Solved

Is Openvpn Access Server a good option for remote and site-to-site VPN?

Posted on 2013-11-30
4
601 Views
Last Modified: 2013-12-07
A client has two branch offices in different geographical areas that need to be connected to their headquarters, via VPN, primarily for data backup purposes.

The backup application is going to run on an in-house Windows server in the headquarters. The I.T administrator at the hq will log in to the systems at the branch offices remotely and perform the backup manually.

My original idea was to put UTM boxes in each location to create the VPN, but after looking at the OpenVPN Access server from Openvpn.net, it looks like it could do the trick for a much lower cost.

Does anyone here have any experience using OpenVpn Access server? Would you recommend it for my purpose? It looks like we will have to use the Virtual appliance as we will be running it on a Windows Server.

Thanks in advance.
0
Comment
Question by:scmeeven
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 2
  • 2
4 Comments
 
LVL 69

Assisted Solution

by:Qlemo
Qlemo earned 500 total points
ID: 39687337
For backup and maintenance purposes the free OpenVPN community edition should suffice, and that can be run on Windows, either in a point-to-point or client-server configuration. Both will allow full routing, but no firewalling.
The free edition is less comfortable, but still nothing difficult to set up.
BTW, Astaro hardware firewalls are one of many manufacturers who incorporate OpenVPN into their products.
0
 

Author Comment

by:scmeeven
ID: 39688001
@Qlemo, thanks for your comment, especially the point about the free edition allowing full routing but no firewalling.

At the moment, the client has no firewall at all in their central office, so it's an open connection.

Does the commercial edition of OpenVPN have firewalling capabilities?
0
 
LVL 69

Accepted Solution

by:
Qlemo earned 500 total points
ID: 39688042
The site says:
OpenVPN Access Server supports  a wide range of configurations, including secure and granular remote access to internal network and/ or private cloud network resources and applications with fine-grained access control.
That is, you can secure remote access via OpenVPN, but nothing else. It is not a full-size multi-purpose firewall solution.
As said, if you just want to allow access, not restrict remote resources by user groups, you do not need Access Server.

I'm not clear about what the VPN is for (now), and what it should be capable of in the future. As-is, very simplistic approaches are sufficient, like Windows VPN (PPTP), which comes at absolutely no costs and with minimal setup effort.
However, not having a firewall in the HQ makes me quiver if it comes to always-on connections. It doesn't matter for the occassional Internet access, but whenever you want to do connect from outside, you'll usually need something able to protect the innocent, and restrict general availability of services.

And that is another point. If you need to contact a remote site, you need something able to forward dedicated traffic. Imagine you want to contact a VPN service, which is not hosted on the device managing the connection to the Internet. How should the device know where to send the request to?
Low budget routers allow for simple forwarding rules, and that might be enough here (for now). E.g. they can be configured to forward all inbound PPTP related traffic (to implement Windows VPN) to a single PC running the VPN server (RRAS). You would not be able to restrict that on the router, to allow only connections from the HQ, so using strong passwords and stuff is a requirement (else they will end up being hacked some day).
0
 

Author Comment

by:scmeeven
ID: 39703281
@Qlemo, thank you for the additional insights into the subject. They are helpful and I appreciate it very much.
0

Featured Post

Simple, centralized multimedia control

Watch and learn to see how ATEN provided an easy and effective way for three jointly-owned pubs to control the 60 televisions located across their three venues utilizing the ATEN Control System, Modular Matrix Switch and HDBaseT extenders.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
VOIP Setup through a Watchguard BOVPN 4 104
HTTPS/SSL based VPN will full functionality? 2 70
Setting up a VPN 60 205
VPN connect issues 2 24
Secure VPN Connection terminated locally by the Client.  Reason 442: Failed to enable Virtual Adapter. If you receive this error on Windows 8 or Windows 8.1 while trying to connect with the Cisco VPN Client then the solution is a simple registry f…
This is an article about my experiences with remote access to my clients (so that I may serve them) and eventually to my home office system via Radmin Remote Control. I have been using remote access for over 10 years and have been improving my metho…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…

735 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question