localzuk Posted November 27, 2014 Posted November 27, 2014 So, further to my last theoretical discussion about multiple active directory domains on different sites, I now have a question about site to site VPNs. I've used various tools in the past to connect sites together via a VPN, such as using Sonicwall, IPCop (that was a while ago!) etc... My question is - what do you guys use, if you have site to site VPNs in place anywhere?
CyberDrac Posted November 27, 2014 Posted November 27, 2014 I have a site to site VPN between my home address and my friends house, pfSense box at either end using OpenVPN
tmcd35 Posted November 27, 2014 Posted November 27, 2014 I've setup SSL VPN on our Smoothwall box so I can remote in from home. Seems to work pretty well and was easy to set up. Between sites? Not had to do it as yet but would probably look at something using this in the first instance.
sparkeh Posted November 27, 2014 Posted November 27, 2014 I've setup SSL VPN on our Smoothwall box so I can remote in from home. Seems to work pretty well and was easy to set up. Between sites? Not had to do it as yet but would probably look at something using this in the first instance. Yeah we have a SW VPN that works really well and dead easy to setup, the config to turn it into site to site seems trivial.
plexer Posted November 27, 2014 Posted November 27, 2014 Do you have any current equipment you may be using for this? Ben
localzuk Posted November 27, 2014 Author Posted November 27, 2014 Nope. This situation would be entirely from scratch joining networks. Has anyone looked at/used the Black Box EncrypTight stuff?
FN-GM Posted November 27, 2014 Posted November 27, 2014 (edited) Used Sonicwall, was pretty good, never had any issues once it was setup. In the end 1 school dumped the internet connection and the VPN was replaced with a Point 2 Point link. Both sites shared the same internet connection. Worked out much easier and cheaper. In a lab environment I have also setup site to site VPN on Cisco routers. It was dead easy to setup. It can be pretty cost affective as well. Edited November 27, 2014 by FN-GM
Mr_Jiminy Posted November 27, 2014 Posted November 27, 2014 Meraki MX Security Appliances are pretty easy to configure, however not been overly keen with their tech support (for other reasons).
john Posted November 27, 2014 Posted November 27, 2014 We have lots of them and they are all on Cisco ASAs, small offices have 5505s and larger offices have larger ciscos in the same range, bulletproof bits of kit, never let us down etc...
Ergo_Computing_IS_Support Posted November 27, 2014 Posted November 27, 2014 Watchguard firewalls do this really well from past experience. In terms of what they offer functionality-wise vs. the price, they are hard to beat. Also, the management interfaces (webgui + software app) are really straight forward to use and administer on a day-to-day basis. No command line knowledge required! (but can be still be used for very advanced scenarios) Thanks.
nicholab Posted November 27, 2014 Posted November 27, 2014 I would say the same about Pfsense the GUI is really good. Also you can either go free or get support.
avenn Posted December 2, 2014 Posted December 2, 2014 we use mikrotik so pick what VPN you want from OpenVPN, IPsec, PPTP, L2TP or SSTP which is what we use. We create self signed certs for win7 and mikrotik box to box. so far very stable.
MatthewL Posted December 2, 2014 Posted December 2, 2014 Used over 100 watchguard boxes in the last job site connection back to our core site. Pfense another good one. On the topic of VPN what is the best type to use PPTP, IPsec or L2TP?
avenn Posted December 3, 2014 Posted December 3, 2014 we have used openVPN and SSTP (road warrior and site 2 site) a lot and all appears good so far. we looked at PPTP but to many vulnerability reports/issues however quick and easy to setup. IPses - used in the past (site 2 site) but can be complex and we found cross platform compatibility issues. SSTP - i believe - is now the default for windows - ensure enough BW to cope with encrypted data TCP timing issues. L2TP - no encryption - generally paired with IPsec if enryption needed. a few things to consider: site to site or roadwarrior connections? bandwidth available? can this be know for road warrior? good luck! regards aidan
localzuk Posted January 12, 2015 Author Posted January 12, 2015 This is a long term possibility, its still early days. I'm looking at 6-12 months away before implementation is needed.
nwilkie Posted January 12, 2015 Posted January 12, 2015 If you are doing it within the same LA and ofc you are using them for your internet couldn't you consider asking them to connect the two ranges for you their end. Works for us we have three sites connected this way works a treat.
localzuk Posted January 13, 2015 Author Posted January 13, 2015 Its a bad idea to have internal traffic going across a network you don't control unencrypted - you have no control over who is intercepting, monitoring or logging your traffic. Putting a VPN in adds a little overhead, but adds a layer of protection which controls who can see what. Our LA network is complex, with people from various companies involved in its provision. I would not like to leave it open whatever the case.
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now