
Configuring WAN Bonding Settings
55
BODi rS BD1000 User Manual
4 • Configuring the WAN
Configuring a NAT Router Behind the BD1000 for VPN Connections
The BD1000 supports establishing Site-to-Site VPN over WAN connections that are behind a NAT (Network
Address Translation) router. In order for a WAN connection behind a NAT router to accept VPN connec-
tions, you can configure the NAT router in front of the WAN connection to forward to TCP port 32015.
If one or more WAN connections on
Router A
can accept VPN connections (by means of port forwarding or
not) while none of the WAN connections on the peer
Router B
can, you should put all public IP addresses or
host names of the
Router A
in the
Router B
on
Router B
. Leave the
Peer IP Addresses / Host Names
field
on
Router A
empty. With these settings in place, the BD1000 can set up a site-to-site VPN connection and all
WAN connections on both sides can be used. For example, see Figure 31 below:
Figure 31. BD1000 Behind a NAT Router Application
One of the WAN connections of
Router A
is not using NAT (
212.1.1.1
). The rest of the WAN connections
on
Router A
and all of the WAN connections on
Router B
are using NAT. In this case, the
Peer IP
Addresses / Host Names
field in
Router B
should be filled with all of the
Router A
’s host names or public IP
addresses (i.e.
212.1.1.1
,
212.2.2.2
and
212.3.3.3
), and the field in
Router A
can be left blank. The two NAT
routers on WAN1 and WAN3 of
Router A
should forward inbound traffic through TCP port 32015 to
Router A
so that all of the WAN connections can be utilized to establish the VPN connection.
Viewing the WAN Bonding Status
To view the status of VPN connections, click on the
Dashboard
in the Web Admin Interface. The
WAN
Bonding
section shows the connection status of each connection profile. To view more details about a VPN
connection status, click the
Status
button in the top-right hand corner of the
WAN Bonding
table. The
Sta-
tus > WAN Bonding
page display provides the subnet and WAN connection information of each VPN peer.
Refer to
“Viewing Site-to-Site VPN Connection Details”
on page 136 for more information.
Note
IP Subnets must be unique among VPN peers.
The entire inter-connected WAN Bonding network is one single
non-NAT IP network. No two subnets in two sites can be dupli-
cated. Otherwise, the BD1000 will experience connectivity problems
in accessing those subnets.