Allow guest access on branch VPN?

Posted on 2011-09-12
Last Modified: 2012-05-12
Hello Experts,

We are currently setting up a branch VPN using the following hardware:

SonicWALL NSA 240 @ Main Site
SonicWALL TZ 100 @ Branch Site

The Branch site is only going to be used to replicate our incremental backups after an initial full backup is taken onsite.  However, the "Branch Office" is going to be at our President's home.  In this scenario, what is the best way to secure the "Branch Office" against home internet traffic?  I've already seen his children infect several PCs with all kinds of Malware.  I don't want to take that chance with our corporate network.  The original plan was to get a seperate internet connection all together.  Is that absolutely necessary?
Question by:2_under_par
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 4
  • 3
LVL 33

Expert Comment

ID: 36523514
What hosts will need to be accessed over the VPN? If it's just the President's workstation as he access it via RDP, then you'd only need to allow that IP address and port over the VPN.

Author Comment

ID: 36523536
Only the President's PC and a NAS Device will need access to the VPN.

Accepted Solution

-tjs earned 250 total points
ID: 36523544
Aside from the fact that since the branch office is "untrusted" and therefore you can't really trust anything coming out of the environment, you could make it slightly more difficult for traffic to enter your main office "accidentally".  You should be able to configre the sonicwall(s) to allow traffic from only one or more IP addresses in the brach office to reach the main office.  You could also put a separate hub/switch/access point in the branch office and run a separate network, and plug that separate network into the sonicwall.

A second internet connection should not be required.
Technology Partners: We Want Your Opinion!

We value your feedback.

Take our survey and automatically be enter to win anyone of the following:
Yeti Cooler, Amazon eGift Card, and Movie eGift Card!

LVL 33

Expert Comment

ID: 36523583
So, from president's home his workstation and a NAS, right? What about access from the other direction?

Author Comment

ID: 36523713
So, from president's home his workstation and a NAS, right? What about access from the other direction?

Only His workstation needs full access to our main network @ Branch.  

Then, since we're replicating existing backups to the NAS @ the Branch Office, we simply need to copy backups from one NAS @ the main office to a 2nd NAS @ Branch Office.  

Question...  If setting up a second network that plugs into the SonicWall @ Branch, as tjs suggested, would setting that as the exact same subnet as the one at the MAIN office restrict traffic?  
Main Office subnet =
Branch Office subnet =
President's personal router @ Branch =
LVL 33

Expert Comment

ID: 36523766
What will restrict traffic are firewall rules. I'd not recommend configuring the subnets the same. This will be a nightmare to configure over the VPN. If the traffic is trusted and goes through the sonicwall, then there will be no restrictions. The more complex you setup the networks, the harder it will be to control the traffic. I'd still recommend setting up firewall rules restricting what hosts were allowed to talk to each other over the VPN.

Author Comment

ID: 37455615
SonicWall was extremely helpful when trying to accomplish this.  We wound up placing the President's home wireless router in a DMZ.  All traffic was then seperate.  I wish I could provide more details, but it took about 3 hours for them to finally get it working.  My attention was a bit strained at that point.  

Author Closing Comment

ID: 37455628
Answered the question that the 2nd Internet Connection is not necessary.

Featured Post

Announcing the Most Valuable Experts of 2016

MVEs are more concerned with the satisfaction of those they help than with the considerable points they can earn. They are the types of people you feel privileged to call colleagues. Join us in honoring this amazing group of Experts.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
Network adapter for Windows 7 9 53
Layer 3 Switch Configuration 12 43
Citrix App 7 29
Blocking outside IP Addresses 16 49
Meet the world's only “Transparent Cloud™” from Superb Internet Corporation. Now, you can experience firsthand a cloud platform that consistently outperforms Amazon Web Services (AWS), IBM’s Softlayer, and Microsoft’s Azure when it comes to CPU and …
When you try to share a printer , you may receive one of the following error messages. Error message when you use the Add Printer Wizard to share a printer: Windows could not share your printer. Operation could not be completed (Error 0x000006…
Internet Business Fax to Email Made Easy - With  eFax Corporate (, you'll receive a dedicated online fax number, which is used the same way as a typical analog fax number. You'll receive secure faxes in your email, f…
In this tutorial you'll learn about bandwidth monitoring with flows and packet sniffing with our network monitoring solution PRTG Network Monitor ( If you're interested in additional methods for monitoring bandwidt…

749 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question