cancel
Showing results for 
Search instead for 
Did you mean: 

VPN Site to Site Advice Needed

Strat
Community Veteran
Posts: 31,320
Thanks: 1,609
Fixes: 565
Registered: ‎14-04-2007

VPN Site to Site Advice Needed

A friend of mine is looking to connect two small company sites together using VPN over broadband.
There are no servers involved, just a couple of PCs, one at each site.
What he is looking for is suggestions for routers and a setup guide.
Details of personal experience would be great.
All assistance welcome. Smiley
Edit: Forgot to mention, no kit has been purchased yet.
Windows 10 Firefox 109.0 (64-bit)
To argue with someone who has renounced the use of reason is like administering medicine to the dead - Thomas Paine
4 REPLIES 4
MisterW
Superuser
Superuser
Posts: 14,754
Thanks: 5,527
Fixes: 394
Registered: ‎30-07-2007

Re: VPN Site to Site Advice Needed

Strat,
He/She will need routers that provide VPN tunnel support. The main off the shelf ones I'm aware of are some of the Billion Bipac range here  http://www.billion.com/product/product-vpn-soho.html i.e the 7402 or the 7800 or some of the Draytek range http://www.draytek.co.uk/products/comparison.html i.e 2820 upwards. Some of the Fritzbox range also have VPN tunnel support http://www.avm.de/de/Service/Service-Portale/Service-Portal/VPNen_Praxis_und_Tipps/grundlegende_schr.... I think DD_WRT has VPN support but I'm not sure and have never tried it.

OK, personal experience, I have a Draytek 2820 in the office which provides an IPSec VPN link to a customer site ( another 2820 ) for them to remotely access a system here. The Draytek here actually uses its WAN port to connect to our main ADSL modem/router since we have our main firewall ( Smoothwall ) which provides another VPN to our Netherlands office ( Fritzbox ) and dial in VPN support.
The Drayteks are pretty easy to setup and there are some guides here http://www.draytek.co.uk/support/router_faq.html#vpn. I've no experience of the Billions but there is a setup guide here au.billion.com/downloads/VPN-IPSec%20FAQ.pdf ,
the Fritzbox works ok but is a little tricky to setup.
One of the main pitfalls when setting up a LAN-LAN VPN betwwen 2 sites is to make sure that the 2 sites are on different private subnets e.g 192.168.1.x and 192.168.2.x for example, otherwise you won't get anything to work. In fact its a good idea to get away from any of the typical router default subnets and say use something like 192.168.11.x and 192.168.12.x.
Also, you need either to have static public IP's or use dynDNS  to setup a LAN-LAN VPN.
Hope that helps for starters, post back with any queries.

Superusers are not staff, but they do have a direct line of communication into the business in order to raise issues, concerns and feedback from the community.

Strat
Community Veteran
Posts: 31,320
Thanks: 1,609
Fixes: 565
Registered: ‎14-04-2007

Re: VPN Site to Site Advice Needed

That's excellent stuff MisterW, plenty for him and I to get our teeth into.
Thanks.
Windows 10 Firefox 109.0 (64-bit)
To argue with someone who has renounced the use of reason is like administering medicine to the dead - Thomas Paine
MisterW
Superuser
Superuser
Posts: 14,754
Thanks: 5,527
Fixes: 394
Registered: ‎30-07-2007

Re: VPN Site to Site Advice Needed

You're welcome. Setting up a LAN-LAN VPN is reasonably straightforward but not trivial. You certainly need to understand the basics first and plan it.
Diagnosing the problem when it doesn't work can be a bit tricky!.
Edit: another tip:- make sure the remote sites router has 'remote management' enabled as it saves an awful lot of travelling...

Superusers are not staff, but they do have a direct line of communication into the business in order to raise issues, concerns and feedback from the community.

Strat
Community Veteran
Posts: 31,320
Thanks: 1,609
Fixes: 565
Registered: ‎14-04-2007

Re: VPN Site to Site Advice Needed

I've had experience of configuring Microsoft SBS but this situation has no server hence my question.
They need to look into getting something as the company grows.
I know only too well from past experience the value of remote access. The last company I worked for was in Sheffield and their other office was in Crawley.
Remote access was a godsend....until their router died.
Windows 10 Firefox 109.0 (64-bit)
To argue with someone who has renounced the use of reason is like administering medicine to the dead - Thomas Paine