Solved

Using a VPN to amazon EC2 instance

Posted on 2015-01-28
10
188 Views
Last Modified: 2015-03-03
I have a Windows 2012 EC2 Instance that I'm launching on Amazon and I want to connect to it from a few different computers using a VPN.

What is the best way to go about this? Is it possible to use the Windows built in VPN client using IPsec?
0
Comment
Question by:Gerhardpet
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 5
  • 3
  • 2
10 Comments
 
LVL 30

Expert Comment

by:Kerem ERSOY
ID: 40577652
Hi,

Can you clarify your question? I am not sure I understand what is that you want. You say you have Windows 2012 Instance and you want to connect it through VPN. If you want strong authentication and encryption this is definitely the way to go. Otherwise you'd open your Remote management port to the world which would be very dangerous.

In your second part you say something but what is the alternative? what VPN Server you're using? Is there a separate VPN service?  Are you using the Windows Built In VPN server? If you're using the Built in VPN server you can easily use the built in IPSec client. What are you current options?  The IPSec is good and widespread but it is not go through in most corporate environments to it. Also the implementation is relatively complex when compared to a SSL VPN.

Until you could elaborate your question this is all I could say to you .

Cheers,
K.
0
 
LVL 1

Author Comment

by:Gerhardpet
ID: 40577966
Correct I want to avoid opening the 3389 port for remote desktop access.

What I'm trying to accomplish is connect from my computer from any ISP to the Windows 2012 instance.

How would I use the built in VPN server in the Windows 2012 instance?
0
 
LVL 30

Expert Comment

by:Kerem ERSOY
ID: 40578186
Ok. If this is the case I'll suggest you to use SSTP VPN rather than IPSEC or PPTP. PPTP has a limited bandwith and limited implementation problem. IPSEC requires some TCP packets to be sent along with TCP and UDP ports due to complex implementation. SSTP requires you  to access a single port 443. If you're using this port for your application then you can remove it to a different port.

Here's an article on how to setup SSTP VPN over 2012 Server:
http://www.petenetlive.com/KB/Article/0000819.htm
Another one is here:
http://advancedhomeserver.com/windows-server-2012-sstp-vpn/

Unfortunately Microsoft TechNet documentation on SSTP is a bit stale this is why I've suggested some third party sources for setup.

Cheers,
K.
0
Why Off-Site Backups Are The Only Way To Go

You are probably backing up your data—but how and where? Ransomware is on the rise and there are variants that specifically target backups. Read on to discover why off-site is the way to go.

 
LVL 30

Expert Comment

by:Kerem ERSOY
ID: 40578198
Another option is setting up OpenVPN. OpenVPN implements SSL based VPN and open source and free. There are lots of information over internet for setup. Ican provide you some if you're interested.
0
 
LVL 1

Author Comment

by:Gerhardpet
ID: 40580303
Using Open VPN would't that require an EC2 instance?
0
 
LVL 33

Expert Comment

by:shalomc
ID: 40581506
The recommended way is to launch your EC2 instance inside a VPC, and then map a VPN link between the VPC and your office network.  Of course, if you don't have an office this is irrelevant.. :(
1
 
LVL 1

Author Comment

by:Gerhardpet
ID: 40581625
I have an office but both users connecting to the server are on the road for the most part
0
 
LVL 33

Expert Comment

by:shalomc
ID: 40582198
If you have one of these in your office, then you can configure a permanent VPN link between the office and Amazon, and let your users connect via the office VPN connection.
https://aws.amazon.com/vpc/faqs/#C9
0
 
LVL 1

Accepted Solution

by:
Gerhardpet earned 0 total points
ID: 40622128
I ended up hiring a firm to so the setup for me. Too complicated and I couldn't figure it out.
0
 
LVL 1

Author Closing Comment

by:Gerhardpet
ID: 40641591
No answer
0

Featured Post

Create the perfect environment for any meeting

You might have a modern environment with all sorts of high-tech equipment, but what makes it worthwhile is how you seamlessly bring together the presentation with audio, video and lighting. The ATEN Control System provides integrated control and system automation.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Learn how the use of a bunch of disparate tools requiring a lot of manual attention led to a series of unfortunate backup events for one company.
When speed and performance are vital to revenue, companies must have complete confidence in their cloud environment.
There's a multitude of different network monitoring solutions out there, and you're probably wondering what makes NetCrunch so special. It's completely agentless, but does let you create an agent, if you desire. It offers powerful scalability …
Michael from AdRem Software explains how to view the most utilized and worst performing nodes in your network, by accessing the Top Charts view in NetCrunch network monitor (https://www.adremsoft.com/). Top Charts is a view in which you can set seve…

726 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question