On 4/7/06, Mike Ansell <mike dot ansell at norrcom dot com> wrote:
>
> Firewall WAN: 172.16.1.1 - Wireless AP plugged in here
>
> Firewall LAN: 10.20.1.5 - plugged to VPN WAN
>
You didn't mention, so I'll assume you haven't disabled NAT. In this
situation, you don't want to NAT. Enable advanced outbound NAT on the
Outbound tab of the NAT screen. Then, I'd switch the LAN and WAN so
LAN is the wireless network and WAN is the VPN server. That way the
default gateway of the system is pointing in the correct direction
(default gateway is always on WAN). In this type of setup, it doesn't
matter what the interfaces are labeled by the system, you're using it
as a filtering router, not a firewall.
-Chris |