Solved

Site to site VPN

Posted on 2011-02-14
4
1,260 Views
Last Modified: 2012-05-11
Hello everyone. I have a question, and would be grateful for some help. It's like this.

I inherited a pre-existing condition of network in one company. Company has offices in two locations, and what is been suprising two (separate) domain's with no vpn between them. Domain subnets are different - location 1 is 192.168.1.0/24, and location 2 is 192.168.0.0/24. Location 1 has about 50 clients with one win 2003 DC and one linux gateway/firewall. Location 2 had about 20 clients with only one win2008 DC (was gateway WITHOUT firewall or anything) and i added separate Linux that is now gateway/firewall for that domain. Both locations are behind ADSL modem (no routing or VPN possible) with dynamic public IP (we have dyndns service).
The question is, what would be steps for creating site to site VPN between those two location if possible using only what is already there. I would be more willing to create routers on separate linux machines rather than buying hardware vpn capable routers.
And also, what would be best practice for domains, to leave as they are or to put everything in single domain, or promote location 2 domain as child domain on location 1 domain... Many questions but i draw a diagram below for better realizing, i more or less put everything in it (VPN as it should be is in center of image) as my English is not as good, so me typing this question is pretty challenging.

Thanx in advance.



 vpn wanna be
0
Comment
Question by:skrga
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 2
4 Comments
 
LVL 11

Assisted Solution

by:DIPRAJ
DIPRAJ earned 250 total points
ID: 34894184
way:-
1. make different network for two different networks(if possible same subnet)
2.go for site to site ipsec based vpn
you can use linux/vpn box/firewall
3.if you don't want to buy  extra device..then please use same subnet for two different location...
0
 
LVL 5

Author Comment

by:skrga
ID: 34894296
diprajbasu thanks, if not too much of a problem little more info:

1. make different network for two different networks(if possible same subnet)
Does that mean that addresses should be for example Location 1 192.168.0.1-192.168.0.100 and for location 2 192.168.0.101-192.168.0.254 ?
What about domain names (leave like it is..)?

2.go for site to site ipsec based vpn
you can use linux/vpn box/firewall

Do you maybe have some example how to do it behind ADSL with dynamic ip ?
(Should i have static public ip on locations or it would work with dyndns name ?)

Thanks in advance.




0
 
LVL 3

Accepted Solution

by:
paulwquinn earned 250 total points
ID: 34898309
If you're looking for a low cost solution, look at setting up what you want using OpenVPN

Take a look at:

 How to bridge networks with OpenVPN
Joining Networks with Open VPN
OpenVPN - Site-To-Site Routed VPN Between Two Routers

There are also relevant e-books available. See:

Open VPN 2 Cookbook
Beginning OpenVPN 2.0.9

In terms of best practises for domains, I think of medicine's "Primum non nocere" (Latin for "First, do no harm") and the American idiom "If it ain't broke, don't fix it".

In other words, if you inherited the current infrastructure, and it's currently working correctly, and you can achieve what you want (VPN between sites) with minimal modifications to the existing infrastructure, then I would recommend that as the way to go.Best practises in network design are for the design phase, not the post-implementation phase. You would need a compelling reason to change the current set up.

If you can set up what you want without incurring a lot of overhead/cost using your current subnets, why change them?

Anyway, hope that helps.
0
 
LVL 5

Author Closing Comment

by:skrga
ID: 34898554
Thank you both. You gave me a good place to start.

So long!
0

Featured Post

Manage your data center from practically anywhere

The KN8164V features HD resolution of 1920 x 1200, FIPS 140-2 with level 1 security standards and virtual media transmissions at twice the speed. Built for reliability, the KN series provides local console and remote over IP access, ensuring 24/7 availability to all servers.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
Windows 10 64bit Mapped drive issue 38 123
Domain Controller/ Old server 9 70
DESKTOP MONITORING 41 83
Linux Server mapping drive using SSH key 9 53
How to set-up an On Demand, IPSec, Site to SIte, VPN from a Draytek Vigor Router to a Cyberoam UTM Appliance. A concise guide to the settings required on both devices
Most of the applications these days are on Cloud. Cloud is ubiquitous with many service providers in the market. Since it has many benefits such as cost reduction, software updates, remote access, disaster recovery and much more.
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
Windows 10 is mostly good. However the one thing that annoys me is how many clicks you have to do to dial a VPN connection. You have to go to settings from the start menu, (2 clicks), Network and Internet (1 click), Click VPN (another click) then fi…

738 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question