December 2012
NETGEAR, the NETGEAR logo, and Connect with Innovation are trademarks and/or registered trademarks
of NETGEAR, Inc. and/or its subsidiaries in the United States and/or other countries. Information is subject to
change without notice. Other brand and product names are registered trademarks or trademarks of their
respective holders. © NETGEAR, Inc. All rights reserved.
Intended for indoor use only in all EU member states, EFTA states, and Switzerland.
Now, Configure WAN Rollover Mode
The WAN ports of the firewall can be configured for either rollover for increased system
reliability or load balancing for maximum bandwidth efficiency. The rollover option is
presented here. Refer to the manual for instructions on configuring the load balancing
mode.
In rollover mode, expect the following:
• You designate one WAN port as primary and the other as the rollover link.
• While the primary link is up, all traffic goes over the primary WAN port. If the
primary link goes down, traffic is sent over the rollover link.
• Traffic will automatically roll back to the primary link once it is back up.
To configure the dual WAN ports for rollover:
1. Select WAN Mode from the sub-menu. The WAN Mode screen will display.
2. From the Auto-Rollover pull-down menu, select which WAN port will be primary.
3. WAN failure is detected using DNS queries to the DNS server or PING messages to
an IP address. If the replies are not received, the WAN interface is considered down.
Fill in the appropriate fields:
• Configured DNS Servers – In this case, DNS queries are sent to the ISP DNS
servers configured on the WAN ISP pages.
• Using this DNS Server – In this case, DNS queries are sent to a specified DNS
Server.
• Ping to this IP address – In this case, PING queries are sent to the specified IP
address.
• Test Period – a DNS or PING query is sent after every test period. The minimum
test period is 30 seconds.
• Failover after – The WAN link is considered down after the configured number
of queries fail to get a reply. The minimum number of failed queries is four. The
rollover link is brought up after this.
4. Click Apply to save your changes.
Troubleshooting Tips
Here are some tips for correcting common problems you may encounter.
Be sure to restart your network in this sequence:
1. Turn off and unplug the modems, turn off the SRX5308, and shut down the computer.
2. Plug in and turn on the modems. Wait for the modems to power up (approximately 2
minutes).
3. Turn on the SRX5308. Wait until the amber test light goes out.
4. Turn on the computer.
Make sure the Ethernet cables are securely plugged in.
• The WAN Link/Act light on the VPN firewall will be lit if the Ethernet cable to the
VPN firewall from each modem is plugged in securely and the modems and VPN
firewall are turned on.
• For each powered on computer connected to the VPN firewall with a securely
plugged in Ethernet cable, the corresponding VPN firewall LAN port status light
should be lit. The front of the SRX5308 identifies the number of each LAN port.
Make sure the network settings of the computer are correct.
Computers must be configured to obtain IP and DNS addresses automatically via DHCP.
For help with this, please see the online Reference Manual; a link to the manual is on the
ProSafe® Gigabit Quad WAN SSL VPN Firewall SRX5308 Resource CD.
For Cable Modem connections, use MAC spoofing.
Some cable modem ISPs require that you use the MAC address of the computer registered
on the account. If so, in the Router’s MAC Address section (accessed through the
Advanced link on the WAN1 ISP Settings screen), select either “Use this Computer’s
MAC” or “Use this MAC address” and enter the appropriate MAC address. The firewall
will then capture and use the MAC address of the computer that you identified. You must
select the computer that is registered with the ISP. Click Apply to save your settings.
Restart the network in the correct sequence.
Use the SRX5308 status lights to verify correct operation.
If the SRX5308 Test light does not go out approximately 2 minutes after turning the
firewall on, reset the fiewall as described in the Reference Manual.
Technical Support
After installing your device, locate the serial number on the label of your product and use
it to register your product at https://my.netgear.com.
You must register your product before you can use NETGEAR telephone support.
NETGEAR recommends registering your product through the NETGEAR website.
For product updates and web support, visit http://support.netgear.com.
NETGEAR recommends that you use only the official NETGEAR support resources.
You can get the reference manual online at http://downloadcenter.netgear.com or through
a link in the product’s user interface.
For the current EU Declaration of Conformity, visit
http://support.netgear.com/app/answers/detail/a_id/11621/.
SRX5308_IG.fm Page 2 Friday, December 14, 2012 12:37 PM