User`s manual

A subnet on your Internal network, protected by a VPN gateway, can connect through your DFL-500 to a
VPN on the Internet
No special VPN configuration is required for the client or VPN gateway on your internal network. The VPN
tunnel configuration of the VPN gateway on the Internet must be changed to accept connections from the IP
address of the external interface of the DFL-500.
L2TP VPN connections can be made from the internal network to an L2TP VPN gateway on the Internet without
modifying the DFL-500 configuration.
This section describes how to create three VPN pass through configurations:
PPTP client to network VPN pass through
Use the following procedure to create the configuration shown in PPTP client connecting to a VPN in the
Internet using VPN pass through. In this configuration, the PC on your Internal network runs PPTP VPN client
software and connects to the PPTP VPN gateway on the Internet.
PPTP client connecting to a VPN in the Internet using VPN pass through:
Configure the PPTP VPN client to connect to the destination PPTP VPN gateway as if the client computer
is connected directly to the Internet. See PPTP VPN configuration.
Configure the destination PPTP VPN gateway. See Configuring the DFL-500 as a PPTP server
.
On the DFL-500 firewall, go to Firewall > Policy .
Select PPTP Pass Through and click Apply.
When the PPTP VPN client connects to the destination PPTP VPN gateway, the DFL-500 firewall accepts
PPTP VPN connections from the internal network and performs network address translation on them. The
DFL-500 User’s Manual
61