Jump to content

Recommended Posts

Posted (edited)

Afternoon folks,

 

This might take some time to explain, so please bear with me!

Or - TLDR: Folder redirection + smoothwall vpn = noworky, how to worky, or better?

 

Moving on'

Im a system admin at a muti site PRU, with off site staff that travel around. Way back when (past two years), we had Roaming profiles, but due to size of profiles (120gb for some), network usage, login loads, generic slow downs, just became a slow race for someone to slap IT around the head and say "oi what you playing at"

 

Summer turned up;

So we moved over to folder redirection and windows 10. Long story short for here, it works lovely. Staff accessing their files in a reasonable time, logins are smooth and crisp, and everyones happy..... apart from off site staff.

I pushed for smooth-wall firewall to be installed over the summer (since we had none before......) which has been grand, and with their included VPN access, i believe it would solve off site users woes ten fold - oh how wrong i was.

 

So accessing shared folders / SIMS's and other network based programs/DB's/folders has been fine to the most part, but folder redirection just wont work flat out.

Checking upon google, and around 150 tabs later, it seemed i was not alone. From what i could tell (no exact straight answer) their folders where unable to be accessed due to the DNS not resolving the naming convention of the NAS (all users folders located there - Documents/downloads etc etc)

So we have tried everything - Directing DNS settings on smoothwall to point to our DNS server - Removing AV to see if that was stopping anything - Adjusting our DNS server to what we could to attempt a fix, and alas, no luck.

 

Il have to note here, i am the only IT tech/systemadmin at this site with no other support - or rarely at all - so i am always looking at making my job easier along the route. Anything that can make the users experience more seamless and borderline "easier" makes my day easier. Lately, amending the start menu just with shortcuts to EVERYTHING they require, meaning less confusion and upset for an example - custom background with details about the machine, and numbers to contact for IT support, etc etc etc.

Plus we are placing 3 other sites onto my network over the next two years, and having a meshed network. So you can see how i would like everything to work for the end users, or my ticket system be broken after 5mins!

 

So with this issue, i was wondering if i could somehow do one of the following;

1)
Fix folder redirection over VPN clients - keep what we got, nothing new, just a fix. possible?

 

2)
Using 365 Sharepoint's as a cloud based redirect to their folders (possible? Mirgration tool?) And then having it backed up to our local nas daily/Every save etc etc. Giving a lot of backups in case of worse case.

Know it can be done using the onedrive pro app, and enforcing users to embrace with a small GUI tool, but can this be directed per user on that machine?

 

3)
Work-folders? I herd this is mostly aimed at Single user per device, over multiple users one device - Seems the reg edits and setup focuses more on one user > One device (according to Microsoft techcommunity/ Microsoft doc's etc etc) . While that resolves our off-site staff, internal staff use mixture of desktops all over the site, and their own laptop.

 

4)
Telling them to get over it, and just put files they need to work on to the desktop, and risk more slaps and abuse?

 

I have been looking around the past few weeks, with what little downtime i get. But felt that maybe reaching for a hand here might be a better option.

Have you guys managed folder-redirection over VPN? How did you get that resolved? Is it just smooth-wall that might be causing the issue.

Are my other suggestions more worth while? Would AzureAD profiles help at all? or maybe moving to sharepoints? What would you suggested for End user experience.

 

Any suggestions or idea's are really appreciated. And sorry if it sounds a mess, as i really feel like it today! think the weather is getting to me....

 

Cheers guys!

Edited by Xellpnz
Posted
I am having the same issue, I've tried using IKEv2 instead but apparently there is a bug with Windows 10 that drops the connection after 30 seconds but it looks like its still connected.
Posted

So you can VPN correctly and everything works except the DNS for the folder redirection.

 

So a client connected through the VPN if they try to ping fileserver.YOURCHOOL.ORG.UK or whatever you DNS name is, it gets dropped pings?

 

What happens if you put a conditional forwarder on your Smoothwall DNS for all the .YOURSCHOOL.ORG.UK to go to the correct server? Does it still drop the pings?

 

 

Otherwise could you try redirected folders using IPs instead of DNS names for the off site people? I am aware this might cause you other issues, but it will prove if the issue is DNS related.

  • Thanks 1
Posted
You could add the servername & IP to the hosts file on each offsite client - to save you wrecking any existing offline file caches... easy to test on one machine too!
  • Thanks 1
Posted
So you can VPN correctly and everything works except the DNS for the folder redirection.

 

So a client connected through the VPN if they try to ping fileserver.YOURCHOOL.ORG.UK or whatever you DNS name is, it gets dropped pings?

 

What happens if you put a conditional forwarder on your Smoothwall DNS for all the .YOURSCHOOL.ORG.UK to go to the correct server? Does it still drop the pings?

 

 

Otherwise could you try redirected folders using IPs instead of DNS names for the off site people? I am aware this might cause you other issues, but it will prove if the issue is DNS related.

 

 

Pining directly off site from my home via vpn -> to the file-server works fine, just not when logged into a clients desktop, with VPN and attempting to access the files. Tried on two accounts, "Testers" and gave same issue.

Il give a conditional a go later, should of thought of that!

Looked into Microsoft Direct Access? (https://docs.microsoft.com/en-us/windows-server/remote/remote-access/directaccess/single-server-advanced/deploy-a-single-directaccess-server-with-advanced-settings) we run it here (we also have smoothwall) and it works a treat, no need for VPN etc, might take a day to setup, but then when offsite you can continue to use mapped drives all that stuff as if you were in school.

I shall look into that! After all that looking, never even seen this. They arnt advertising it much are they? =P

Posted
DirectAccess is a technology stack that's being deprecated. It's been replaced with one called AlwaysOn VPN which is simpler to set up. The big difference between the two systems is that AlwaysOn VPN doesn't require IPv6.
  • Thanks 1
Posted

I'm in the process of testing Always-On VPN and also use Smoothwall. I have had it working on a test laptop used at my home (as a basic test to browse home/shared folders and ping servers...which worked). My only issue appears to be connecting the VPN before or during the logon as we use redirected desktops, located on a network share. Obviously when at home without the VPN connected, it can't find the desktop location, so an error accessing the location is shown. When the VPN is manually connected and the desktop refreshed, it works.

 

I was using SCCM's built-in VPN configuration to create and deploy the VPN client connection. Instead I've used Powershell script provided by Microsoft in SCCM as a package to connect the VPN (which also has an auto-connect feature that SCCM's built-in one didn't have). So I'll be testing that this evening.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...