Posted on 2007-11-15
Last Modified: 2010-04-21
Looking for recommendations.
Here's the setup.

We have 2 offices directly across the street from each other.  Both have DSL, one office connects to the other using terminal services, we have a rather large application to run and only works really well when run locally.  I'm having issues with the VPN tunnel I created, it keeps disconnecting.  

I have a LinkSys BEFVP41 on both sides and have set up the VPN, but I have to keep fiddling with it to make it work.  It goes down 2 or 3 times a day, totally unacceptable.

So my question is, what do you recommend I use to handle the VPN tunnel.  What hardware is out there (if any) that could be a DSL modem, firewall and can create VPN tunnels all in one.  The only caveat is it must all cost under $1500.  I need a stable connection that can optimize speed, and semi-easy to use.

Comments please, and thanks.
Question by:djanoian
  • 3
  • 3
  • 2
  • +1

Expert Comment

ID: 20291113
It may not be your hardware causing the problem. It could very well be your ISP. If one of your locations is on a dynamic IP plan - a VPN should drop in the event of a change in origination IP. Additionally, a VPN is encrypted and will add overhead to the connection, effectively making it appear slower. Coupled with a spike in use of available bandwidth could have the same effect as dropping the connection.

Why use a VPN? My suggestion would be to setup a wireless bridge between the locations. SInce they are right across the street line of sight and distance should be no problem. That would give you a minimum of an 11MB routable connection. Most Linksys equipment will act as a bridge so cost can be minimal and you already are familiar with the product line.

I am using a couple of these for temp connection up to a mile ( They are self contained, work good, weatherproof, power over ethernet and about $250 each.

Expert Comment

ID: 20292295
Bravo moondist. My thoughts exactly.
LVL 57

Expert Comment

ID: 20292322
How far is "across the street?"  I agree with moondist's idea about using Wireless, but I would suggest getting 802.11n equipment that may give you 100Mbps connection and most likely a more reliable connection.

Author Comment

ID: 20295349
We had tried the wireless connection first, its only about 70 feet, both buildings had directional antennas pointed to each , 2nd floor to 1st.  It seemed terribly slow, probably because we configured it incorrectly.   But if I had to keep the DSL ( both are Static IPs), is there any recomended hardware?
Netscaler Common Configuration How To guides

If you use NetScaler you will want to see these guides. The NetScaler How To Guides show administrators how to get NetScaler up and configured by providing instructions for common scenarios and some not so common ones.

LVL 57

Accepted Solution

giltjr earned 125 total points
ID: 20295737
My assumption is that the VPN may be "breaking" when you have high link utilization to the Internet.  VPN's are very sensentive to latency.

I am suprised the wireless betwee the sites seemed slow.  With ADSL, I am assuming it is ADSL, most likely your "uplink" speed would be limited to 384Kbps or 512Kbps on both sides, which would limit your speed for all transfers in any direction to 384 or 512 Kbps.  With wireless you should have been able to get at least 11 Mbps as moondist said, so you are taking at least 20 times the speed.  Now, 11 Mbps would be half duplex which would get you down to the 7-8 Mpbs range, but that is still faster than ADSL uplink speeds.

With 802.11n you can get full duplex, and if you get 100 Mbps this would give you LAN like speeds between the two sites.

Author Closing Comment

ID: 31409382
OK.. you've convinced me.  Time to take a look at the wireless option again. With that said, any ideas on the best wireless equipment to use.  Again, you've got a lot to play with here, $1500.

Author Comment

ID: 20295759
OK, you've convinced me.  Time to take a look at the wireless option again.  Since I still have some money to spend ($1500) do you have any suggestions on the better equipment I could use.

Expert Comment

ID: 20295778
70' is nothing. That had to have been a configuration issue. You should really investigate and try again. Right now I am sitting in my home on a wireless connection using similiar equipment to the one I posted above. The other access point is over 3 miles away.  If both your units were low end and behind glass, that could limit your distance greatly. The form factor I posted is weatherproof and designed to be outside and is only one of several brand choices. 802.11a, b, g , or n wouldn't matter - any of them would be much faster than a DSL VPN.

Another benefit would be to drop one DSL line as both offices could then use the same internet connection. Then your budget could afford a better firewall. (2 wireless bridges ~ $500, 1 Fortinet Fortigate 60 ADSL ~$995, optimized, secure and more  manageable network ~ Priceless)

Remember, most DSL is "up to" speeds and async (D/L faster the U/L). Since your connection is roundtrip, your upload speed is the max you could ever expect to achive (Office A's download = Office B's upload). Then once you add encryption overhead, you may as well just use a dial up between the offices. But if that is the direction you need to head, my personal recommendation is the Fortinet Fortigate 60 ADSL (but 2 of them will bust your budget).

Let me know if you want me to expand on anything. Good luck.
LVL 57

Expert Comment

ID: 20298421
I would have to do some looking.  Do you have the ability to mount outside antennas? Do you want to mount outside antennas?  It will make it more expensive, but they do work better than going through windows.  However with 802.11n and only about 70 feet of distnance I don't think two windows will make that much differences.

If you can't, I am assuming that you have windows that face each other between the buildings.  Do you have a spare PC laying around?

All you really need is one 802.11n AP and then get a PC with an 802.11n card.  Setup the PC to be a router between the two sites.  Put the AP and the PC as close to a window as possible.  And, of course, you need to setup the wireless connection with the standard security setup.  You can get different antenna for the PC so that it can sit on something right in-front of the window.  Depending on the model and brand the AP, the card for the PC, and the antenna should be under $500, easily.

You would need to look at the current utilziation of your ADSL links.  moodist's idea of dropping one of the them to help save money is right on target as long as you are not running either of the links at or near capacity.  If you are running one or both close to capacity, are there other ADSL speeds?  Some ADSL providers offer 2, 3, or even 4 different options, if you are running say 1500/384 in two offices at $50 per month, but they offer 3000/768 for $70 per month, you could drop one, upgrade the other one and save $20 per month.

If you still have your old wireless equipment, you may want to try it again.  You could always ask another question here for ideas on how to improve perforemance.

Featured Post

PRTG Network Monitor: Intuitive Network Monitoring

Network Monitoring is essential to ensure that computer systems and network devices are running. Use PRTG to monitor LANs, servers, websites, applications and devices, bandwidth, virtual environments, remote systems, IoT, and many more. PRTG is easy to set up & use.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
iPad Won't Connect 16 74
Cisco ASDM device NT domain question 4 33
Packet Tracer Router to Router 10 59
New TWC modem/router breaks network 53 69
Creating an OSPF network that automatically (dynamically) reroutes network traffic over other connections to prevent network downtime.
Shadow IT is coming out of the shadows as more businesses are choosing cloud-based applications. It is now a multi-cloud world for most organizations. Simultaneously, most businesses have yet to consolidate with one cloud provider or define an offic…
After creating this article (, I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
Windows 10 is mostly good. However the one thing that annoys me is how many clicks you have to do to dial a VPN connection. You have to go to settings from the start menu, (2 clicks), Network and Internet (1 click), Click VPN (another click) then fi…

911 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

21 Experts available now in Live!

Get 1:1 Help Now