simple vpn stuff
Author
Discussion

davidd

Original Poster:

6,677 posts

308 months

Thursday 30th September 2004
quotequote all
A customer has a main office in cambridge, they have 4 or 5 people who need vpn access to it. Currently the office and a couple of them have bt adsl, whilst the rest have NTL cable.

Assuming they can all get ADSL, is there a simple off the shelf offering from an isp to give them a company VPN with no pissing about?

D

rsvmilly

11,288 posts

265 months

Thursday 30th September 2004
quotequote all
We have a hardware firewall which takes care of the office end (Symantec) and use Symantec VPN client - does tend to bugger up some software though; like ZoneAlert amongst others.

neil_cardiff

17,113 posts

288 months

Thursday 30th September 2004
quotequote all
You need to bear in mind the sort of work they will want to do over this link, as ADSL doesn't really cut it that well with VPN's.

Because the upload is generally 256Kb/sec max, you will only see that or less in terms of actual operating speed.

Throw big emails, file transfer etc over it and it'll grind to a halt.

Consider SDSL for VPN traffic, as this give you the upload as well as download speed. Also basic NTL cable doesn't allow VPN'ing unless you have the business connection (although doesn't stop you from doing it).

Your best bet (if you haven't already done it) is a firewall that works, and works with IPSEC etc and use end user software like SafeNet Soft Remote for the VPN initiation and authentication.

Be careful, and make sure that every user/laptop is patched and updated to the hilt, 'cos if anyone is infected or whatever, they can infect the whole network etc. Also think in terms that if a 'road warrior' is infected with a trojan then any hacker can use that machine to access your tightly firewalled network with no detection, so consider software firewalls on any laptops.

Its a very big thing to open your network up for VPN traffic, and not one you want to get wrong - I know, I've learn't the hard way...

Neil

Edited to add: Any solution that gives you VPN access with no arsing about should be very cautiously looked at - would you give someone keys to your house without first ensuring that you trust them and they know hoe to lock up afterwards?

>> Edited by neil_cardiff on Thursday 30th September 10:50

davidd

Original Poster:

6,677 posts

308 months

Thursday 30th September 2004
quotequote all
Neil

Interesting post, thanks. The traffic won't be a problem, 256kb is fine for what they need.

I'll check out the clients you recommend.

D