN gateways, you must use ESP(not AH) as the authentication protocol when you create VPN tunnels between the devices.If you send IPSec or PPTP traffic through a Firebox® (IPSec or PPTP pass-through), the Firebox can use 1-to-1 NAT to send the traffic.Access ControlVPN tunnels lets users get access to resources on your computer network. Think which type of resourcesare needed by a given type of user. For example, you can let a group of contract employees get access toonly one network and your sales personnel can get access to all the networks.Different VPN types also can set your level of trust. Branch office VPNs (BOVPNs) have a firewall device atthe two ends of the tunnel. They are more safe than MUVPN and RUVPN, which have protection at onlyone end.Network TopologyYou can configure the VPN for support of meshed and hub-and-spoke configurations. The topology thatyou select sets the types and number of connections that occur. It also sets the flow of data and the flowof traffic.Meshed networksIn a fully meshed topology, all servers are connected together to make a web. Each device is only onestep from each other VPN unit. Traffic can go between each unit of the VPN, if necessary.Fully Meshed Network<strong>User</strong> <strong>Guide</strong> 229

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!