contink Posted October 19, 2006 Posted October 19, 2006 I appreciate I must sometimes sound like a complete n00b at the best of times but in this respect I really am... VPN is a complete mystery to me as I've never had the opportunity to play with it before now... So basically I'd like to get myself prepped up and ready so I can sort out a VPN link from my home/office to school when a VPN link is finally opened up in 6 weeks time. What I'm intending to sort out is a smoothwall box at my end along with the extended defence pre-mod and as far as I've gathered from SchoolsICT I'll be able to VPN throught the coming Bull Network to our site.. but what I'm unsure about at this juncture is whether I'll need to have a similar box at the school end, ready to hook in. Not a problem if I do as I'm intending to put in a proxy server here anyway and smoothie would do the job easily enough. What's key to this thogh is the fact that I have no partner who I can plonk at one end while I test and tweak the other so I need to get this pretty much on the money.... So, can anyone share a fairly idiot proof (no prizes for spotting the idiot in question ) guide to getting organised so minimal bug testing is required? Hand holding much appreciated.
Geoff Posted October 19, 2006 Posted October 19, 2006 Do schoolsICT run a VPN server or are they expecting you to run your own?
contink Posted October 19, 2006 Author Posted October 19, 2006 Do schoolsICT run a VPN server or are they expecting you to run your own? That'll be my first question to ask them I guess...
contink Posted October 19, 2006 Author Posted October 19, 2006 How many users are going to use the VPN? Just me... This is solely so I can handle the mundane "the print queue is borked again" style problems up to GPO tweaks and the like... Basically anything that doesn't really need me to jump into a car and drive to the school (which is nearly an hour away).
djm968 Posted October 19, 2006 Posted October 19, 2006 RDP would be far easier to implement. Get port 3389 open and pointed to the PC or server on your LAN, make sure you have selected the "allow users to connect remotely to this computer" option and bobs your uncle A lot less hassle than VPN... trust me!
contink Posted October 19, 2006 Author Posted October 19, 2006 That had occured to me but I suspect SchoolsICT are going to require me to VPN in so that option may not be available. i'll have to drop them a line and find out more but either way I would still like to get a grip on VPN as much for self educations sake.
djm968 Posted October 19, 2006 Posted October 19, 2006 I agree with the VPN for your own developement, but if SchoolsICT block you (I would fight them all the way) then I would install a seperate broadband connection and bypass them altogether. I have done this at a few schools and you can justify the additional cost becuase it gives you redundancy in the event that the main internet connection fails.
eean Posted October 19, 2006 Posted October 19, 2006 Have you thought about using http://www.logmein.com It's free and works through firewalls and NAT etc... You just tap into their address and you can remote control the server, or whatever. Pro version allows you to do file transfer etc.. and ain't a lot of cash. Some LEAs ban it, but it works really well here (Essex).
Geoff Posted October 19, 2006 Posted October 19, 2006 I agree with the VPN for your own developement, but if SchoolsICT block you (I would fight them all the way) then I would install a seperate broadband connection and bypass them altogether. Be careful here. We can't do this in Lancs because it's a breach of our CLEO broadband contract. I expect the contract with SchoolsICT will be similar?
ITWombat Posted October 19, 2006 Posted October 19, 2006 RDP would be far easier to implement. Get port 3389 open and pointed to the PC or server on your LAN, make sure you have selected the "allow users to connect remotely to this computer" option and bobs your uncle A lot less hassle than VPN... trust me! Caereful with raw RDP. There's quite a few mentions on the net that it might be vulnerable to Man in the Middle attacks because there is no autentication of server identity.
Rozzer Posted October 20, 2006 Posted October 20, 2006 Our council would be well annoyed if we had another internet connection also the connection would not be filtered by the LEA. Ross
djm968 Posted October 20, 2006 Posted October 20, 2006 Most councils I have worked with have not had an issue with this and it did not breach any existing broadband contacts. I have had to do risk assessments and prove that their are no security issues but with a well configured firewall there is no risk. As for LEA filtering....... what filtering? If you are going to use it for kids, which you are not, it is only there for remote access, filter it yourself. LEA's take a large chunk of money off you, throws it at an ISP who rubs their hands together and provides overpriced broadband connections while dictating what you can and can't do with it and when you mention the word SLA they suddenly loose the ability to comprehend English
Teth Posted October 20, 2006 Posted October 20, 2006 We have an outside net connection here too for admin and staff access. We're filtered by C2K in northern Ireland and they're filtering choices tend to be "intresting". Its just 2meg ADSL but it lets me RDP in and lets teacher or upper school pupils use things like google images that the C2K filter blocks. I also hope to setup a squid, dansguirdian box over half term to allow some filtering on it so that I can add it to classrooms to do the online clait + exam.
djm968 Posted October 20, 2006 Posted October 20, 2006 I also hope to setup a squid, dansguirdian box over half term to allow some filtering on it so that I can add it to classrooms to do the online clait + exam. Good choice how about setting up two squids and load balaced the connections you will also have redundant internet access!
Teth Posted October 20, 2006 Posted October 20, 2006 That I'd love to do but under the C2K system we have no admin access to anything on they're managed network. No access to they're router or proxy, switches or even client setup. Thats the reason we have 2 networks. Mine which the SMT loveingly referre to as the "legacy" network, and the one provided by C2K northern Ireland. My one concern with providing internet access on the "legacy" ( I hate that word) network is that thats really the only reason a teach voluntarily uses the C2K machines with a class. I think my 5 suites may become very over subscribed.
djm968 Posted October 20, 2006 Posted October 20, 2006 With squid, you only need the proxy address and port to do round robin load balancing. cache_peer proxy1.1stISP.net parent 80 7 no-query round-robin weight=10 no-digest cache_peer proxy2.2ndISP.net parent 8000 7 no-query round-robin weight=10 no-digest
contink Posted October 20, 2006 Author Posted October 20, 2006 Not wanting to slap any wrists here but we are drifting a mite off topic and much as I want to discuss the other bits that have popped up I reckon each could use a split or seperate topic to get over properly. To get back to the VPN thing though... My primary concern is the security side of things and I'd rather have to spend some time with my head stuck in a book, on here asking daft questions and getting to grips with it all than trying an end run that may end with me and egg applied to face. As to a seperate connection, it's been considered but in truth we're now reaching a point where the head wants me to explore whether we are actually tied in to any contract and what movement we have for supplying our own broadband link... £4k for an unreliable 2mb connection that goes snafu whenever there's a storm, lots of rain and has poor filtering (ie: pretty much everything is blocked!) means we're wondering why we don't just go to a bonded ADSL link and a smoothie with content and security filtering that we can control... It'd certainly be a LOT cheaper and less prone to "It's the other guys fault" support ping pong.. :? Anyway... I'm drifting OT myself now.. so back to VPN...
djm968 Posted October 20, 2006 Posted October 20, 2006 Not wanting to slap any wrists here but we are drifting a mite off topic and much as I want to discuss the other bits that have popped up I reckon each could use a split or seperate topic to get over properly. Sorry, got a little carried away there. :oops:
contink Posted October 20, 2006 Author Posted October 20, 2006 Not wanting to slap any wrists here but we are drifting a mite off topic and much as I want to discuss the other bits that have popped up I reckon each could use a split or seperate topic to get over properly. Sorry, got a little carried away there. :oops: LOL... no worries... just very conscious that other people will miss the topic of discussion and not get their rant/rave/drivel in.. The whole "if you can't work with them, work round them" thing is seriously valid so go forth and start the topic
djm968 Posted October 20, 2006 Posted October 20, 2006 Here it is, and thanks for the title! http://www.edugeek.net/index.php?name=Forums&file=viewtopic&t=4742
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now