Solved

hardware vpn sharing

Posted on 2013-06-30
5
322 Views
Last Modified: 2013-07-11
We are equipping a roaming group of RDP users that connect to one Windows Server 2008 Terminal Server from various sites. They move from site to site as a group and when working, they are all at the same site, generally in the same room.

When on site, they will be behind whatever NAT device is installed at that site. These are generally simple common brand firewalls that don’t block ports; they just require that the session be initiated from the LAN side of the device.

We are working to develop a configuration that will allow their terminal server sessions to share scan and print devices at their remote sites as they roam. We are investigating a native Windows solution, third party software solutions, and hardware solutions if they exist. This question is in reference to a hardware solution.

We would like to find hardware routers with VPN built in that can be configured like this:

Install one as the main gateway and NAT device at the site where the Terminal Server is located. It would be the gateway for the LAN that the Terminal Server is installed on and fixed endpoint for roaming tunnels.
Have a roaming router/VPN device with at least two Ethernet ports. One port would get a protected address from the LAN where the group is working and establish an IPSec tunnel to the gateway where the Terminal Server is located. Use the second port on the roaming router/VPN device to service a small LAN that RDP clients and network scanners and printers could be connected and be used simply as any other network device as the hardware handles all the routing and tunneling.

Two things concern us.
One – That the tunnel can be established through most common NAT devices that they will encounter and be behind as they roam.
Two – That the VPN device at the main Terminal Server location can accept tunnels established from roaming addresses. I seem to remember on older VPN devices that tunnels could be defined from roaming addresses, but on the newer equipment, it seems that both ends of the tunnel need to be defined with a fixed address.

.

Thank you.
0
Comment
Question by:mj2112
  • 3
5 Comments
 
LVL 23

Assisted Solution

by:Mysidia
Mysidia earned 250 total points
ID: 39288855
"One – That the tunnel can be established through most common NAT devices that they will encounter and be behind as they roam."

My suggestion would be to ditch IPsec, then, and look to   OpenVPN solutions.
Or look to Logmein Hamachi.


In either case,  for your VPN hardware, you can look towards consumer routers that are capable of being flashed with DD-WRT  imagines  that have Hamachi or OpenVPN client capability;  due to the requirement to have multiple devices connect.


On the destination network side, look at using an x86 server with an interface outside your normal firewall rules (Bastion system),  or a virtual access server appliance...



The problem with using an IPsec VPN is,  that even with NAT-T    NAT traversal, it is not very robust or foolproof.

For a VPN that will reliably traverse NAT,  you should leverage a TCP or UDP based tunneling protocol  that by design works through a client-side NAT.
0
 
LVL 93

Assisted Solution

by:John Hurst
John Hurst earned 250 total points
ID: 39288895
Take a look at Cisco RVxx VPN routers or Juniper Netscreen SSG routers. Both are reliable and both can handle NAT Traversal - I use it.

Hardware VPN routers work best with Static IP and always did. If your IP does not change a lot, you can get by with dynamic - I do that as well.

You can use NCP Secure Entry (www.ncp-e.com) for client access into these devices. NCP handles NAT Traversal very well.

... Thinkpads_User
0
 

Accepted Solution

by:
mj2112 earned 0 total points
ID: 39292088
Thank you both. I am assimilating your information. I will post back soon.
0
 

Author Comment

by:mj2112
ID: 39304399
i didn't mean to click my own comment................
0
 

Author Closing Comment

by:mj2112
ID: 39316939
Again, thank you both. I am using your advice as i decide. Best Regards...
0

Featured Post

VMware Disaster Recovery and Data Protection

In this expert guide, you’ll learn about the components of a Modern Data Center. You will use cases for the value-added capabilities of Veeam®, including combining backup and replication for VMware disaster recovery and using replication for data center migration.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Shadow IT is coming out of the shadows as more businesses are choosing cloud-based applications. It is now a multi-cloud world for most organizations. Simultaneously, most businesses have yet to consolidate with one cloud provider or define an offic…
In this article, I am going to show you how to simulate a multi-site Lab environment on a single Hyper-V host. I use this method successfully in my own lab to simulate three fully routed global AD Sites on a Windows 10 Hyper-V host.
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…

808 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question