How should i plan the network for small branch office with only 5 pcs???

Posted on 2010-01-09
Medium Priority
Last Modified: 2012-05-08
Dear experts

Main Office:
Using:Microsoft AD, DHCP, DNS
Using: Juniper N5GT
Bandwidth: ADSL 10M download & 1M upload bps

I will need to set up the branch office with 5 PCs. I am planning to VPN both office which i will connect N5GT to SSG5.

1.Is it a good idea (with only limited bandwidth) for me to set the SSG5 (branch Office) as a DHCP agent so PCs in the branch office can be served by DHCP server in the main office????????

2. Would i be able to serve the branch office using AD, DNS, Antivirus Servers in branch Office

Question by:Gordon Tin
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 3
  • 2
LVL 97

Expert Comment

by:Experienced Member
ID: 26273060
You can set the branch office Netscreen to be the DHCP server for the branch. At that point, the branch office users get an IP address and can use the internet independently of head office.

Now set up a tunnel between the two Netscreen devices and then branch office users have all the services they need from the head office server.

Be sure (since you are using ADSL) that you set the MTU in the routers at 1492. Default is 1500 and is not efficient for VPN.
... Thinkpads_User
LVL 21

Accepted Solution

Rick_O_Shay earned 1500 total points
ID: 26273531
It may be a question of whether or not you want to maintain 2 DHCP servers and do you want those users to get to the internet bypassing the corporate firewall, IDS, etc. I realize that the administration part isn't much with just 5 devices but can the remote VPN based DHCP server do everything you need like the main one? I am not a server guy so I don't know how much Microsoft AD relies on the local DHCP and DNS servers for things relating to the clients they are responsible for.

DHCP isn't going to consume that much bandwidth if you are relaying it through the VPN tunnel and if the PC has not gotten its IP address yet it isn't going to be sending anything to the Internet anyway.

The second part is do you want to get DNS and Internet access through the corporate structure or locally?

To your question number 2 the answer is yes.

Author Comment

by:Gordon Tin
ID: 26333794
I will set the branch office Netscreen to be the DHCP server at the beginning stage until Microsoft Server is ready to pick up the DHCP work.
I have the following questions regarding using SSG5 as DHCP server.
1.    Do i have options in netscreen to provide DHCP service only for certain IP range.
2. For example, i have trust ( & subinterface in trust (
Does Netscreen-SSG5 is capable of serving both networks?
Please kindly share yr expert experience.  
Will your db performance match your db growth?

In Percona’s white paper “Performance at Scale: Keeping Your Database on Its Toes,” we take a high-level approach to what you need to think about when planning for database scalability.

LVL 97

Expert Comment

by:Experienced Member
ID: 26334833
For question 1: Yes.
For question 2: I do not know.

The branch box provides DHCP for the branch location. The tunnel back to the main office is in the static range of both boxes. And presumably the Server at the main location will be the DHCP server for the main location.

... Thinkpads_User

Author Comment

by:Gordon Tin
ID: 26339821
Let me revise my question...............
I am NOT trying to  provide DHCP through the tunnel back to the main office.
2. For example, i have trust ( & subinterface in trust (
Does Netscreen-SSG5 is capable of serving both networks?

Please kindly share yr expert experience. .............................  

Author Closing Comment

by:Gordon Tin
ID: 31674974
ok Links

Featured Post

 [eBook] Windows Nano Server

Download this FREE eBook and learn all you need to get started with Windows Nano Server, including deployment options, remote management
and troubleshooting tips and tricks

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

How to set-up an On Demand, IPSec, Site to SIte, VPN from a Draytek Vigor Router to a Cyberoam UTM Appliance. A concise guide to the settings required on both devices
This article explains the fundamentals of industrial networking which ultimately is the backbone network which is providing communications for process devices like robots and other not so interesting stuff.
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
Windows 10 is mostly good. However the one thing that annoys me is how many clicks you have to do to dial a VPN connection. You have to go to settings from the start menu, (2 clicks), Network and Internet (1 click), Click VPN (another click) then fi…
Suggested Courses
Course of the Month14 days, 10 hours left to enroll

771 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question