344☛ NOTE:Typically, no special configuration is necessary to use the IPSec pass throughfeature.In the diagram, VPN PC clients are shown behind the Netopia Gateway and thesecure server is at Corporate Headquarters across the WAN. You cannot haveyour secure server behind the Netopia Gateway.When multiple PCs are starting IPSec sessions, they must be started one at atime to allow the associations to be created and mapped.VPN IPSec Tunnel TerminationThis Netopia service supports termination of VPN IPsec tunnels at the Gateway. This per-mits tunnelling from the Gateway without the use of third-party VPN client software on yourclient PCs.Stateful Inspection FirewallStateful inspection is a security feature that prevents unsolicited inbound access whenNAT is disabled. You can configure UDP and TCP “no-activity” periods that will also apply toNAT time-outs if stateful inspection is enabled on the interface.Technical details are discussed in “Expert Mode” on page 39.SSL Certificate SupportOn selected models, you can also install a Secure Sockets Layer (SSL V3.0) certificatefrom a trusted Certification Authority (CA) for authentication purposes. If this feature isavailable on your Gateway, an additional link will appear in the Install page.See “Install Certificate” on page 188.