Inter-Site VPN File Transfer - Good Practices?

I have 3 sites connected with site-to-site VPNs using RV042.
The service is ADSL with 3000kbps down and 500kbps up.  
So, file transfers from site to site are  necessarily limited by the 500kbps upload speed that's available.
(We're considering upgrading the speeds and that's one good reason for this question).

I'm in the middle of running some tests because of the following:
- I know that external ftp transfers do work at the limits of the ADSL
- Windows file transfers through the VPN, like copy and paste, are *very* slow.  They seem to start up quickly enough but the tranfer rate seems very low.  (I'm measuring this now.)
- I want to compare doing Windows transfers (as above) to doing ftp transfers over the VPN.
In the end, we want to do useful/responsive file sharing between sites.

One consideration would be to set up a file server at one site and then use ftp over the VPN between sites but I'm not sure it's worth the trouble or if using ftp is going to be any better than the Windows transfers or if there isn't even a better way to get decent transfer rates.  I'm not even sure I can sell this approach to the users.

What are good practices for site-to-site file sharing like this?
LVL 27
Fred MarshallPrincipalAsked:
Who is Participating?
I wear a lot of hats...

"The solutions and answers provided on Experts Exchange have been extremely helpful to me over the last few years. I wear a lot of hats - Developer, Database Administrator, Help Desk, etc., so I know a lot of things but not a lot about one thing. Experts Exchange gives me answers from people who do know a lot about one thing, in a easy to use platform." -Todd S.

arnoldCommented:
Look at DFS if all sites are AD and members of the same AD domain/forest.
win2k3 R2 or newer.

You would have a DC or a RODC with a local Fileserver that is a target as well as a member of a replication group for a share \\domain\sharename.
The DFS replication can be configured to manage the amount of bandwidth it uses for the replication such that it does not saturate your outbound connection.
0
MaestroOO7Systems AdministratorCommented:
Hi,

I have woked for two big IT Companies, the one used FTP and another used DFS.

Something like this:

http://filetrans.be.getronics.com/

users log in, upload something,
Send link to someone else,
the other gets the mail and can download with the tem credentials in the e-mail, so it 's also for external use.
0
Fred MarshallPrincipalAuthor Commented:
This is a Windows XP Pro (mostly) peer to peer network with shared files - no server OS system on it, no DC, no AD.
Inter-site addressing by IP only, no name service inter-site.  So, inter-site computers are not in My Network Places.
One way (the best/only?) to see a remote computer is
Start/Run   \\[IPaddress]
Then, from this display of shared folders:
- Copy paste
- Map a folder as a local drive. Copy/Paste to local.
Or:
ftp
To me, setting up ftp servers on all the peers seems like way too much work and maintenance and the interface probably isn't familiar enough to the users.
But, at some level, setting up a file server for ftp might make sense.

Another concern is "version control" if files are actively shared amongst users.  There is no discipline that I know of that is currently in place.  
0
What were the top attacks of Q1 2018?

The Threat Lab team analyzes data from WatchGuard’s Firebox Feed, internal and partner threat intelligence, and a research honeynet, to provide insightful analysis about the top threats on the Internet. Check out our Q1 2018 report for smart, practical security advice today!

arnoldCommented:
You could setup a linux based file server with samba and then have rsync on each configured to synchronize the data.
You could use subversion, but the problem is that it either will be in a single location. or you would have to look at trying to synchronize deal with subversion at each location and then have each synchronize with the other which makes things complicated.
The other option is to have a process that while doing sync preserves/saves a copy to subversion in one location.
0
Fred MarshallPrincipalAuthor Commented:
We've decided to upgrade the links.  So that will help.

I ran some tests and it appears that ftp isn't all that much better than Windows file transfers in general.  Is there experience with VPN inefficiency and choice of encryption methods?  I know there's some inefficiency there....
0
arnoldCommented:
The VPN has added encryption overhead.
It all depends on where this transaction takes place.
i.e. on the systems or on an appliance.

computer <=>VPN/Router<=> internet <=> VPN/router  <=> computer
computer <=>Router<=> internet <=> router  <=> computer
The VPN is between the computers such that each computer has to encrypt/decrypt the data as well as process it.
www.speedtest.net has a tool (mini speedtest) that you can install on your web servers then access it from each side and get an estimate for the transfer speed.
You can see whether the speed within the LAN is as good as it can be i.e. ~100MB for 100MB interface or ~1000MB for 1000MB.  You may have a situation that the networking is not maximized for network applications.

 
0

Experts Exchange Solution brought to you by

Your issues matter to us.

Facing a tech roadblock? Get the help and guidance you need from experienced professionals who care. Ask your question anytime, anywhere, with no hassle.

Start your 7-day free trial
Fred MarshallPrincipalAuthor Commented:
This is being done site-to-site with dedicated hardware. RV042s.
The choices for encryption, etc. are many - how much does it matter re: VPN efficiency?
0
arnoldCommented:
The resource needs for VPN are higher than a data transfer over a non-VPN connection.
The other items that go into it is how loaded the VPN Router is.i.e. if you have high activity on your LAN/WAN besides the VPN, you may want to configure a QoS policy to assign a higher preference to the VPN versus other traffic on your LAN.
0
Fred MarshallPrincipalAuthor Commented:
No answer dealt with VPN encryption selection vs. performance - maybe that's not too relevant.
0
It's more than this solution.Get answers and train to solve all your tech problems - anytime, anywhere.Try it for free Edge Out The Competitionfor your dream job with proven skills and certifications.Get started today Stand Outas the employee with proven skills.Start learning today for free Move Your Career Forwardwith certification training in the latest technologies.Start your trial today
System Utilities

From novice to tech pro — start learning today.