VPN Domain Access over pptp

Hi,

One of our offices is using RAS dialup into a Small Business Server 2000.
Problems include connection dropping, failing to call back and limited to the 2 ISDN channels for 5 staff.  Also problems copying files to local computer.

Router
  |
Switch
  |
SBS2000, Workstations
  |
RAS

I am considering changing this as follows as well as upgrade to SBS 2003

Router
  |
VPN Firewall
  |
Switch
  |
SBS2000, Workstations

Users will connect mainly via ISP dialup but hopefully later broadband, and need to authenticate onto active directory to have their home drive mapped.

Considering one of the Cisco PIX firewalls and the following setup.

http://www.cisco.com/en/US/products/hw/vpndevc/ps2030/products_configuration_example09186a00800b6099.shtml

Is this the best way to do this and if so, which PIX or other hardware offer the best value for money.  There are currently 5 users.  Not sure if this is likely to increase in the near future at least.

Any advice appreciated.

Jess
LVL 8
jessmcaAsked:
Who is Participating?
 
Rick HobbsConnect With a Mentor RETIREDCommented:
Sorry, hit 'Submit' too fast.   Wanted to add that Cisco is the gold standard for Network hardware in a business environment.   You could use Netgear, Linksys, D-link, Sonicwall and many other excellent products, but there are more engineers familiar with the Cisco products than any other. The PIX-501 bundle includes licensing for 50 users.  So you have more than enough growth capability.
0
 
Rick HobbsRETIREDCommented:
With so few users, you would be fine with PIX-501-50-BUN-K9.  
0
 
jessmcaAuthor Commented:
Thanks rickhobbs

Are you aware of any problems with the AD remote authentication using the client software with the 501?
Probably the following would be the best configuration using the PIX DMZ.

ADSL Router
  |
VPN Firewall
  |
SBS2003 ISA 2004
  |
Switch
  |
Workstations
0
Improve Your Query Performance Tuning

In this FREE six-day email course, you'll learn from Janis Griffin, Database Performance Evangelist. She'll teach 12 steps that you can use to optimize your queries as much as possible and see measurable results in your work. Get started today!

 
Rick HobbsRETIREDCommented:
None at all.  It is easy to setup and maintain the VPN for either group or individual user access.
0
 
Rick HobbsRETIREDCommented:
As for the config, you can:

ADSL Router
  |
VPN Firewall
  |
SBS2003 ISA 2004
  |
Switch
  |
Workstations

or

ADSL Router
  |
VPN Firewall
  |
Switch-----------------------------
 |                                           |
SBS2003 ISA 2004             Workstations

Either will work fine.  If you have daul LAN cards in the server, either use the first or, if possible, team the NICs and use the second.
0
 
jessmcaAuthor Commented:
Thanks Rick,

Have never considered teaming network cards before.
Is there a security benefit or just performance increase?

Jess
0
 
Rick HobbsRETIREDCommented:
Performance and failover.  If one fails, the other should keep working.
0
Question has a verified solution.

Are you are experiencing a similar issue? Get a personalized answer when you ask a related question.

Have a better answer? Share it in a comment.

All Courses

From novice to tech pro — start learning today.