Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations derfloh on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

Help setting up VPN with SBS 2003

Status
Not open for further replies.

brokenhalo

IS-IT--Management
Feb 24, 2008
169
US
Hey,
I have a quick question and heres the scenario...
I have a client that has 2 offices, and they wanted a solution to where they can 1) control what their employees do on the company computers, and 2) be able to access files from either location centrally. So with that info, I instructed them to purchase 2 small servers, one for each location, and I would setup a site to site vpn. The servers that they purchased come with SBS installed, and I personally have never worked with it, and also have never actually setup a site-to-site vpn (except for in a classroom). I know I am going to need vpn capable routers, but what do I do from there? Do I need ISA? I know I need to setup the link with AD sites and services, but I don't really know the specifics on the process. If anyone could help me with the process or show me where to start looking it would be appreciated. Both sites use business class DSL (I think) and have static IP addresses. Thanks

Brad L. - MCP

"If the doctors told me I had 5 minutes to live, I would type faster.
 
Both of the servers are brand new and dont come with any firewall pre-installed I don't believe. I don't think I really need anything as complex as setting up ISA, that whole process I think will take too much time, and more $$$ than the company wants to spend. Is there another solution I could use? All they really need is to share files between both offices, so maybe a simpler to install and configure scenario that has basic functionality. Thanks again.

Brad L. - MCP

"If the doctors told me I had 5 minutes to live, I would type faster.
 
I meant do they have a hardware firewall at each office? Like a Cisco pix or similar?
Watchguard do some good value, easy to use SOHO boxes that can have branch office vpn's between them.

Check here

How do the two LAN's connect to the internet?
 
Haha wow I feel stupid. No, they don't have any hardware firewall, just a bottom of the barrel linksys router. I was looking up on just getting them a vpn ready linksys with the quickvpn client or using ssl-explorer. Has anyone used this? If so do you think it might be suitable for me?

Brad L. - MCP

"If the doctors told me I had 5 minutes to live, I would type faster.
 
ssl-explorer rocks. I don't know if you can do branch 2 branch VPN's though.
Whether it works for you is up to you. It is easy to setup and the paid version can be integrated with AD authentication-afaik.
The problem I find with most VPN systems is the management once they're up and running-especially if tokens are passwords which really do need to be changed on a regular basis.
If you can get the VPN to integrate with some kind of auth system you already have in place(ie AD) then it makes it easier to run and manage the security of. My .02 :)
 
This is one of those I need to be sat at my server to see whats going on, which I'm not.
But just as for starters my first concern would be, has the company been assigned 2 specific IP addresses, which can be assigned to the routers.
If memory serves when you run the VPN wizard it will ask you for the IP address of you default gateway, if you turn of the router it will request another IP address from the ISP this may not be the one you had originally.

Working towards my MCSE/A and CompTIA. Any help greatly appreciated.
 
Well I've came to the conclusion that they dont really need a site-to-site vpn, as long as they share the same centrally accessed file server. I think I'm going to just use QuickVPN. Even though I dealt with a nightmare yesterday with another client using the same setup (Linksys VPN with QuickVPN client software), I find it pretty rare for these problems. I think I will use ssl-explorer for my next ordeal. Thanks everyone for the feedback!

Brad L. - MCP

"If the doctors told me I had 5 minutes to live, I would type faster.
 
I was also going to say, make sure you run the VPN wizard before you install the Service Pack 1 or 2, else you'll get an error which requires an uninstall of the SP, run wizard and re-install SP. which can cause another series of headaches.

Working towards my MCSE/A and CompTIA. Any help greatly appreciated.
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top