Need to have the VPN "host" behind NAT



I have a client who has a corporate firewall located out of state. We
have been given permission to setup a VPN solution into the local
subnet via the corporate internet connection. The corp folks will be
giving us a 1-to-1 NAT association for whatever IP address we select
from the external IP they give us on the firewall.

I'm familiar with several brands of small routers (netopia of old,
Watchguard, Sonicwall, etc) and was thinking of putting in a small
Watchguard Edge and let the remote user us MUVPN to get in. The
problem that just occured to me is that a "router/firewall" with VPN
access will not work.

So, I have a local subnet of 10.0.0.x and I want to setup a VPN into
that subnet.
The Watchguard Edge will have a local ip address assigned to the WAN
port (lets say 10.0.0.5) and the LAN port will be on the same
subnet.....this won't work (at least the edge won't let it happen).
I'm not needing the firewall/NAT portion of the firewall. All I need
is the VPN connection.

Anyone have any ideas on a <$1000 solution for a VPN only box that we
could set on the local network, allow a single cllient to access it and
assign that client a local address?

Most of the manufacturer's pre-sales support is lost on this.

Thanks for any ideas.

jf

.



Relevant Pages

  • Re: What am I missing? (Net View issues)
    ... assuming you can't map ip or hostname, do you have a firewall blocking the ... Networking, Internet, Routing, VPN, Anti-Virus, Tips & Troubleshooting on ... > The primary w2003 network is on the 16.0/255 subnet. ... I have been able to map to this particular ...
    (microsoft.public.windows.server.networking)
  • RE: Sandboxing
    ... the 3Com Embedded Firewall would be extremely useful and enabling (in ... your case) when you look at it in a VPN context. ... This security policy will accomplish quite a few things: ... During the Policy Server installation, ...
    (Focus-IDS)
  • Re: VPN Firewall for new webserver
    ... > I'm setting up a webserver at a colocation and I need to put a VPN ... You're not going to get a quality firewall for that amount, ... and D-Link makes a DI-804HV unit ... users access to the SQL server, let them do it through a VPN session. ...
    (comp.security.firewalls)
  • Re: Firewall Info/Recommendations?
    ... I would seriously consider an air-gap solution. ... Let me outline a few features that no other firewall can touch. ... Provide secure access without a VPN from any web browser (this greatly ... > manageable without much higher-level support if you want things like ...
    (comp.security.firewalls)
  • Re: [fw-wiz] Integrated IDS/IPS/Firewall (Cisco ASA and Juniper ISG)
    ... complexity and architectural inelegance of having 3-5 gateway security ... VPN) convinced me to eventually champion a migration to Symantec's SGS ... Nice balance of "default deny" at the firewall, ...
    (Firewall-Wizards)

Loading