AJWhite1970 Posted February 23, 2016 Posted February 23, 2016 Currently thinking out-loud with another (trusted) school in the area about using each others sites to backup key data to as an additional layer of disaster recovery. Both sites have fast robust internet connections and both are completely running 2012R2 servers. Each site would provide a server to be hosted on the others site so basically Site A backs up to a server on Site B and Site B backs up to a server on Site A but only at weekends so as not to affect internet performance during the week. Both sites are on SWGfL What would the collected experts here suggest to use as the gateway server on each site? A windows offering that is available via EES, OpenVPN as a VM or something else? Thanks as always and apologies for sounding dumb, not my area of expertise... Andrew
localzuk Posted February 23, 2016 Posted February 23, 2016 I have been considering this as a possibility for our soon to exist trust. I've been looking at the Meraki options - their site to site VPN automatically configures itself for any devices you add to a group in the dashboard. So basically all you do is buy the device, add it to the VPN group and voila, it will work when put in place the other end. Not bad pricing either for a gateway device. 1
Geoff Posted February 23, 2016 Posted February 23, 2016 (edited) I have managed VPN links between our sites provided by Virgin Media. It's an addon extra to their MPLS cloud offering (which we use). The theory would be that if the MPLS Fibre went down the IP VPN backup link would kick in. It's a very nice system and we've not lost connectivity to a site since we installed it. It costs lots. If I was doing this on the cheap I'd probably use pfSense VMs for my site to site VPN. So this might be something you wish to look at. https://doc.pfsense.org/index.php/OpenVPN_Site_To_Site Edited February 23, 2016 by Geoff 1
cpjitservices Posted February 23, 2016 Posted February 23, 2016 Defo PfSense with openvpn works a treat, and really easy to setup and export the utility so easy install and start at both ends. you could use something like Deltacopy to send the data to/from the servers. 1
Asgard Posted February 23, 2016 Posted February 23, 2016 (edited) I did it just under two years ago with another college - was the subject of a JISC & Microsoft Case Study http://blogs.msdn.com/b/ukhe/archive/2014/05/16/making-literature-come-alive-with-office-365.aspx http://moodle.rsc-northwest.ac.uk/pluginfile.php/1062/mod_resource/content/1/Kevin%20Burke%20%20John%20Paul%20Szkudlapski%20-%20Carmel%20College%20%20Birkenhead%20Sixth%20Form%20College%2C%20Offsite%20Backups.pdf We back up to each other between 8pm and 6am - The slides are a bit out of date now - Our offsite backup is now a physical box running Hyper-V 2012 R2 with both a Read only domain controller and DPM 2012 R2 with a 72TB Dell Md1200 connected to it. The onsite DPM has a 36TB MD1200 In the event of a failure (we tested it recently by disconnecting our Internet link ) I can restore a full VHD of a server and hey presto it connects to the RODC. Or just the file shares I need or critically the MIS data [emoji106] Edited February 23, 2016 by Asgard 1
Steve21 Posted February 23, 2016 Posted February 23, 2016 Both sites are on SWGfL What would the collected experts here suggest to use as the gateway server on each site? A windows offering that is available via EES, OpenVPN as a VM or something else? You might want a chat with SWGfL if you have a contact there. At my old place when linking two of our federated feeders the SWGfL offered to connect their networks together within the SWGfL private network so they could effectively see and communicate without touching the outside world. (By default it's disabled) That way they could backup to eachother without anything being opened firewall wise etc as data never left the grid. Might be worth a chat to see if they still allow it Steve 1
AJWhite1970 Posted February 23, 2016 Author Posted February 23, 2016 Might be worth a chat to see if they still allow it Will be first job in the morning, thanks for the heads-up
twin--turbo Posted February 23, 2016 Posted February 23, 2016 if you have no firewalls, and are using the xGFL IP's then there may be nothing to stop you communicating between each other unhindered, that's how it used to be for a very long time on the xGFL's one big private network . 1
Steve21 Posted February 24, 2016 Posted February 24, 2016 if you have no firewalls, and are using the xGFL IP's then there may be nothing to stop you communicating between each other unhindered, that's how it used to be for a very long time on the xGFL's one big private network . Not sure if it's the same for all of them, but I know when talking to SWGfL at previous place they stopped all intervlan traffic by default (each school is effectively a VLAN on the grid) as apparently back in the day one Conflicker like virus jumped from school to school that way That's why now if you want it they'll enable it but lock it down to the ports you require. Steve
karldenton Posted February 24, 2016 Posted February 24, 2016 I have been looking into this too. Have a look at Sophos UTM at each site - might work out expensive but does site-to-site over low bandwidth.
cpjitservices Posted February 24, 2016 Posted February 24, 2016 We also have this sort of setup on Draytek routers at both ends, using the solution they have built in you can manage VPN clients from the router web interfaces. CVM How to use Central VPN Management (CVM)? - DrayTek Corp
Geoff Posted February 24, 2016 Posted February 24, 2016 Not sure if it's the same for all of them, but I know when talking to SWGfL at previous place they stopped all intervlan traffic by default (each school is effectively a VLAN on the grid) as apparently back in the day one Conflicker like virus jumped from school to school that way That's why now if you want it they'll enable it but lock it down to the ports you require. Steve Sounds like SWGfL is an MPLS cloud like mine. It depends if it's Layer 2 (in which case, yes VLANs) or Layer 3 (In which case OSPF routing). Either way this is technically possible.
mjs_mjs Posted February 24, 2016 Posted February 24, 2016 Silly Question - but do you really need a site to site? If you're only standing one server up, why not just get that server to VPN into your network. And likewise the other way round. This means that both schools networks are isolated also (as you can route all traffic over the VPN tunnel).
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now