ipsec vpn for broadband internet connection with static IPs

Dear Experts

We have 03 locations  one head office + 2 branch offices, application server  web based is hosted in head office and branch offices to access the head office applications, all the 03 locations are having broad brand internet connection and each of the location having static ip, is it possible to setup IP-sec VPN so that branch office users can access the application server of the head office,  if possible please suggest what type of router to be procured and steps please
Who is Participating?

[Product update] Infrastructure Analysis Tool is now available with Business Accounts.Learn More

I wear a lot of hats...

"The solutions and answers provided on Experts Exchange have been extremely helpful to me over the last few years. I wear a lot of hats - Developer, Database Administrator, Help Desk, etc., so I know a lot of things but not a lot about one thing. Experts Exchange gives me answers from people who do know a lot about one thing, in a easy to use platform." -Todd S.

is it possible to setup IP-sec VPN so that branch office users can access the application server of the head office
The short answer to your question is yes.
Long answer: What type of routers do you have at each location now? Many business focused units will let you set up site-to-site VPNs. There are a long list of models that can do this, it just comes down to other requirements.

I tended to like Sonicwall's TZ series, but you could use units from brands ranging from TP-Link to Cisco. Figure out your other requirements first. And no, the brands/models at each site don't have to match, but it would keep your life easier.

Experts Exchange Solution brought to you by

Your issues matter to us.

Facing a tech roadblock? Get the help and guidance you need from experienced professionals who care. Ask your question anytime, anywhere, with no hassle.

Start your 7-day free trial
JohnBusiness Consultant (Owner)Commented:
I agree with the above. We use Juniper VPN boxes at clients and you can connect site-to-site tunnels using these boxes from remote site to head office site. Some Cisco boxes are a bit easier to use.

But it can be done and as suggested above, please let us know your requirements.
D_wathiAuthor Commented:
thanks for masnrock and john, so whatever the connection type could be like the following but with static IP  the IP Sec- VPN can be configured is this correct please suggest
1. Head office leased line circuit and both branch office DSL/Broad Band connection
2. head office and as well the branch offices all are in DSL/Broad Band connection
Get Certified for a Job in Cybersecurity

Want an exciting career in an emerging field? Earn your MS in Cybersecurity and get certified in ethical hacking or computer forensic investigation. WGU’s MSCSIA degree program was designed to meet the most recent U.S. Department of Homeland Security (DHS) and NSA guidelines.  

The answers would stay the same based on the information you're providing. The biggest key is ensuring that your routers w/ site to site VPN are internet facing. So if your modems are also routers, they need to be in bridge mode.
JohnBusiness Consultant (Owner)Commented:
The connections you state are fine, so you need just to select the VPN boxes and set up.

The VPN box needs the external Static IP and that is the Bridge Mode suggested above
Another thing to pay attention to: the speed of the connections. That could impact the performance of your VPN tunnels. You don't need the fast connections in the world, but be sure they are sufficient for your purposes.
D_wathiAuthor Commented:
thank you very much, can you please suggest VPN box,  the  company and model name to procure.
JohnBusiness Consultant (Owner)Commented:
Cisco RVxx
Juniper SSG or equivalent
Sonic Wall

The models are constantly changing
It's more than this solution.Get answers and train to solve all your tech problems - anytime, anywhere.Try it for free Edge Out The Competitionfor your dream job with proven skills and certifications.Get started today Stand Outas the employee with proven skills.Start learning today for free Move Your Career Forwardwith certification training in the latest technologies.Start your trial today
Hardware Firewalls

From novice to tech pro — start learning today.