Jump to content

Recommended Posts

Posted

Hi,

 

I am looking for a cheap vpn system. I did search the forums but it has been a while since anyone asked about vpn’s

 

*It must be very easy to setup as I only work at the school 3 hours a fortnight.

*I do have a spare 2008r2 server

*very limited funds

*Web based if possible.

 

Obviously a hardware vpn would cost way too much but would consider second hand hardware or some form of appliance that turns a computer in to a vpn.

 

Do not want adito or openvpn

 

Thanks for any advice.

Posted

It would be for 10 users.

 

I could probably push them to a few hundred pounds if I make a good case for it.

 

I did have a play with home access a year or so back but never got it working. Might have another bash at that one.

 

MS VPN has always confused me as they seem to do different versions TG web apps SSL etc. None of which I have used before. I only need basic access to the staff folders and it needs to be easy for the staff to use (Web based would be nice). If you can recommend a way of doing this using MS software that would be handy.

Posted (edited)

Since you have 2008R2 you could use DirectAccess, which assuming they're on Windows 7 clients, would be free... and even easier to setup if you could push to a Server 2012 upgrade.

 

I'm looking to do this today actually for a few of our staff.

Edited by Blue_Cookeh
Posted

We have a VPN here with 100 users on it, just set one up this morning also at the same company with an additional 50 users, We use a free routing platform (PC Based) called PfSense, it has OpenVPN built in and the console is all web based, very easy to setup and configure - infact it took me 20 minutes to setup the VPN for all of our users and never had an issue with it since.

 

VPN Capability OpenVPN - PFSenseDocs

PfSense Open VPN Tutorial (with Narrator) - YouTube

 

it even has the OpenVPN Client export utility which is very nice, it basically creates an installer for each person then you give them it and they install it and that's it, they open it when they want to connect.

Posted
You don't need ISA or TMG to use the MS VPN, it is just a role in server 2008, it does use CALs though so any connection to it technically counts. If these are staff laptops then it does not matter as they should already be licenced with CALs anyway.
Posted
Since you have 2008R2 you could use DirectAccess, which assuming they're on Windows 7 clients, would be free... and even easier to setup if you could push to a Server 2012 upgrade.

 

DA is not an option as it needs Windows 7 Enterprise, Windows 7 Ultimate, the school have pro.

Posted
I do like MS VPN BUT - I'm not sure how secure it is... At least with OpenVPN & PfSense you can configure firewall / VLAN options for it which is handy.

 

It's hard to make a choice with out actually using both and getting ports opened with our LA takes forever.

 

Decisions, decisions.

Posted
I do like MS VPN BUT - I'm not sure how secure it is... At least with OpenVPN & PfSense you can configure firewall / VLAN options for it which is handy.

 

Google Image Result for http://www.hagen-bauer.de/blog/201004/201004-pfsense-openvpn2.png

 

It can be secure but you need to use the right settings, i.e. not PPTP, rather IPSEC or HTTPS. HTTPS requires an SSL cert but only requires 443 open, the others require a bit more. DirectAccess is nice and can be tunnelled over 443 but is kinda complex at the moment and far better implemented in 2012.

 

You are just as likely to end up with an insecure connection with OpenVPN if you configure it wrong. Something like Untangle can simplify but you also need to deploy software to use it and they need to install it as Admin for it to actually work. You can also put rather heavy restrictions on VPNed traffic restricting it to certain protocols or even a certain VLAN depending on how your network adapters are configured if you need to. Again, it's all down to the configuration.

 

As to Business, if you have a volume agreement you can use Enterprise, it is just a SA benefit and much better for actually managed networks as it includes everything unlike business.

Posted

The problem with conventional vpn in schools is the LA who ultimately dictates what can be reached or not as the case may be.

 

SSL VPN is by far the easiest to implement in many cases as they don't need to know what it is that your tunnelling to on port 443

The work on almost every platform with iPad and Android supported and even if you only have one IP/port available they can be configured to "Pass Thru" specific services.

Eg. SSL VPN appliance and Exchange server can share one port 443 instance using a method of L4 routing.

 

We have always used the Sonicwall appliances for this as they can provide both the tunnel end point, a customisable reverse proxy for remote access and granular policy controlled webdav

 

The downside is that at £600+ for the SRA1200 it's way over your budget but if you work on the advantages rather than just cost you can normally easily justify the outlay to the SMT

Once they get to use them they quickly realise their true worth:-

 

Such as RDP access without the need for an RDP server or licensing by using your local PCs and software.

Remote access to files and resources.

Windows, Mac and mobile support.

 

Other vendors include Barracuda, juniper, Draytek all offer variations of the same thing.

Posted
I completely agree with twin turbo. A Draytek Vigor will do this for you no problem. If you need help setting it up let me know.

 

Dave

 

+1 for the Draytek, I use the IPSec/L2TP VPN on their Vigor 2830 router for remote admin :)

 

(and they just released a firmware update to enable IPv6 support, score!)

Posted
M25man. SRA 1200 Looks like a fantastic product. I have found all the setup demos but really need to see what the teacher will see when logging on to the system. Can you explain how that works and what they see. For example do they run a connect client or visit a website to make the connection.
  • 3 weeks later...
Posted
DrayTek Vigour Router, Only £180 will do 10 VPN users fine.

 

Rob

 

Do you have to set up each user on this though? can only get it working if i set it up ser username!

  • 2 weeks later...
Posted
DrayTek Vigour Router, Only £180 will do 10 VPN users fine.

 

Rob

 

Ooh that looks nifty. Which one? What features give you your VPN-like access?

 

VPN on the router is not something I (fully) understand, but if you've got time for a summary I'd be interested...

Posted

An ipsec dial-in will be fine. The Draytek comes with software that makes it nice and easy or you can use mac / windows vpn dial-in tool.

 

The Draytek 2830 is fine if you have ADSL or cable or leased line as it's got 2 x WAN ports. Get the N version if you want wireless too.

 

We sell them btw so if you want me to get you one do give us a call :)

 

Thanks

 

Dave

Posted
M25man. SRA 1200 Looks like a fantastic product. I have found all the setup demos but really need to see what the teacher will see when logging on to the system. Can you explain how that works and what they see. For example do they run a connect client or visit a website to make the connection.

 

Sorry for the late response the World Cup Qualifiers meant a 20 day break and a Datacentre move and office refurb, the end users get an AD integrated login.

 

The next screen is a customisable menu we normally have an RDP option (with WOL) that allows the SLT members to access and login to their own PC's thus negating the need to host/run an RDS server.

The technician can have access to the VPN option, others whatever you want hem to have.

If you have an RDS server this can be offered.

External contractors can be given a dedicated portal or non domain account on the SRA with restricted access to any kit they need to maintain .

 

The end result is a Secure VPN , Remote Access Solution (that doesn't need An RDS server or licensing if your happy to send users to an unused PC), Remote File Access all operating on the single SSL port open on your firewall.

It's also possible to use SSL offloading at Layer 4 so all traffic routes to the SRA except for instance an Exchange Server this would pass right through to the desired target server.

 

I have been using these for years and when you look at what it provides for the cost its really easy to sell it to the SMT.

 

The only negative thing that I can say about them is that they are now owned by Dell, which means that once your their list they will not leave you alone until they own you....

Posted

You should be able to setup remote access services and tunnel over 443 is called RAS I think.

 

if not then Watchguard units are good so and the juniper ssl appliances although they are expensive.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...