User guide
Set up a Virtual Private Network (VPN) 114
Set Up a Virtual Private Network (VPN)
Learn about and set up virtual private network (VPN) client-to-gateway and site-to-site tunnels.
A VPN is a network that uses primarily public telecommunication infrastructure, such as the
Internet, to provide remote offices or traveling users an access to a central organizational
network. You need networking knowledge to implement these features.
VPN Overview
Learn about VPN client-to-gateway VPN tunnels and site-to-site VPN tunnels, which use IPSec
IKEv1 (PSK/XAuth).
● Remote-client-to-gateway VPN. The gateway must be connected to the public network
either through an LTE connection or WAN uplink. Remote users on the Internet can
create an IPSec tunnel from their computers to the gateway using the WAN IP address
of the gateway. Once connected, the remote users can access the LAN-side resources
of the gateway.
The gateway supports the following clients:
NETGEAR ProSAFE VPN Client VPNG01L/VPNG05L Professional Software
Version 5.14.003, available here:
http://kb.netgear.com/app/answers/detail/a_id/20316
IPSecuritas VPN client Version 3.4 for MAC OS platforms from Lobotomo Software,
available here: http://www.lobotomo.com/products/IPSecuritas/
● Site-to-site VPN. You can establish an IPSec tunnel between two gateways. The LAN-
side users from either gateway can access the other through the site-to-site tunnel.
When you are configuring the site-to-site tunnel, each gateway must have a unique IP
address range for its LAN side.
● VPN Passthrough. Allow IPSec tunneling through the gateway. This feature enables
gateway NAT clients to connect using their own VPN software, terminating only on their
device. The VPN tunnel “passes through” the gateway NAT. This feature is enabled by
default.
● IP Passthrough. This feature opens a direct connection to one client where the network
IP address is assigned to that client. This is not VPN itself but can be used to facilitate
VPN setup from the assigned IP passthrough client. The following options are
supported: MAC address, name, Ethernet ports 1 through 4. Only one option at a time is
allowed.
Note: This is not a VPN by itself, but can be used to facilitate VPN setup from other devices.