[2 days left] What’s wrong with your cloud strategy? Learn why multicloud solutions matter with Nimble Storage.Register Now


Is Openvpn Access Server a good option for remote and site-to-site VPN?

Posted on 2013-11-30
Medium Priority
Last Modified: 2013-12-07
A client has two branch offices in different geographical areas that need to be connected to their headquarters, via VPN, primarily for data backup purposes.

The backup application is going to run on an in-house Windows server in the headquarters. The I.T administrator at the hq will log in to the systems at the branch offices remotely and perform the backup manually.

My original idea was to put UTM boxes in each location to create the VPN, but after looking at the OpenVPN Access server from Openvpn.net, it looks like it could do the trick for a much lower cost.

Does anyone here have any experience using OpenVpn Access server? Would you recommend it for my purpose? It looks like we will have to use the Virtual appliance as we will be running it on a Windows Server.

Thanks in advance.
Question by:scmeeven
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 2
  • 2
LVL 71

Assisted Solution

Qlemo earned 2000 total points
ID: 39687337
For backup and maintenance purposes the free OpenVPN community edition should suffice, and that can be run on Windows, either in a point-to-point or client-server configuration. Both will allow full routing, but no firewalling.
The free edition is less comfortable, but still nothing difficult to set up.
BTW, Astaro hardware firewalls are one of many manufacturers who incorporate OpenVPN into their products.

Author Comment

ID: 39688001
@Qlemo, thanks for your comment, especially the point about the free edition allowing full routing but no firewalling.

At the moment, the client has no firewall at all in their central office, so it's an open connection.

Does the commercial edition of OpenVPN have firewalling capabilities?
LVL 71

Accepted Solution

Qlemo earned 2000 total points
ID: 39688042
The site says:
OpenVPN Access Server supports  a wide range of configurations, including secure and granular remote access to internal network and/ or private cloud network resources and applications with fine-grained access control.
That is, you can secure remote access via OpenVPN, but nothing else. It is not a full-size multi-purpose firewall solution.
As said, if you just want to allow access, not restrict remote resources by user groups, you do not need Access Server.

I'm not clear about what the VPN is for (now), and what it should be capable of in the future. As-is, very simplistic approaches are sufficient, like Windows VPN (PPTP), which comes at absolutely no costs and with minimal setup effort.
However, not having a firewall in the HQ makes me quiver if it comes to always-on connections. It doesn't matter for the occassional Internet access, but whenever you want to do connect from outside, you'll usually need something able to protect the innocent, and restrict general availability of services.

And that is another point. If you need to contact a remote site, you need something able to forward dedicated traffic. Imagine you want to contact a VPN service, which is not hosted on the device managing the connection to the Internet. How should the device know where to send the request to?
Low budget routers allow for simple forwarding rules, and that might be enough here (for now). E.g. they can be configured to forward all inbound PPTP related traffic (to implement Windows VPN) to a single PC running the VPN server (RRAS). You would not be able to restrict that on the router, to allow only connections from the HQ, so using strong passwords and stuff is a requirement (else they will end up being hacked some day).

Author Comment

ID: 39703281
@Qlemo, thank you for the additional insights into the subject. They are helpful and I appreciate it very much.

Featured Post

How to Use the Help Bell

Need to boost the visibility of your question for solutions? Use the Experts Exchange Help Bell to confirm priority levels and contact subject-matter experts for question attention.  Check out this how-to article for more information.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Juniper VPN devices are a popular alternative to using Cisco products. Last year I needed to set up an international site-to-site VPN over the Internet, but the client had high security requirements -- FIPS 140. What and Why of FIPS 140 Federa…
OpenVPN is a great open source VPN server that is capable of providing quick and easy VPN access to your network on the cheap.  By default the software is configured to allow open access to your network.  But what if you want to restrict users to on…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…

656 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question