Reference Manual for the ProSafe VPN Firewall FVS114
C-8 Virtual Private Networking
202-10098-01, April 2005
You need to know the subnet mask of both gateway LAN Connections. Refer to Appendix A, 
“Technical Specifications” to gather the necessary address and subnet mask information to aid in 
the configuration and troubleshooting process.
Firewalls
It is important to understand that many gateways are also firewalls. VPN tunnels cannot function 
properly if firewall settings disallow all incoming traffic. Please refer to the firewall instructions 
for both gateways to understand how to open specific protocols, ports, and addresses that you 
intend to allow.
VPN Tunnel Between Gateways
A Security Association (SA), frequently called a tunnel, is the set of information that allows two 
entities (networks, PCs, routers, firewalls, gateways) to trust each other and communicate securely 
as they pass information over the Internet.
Table C-1. WAN (Internet/public) and LAN (internal/private) addressing
Gateway LAN or WAN VPNC Example Address
Gateway A LAN (Private) 10.5.6.1
Gateway A WAN (Public) 14.15.16.17
Gateway B LAN (Private) 22.23.24.25
Gateway B WAN (Public) 172.23.9.1
Table C-2. Subnet addressing
Gateway LAN or WAN Interface Name Example Subnet Mask
Gateway A LAN (Private) Subnet Mask A 255.255.255.0
Gateway B LAN (Private) Subnet Mask B 255.255.255.0