User guide
What You Need to Create a VPN
User Guide 95
If the devices that connect through the VPN tunnel are not config-
ured correctly, the VPN tunnel will not function.
Special considerations
Consider these points before you configure your WatchGuard Fire-
box X Edge VPN network:
• You can connect a maximum of 10 Firebox X Edge appliances
together in a star configuration. To configure more VPN
tunnels, a WatchGuard Firebox III or Firebox X with WatchGuard
VPN Manager is necessary.
• WatchGuard recommends that both of the VPN appliances have
a static IP address. Configuring a VPN tunnel between two
appliances using dynamic IP addresses, can pose several
problems. See “Network addressing” on page 5 for more
information about dynamic IP addresses. However, these issues
can be resolved by using Dynamic DNS. For information on
configuring the Dynamic DNS feature, see “Registering with the
Dynamic DNS Service” on page 59.
• Both appliances must use the same encryption method: either
DES or 3DES.
• When two Microsoft Windows NT networks are connected, the
two networks must be in the same Microsoft Windows domain
or be trusted domains. This is a Microsoft Networking design
implementation and not a limitation of the Firebox X Edge.
WatchGuard recommends that you make a record of the configura-
tion information in the following format.