Hardware Installation Chapter 1:
1.2.3 Deployment Scenarios
To secure, restrict or inhibit pass-through traffic to the VPN Concentrator, it must be deployed
behind an enterprise firewall. Connect the WAN port of the VPN Concentrator to the DMZ
network (or port) of the firewall as shown in Figure 1-6. The WAN port should be assigned to a
private IP address (RFC 1918), or an IP address that can be used within a DMZ subnet. Connect
the LAN port of the VPN Concentrator to the LAN network using an LAN IP address from the
LAN’s IP subnet.
Figure 1-6 Connected to WAN
through firewall and gateway router
