Netgear made me pay for "premium" support to get this answer. I hope I
can save somebody else $28.95.
Excerpt from my original question to Netgear...
------------------------------------------
From "Reference Manual for the ProSafe Dual Band Wireless VPN Firewall
FWAG114", SM-FWAG114NA-0 Version 1.0 June 2003, Table 7.1:
'If Remote Access is selected, the “Exchange Mode” MUST be
“Aggressive,” and the ‘Identities’ below (both Local and Remote) MUST
be “Name.” On the matching VPN Policy, the IP address of the remote
VPN endpoint should be set to 0.0.0.0.'
However "VPN Policies" -> "Auto Policy" -> "Remote VPN Endpoint" ->
"Address Data" will not accept 0.0.0.0, Error messages says it isn't a
valid IP address.
------------------------------------------
"..the IP address of the remote VPN endpoint should be set to 0.0.0.0."
Should read (my wording)
"..the FQDN of the remote VPN endpoint should match the FQDN of the
remote identity in the IKE policy."
Normally this would be some arbitrary string that would also appear as
the local identity in the client config.
Did I mention that Netgear support stinks?
|