ProSafe Gigabit 8 Port VPN Firewall FVS318G Reference Manual
Virtual Private Networking Using IPsec 5-21
1.1 November, 2009
The FVS318G is acting as a NAS (Network Access Server), allowing network access to 
external users after verifying their authentication information. In a RADIUS transaction, the 
NAS must provide some NAS Identifier information to the RADIUS Server. Depending on the 
configuration of the RADIUS Server, the FVS318G’s IP address may be sufficient as an 
identifier, or the server may require a name, which you would enter here. This name would 
also be configured on the RADIUS server, although in some cases it should be left blank on 
the RADIUS server.
5. Enable a Backup RADIUS Server (if required). 
6. Set the Time Out Period, in seconds, that the VPN firewall should wait for a response from 
the RADIUS server. 
7. Set the Maximum Retry Count. This is the number of tries the VPN firewall will make to the 
RADIUS server before giving up. 
8. Click Apply to save the settings.
Assigning IP Addresses to Remote Users (ModeConfig)
To simply the process of connecting remote VPN clients to the FVS318G, the ModeConfig 
module can be used to assign IP addresses to remote users, including a network access IP address, 
subnet mask, and name server addresses from the VPN firewall. Remote users are given IP 
addresses available in secured network space so that remote users appear as seamless extensions of 
the network. 
In the following example, we configured the VPN firewall using ModeConfig, and then 
configured a PC running ProSafe VPN Client software using these IP addresses.
• NETGEAR FVS318G ProSafe VPN Firewall
– WAN IP address: 172.21.4.1
– LAN IP address/subnet: 192.168.2.1/255.255.255.0
• NETGEAR ProSafe VPN Client software IP address: 192.168.1.2
Note: Selection of the Authentication Protocol, usually PAP or CHAP, is configured 
on the individual IKE policy screens.