Re: VPN & firewalls question

From: Merv Porter [SBS-MVP] (mwport_at_hotmail.com_no_spam)
Date: 04/17/04


Date: Sat, 17 Apr 2004 13:50:40 -0500


+ What types of things do your remote clients need to do after they
establish the VPN?
If the need access to their WinXP Pro LAN computers, create a VPN and fire
up an RDC session to the target workstation. If the LAN workstations are
Win2000 Pro, WinXP HE or Win9x, use TightVNC (www.tightvnc.com) with a VPN
to securely access the LAN workstation(s). This assumes that the target
workstations are not being used by other LAN or remote users at the time the
RDC or VNC session is established. Remote control software (like RDC) just
sends screen shot over the wires, so the remote user has a better
"experience" during his session. Straight VPNs can be slow when you try to
push large amounts of data down the pipe. That's why RDC sessions are
superior - all the processing happens at the LAN based machine and only the
screen shots of the results are sent back to the remote user..

+ You should be able to use Zonealarm with a VPN. It may need to be
configured to allow the proper traffic.

+ Dial-in... A VPN is an Internet based connection. RAS (Remote Access
Service) is a dial-in connection using standard phone lines. The speed of
your RAS conenction will be limited to 33.6k since it doesn't involve any
digital switching equipment like an Internet connection. Therefore, its
usefullness as a remote connection medium is limited by today's standards.
With RAS, you would need to set up a dedicated modem and phone line to
answer any incoming calls. A RAS connection plus an RDC session to a WinXP
Pro LAN workstation, althiough slow, can be made to work in an emergency.

+ WinXP HE to WinXP Pro... Although WinXP Pro is the preferred OS for
business use, in most cases it's not a requirement in order to remotely
connect to a business LAN or LAN workstation. If your LAN computers are not
all WinXP Pro, at this point your money would be better spent getting the
LAN workstations upgraded.

-- 
Merv  Porter  [SBS MVP]
===================================
"David" <davidp@epplus-nospamplease.org.uk> wrote in message
news:UTagc.18156$4N3.1804@newsfe1-win...
> Hi All
> I have set up my SBS2000 to allow VPN access after applying the reg edits
> and instructions on the small biz server website. All works well and I can
> VPN in from home.
> I am using Win XP Home edition on a desktop PC and a ADSL connection. I
> found that zone alarm firewall on my home PC gave me problems with VPN so
> had to shut it down. I am now using the win xp firewall.
> I now need to set up some other users to access the server via VPN
> Question is:
> 1) Should I leave zone alarm off and just use the win xp firewall - is
that
> sufficient protection
> 2) Should I be using the firewall client that comes with ISA.
> 3) Can users VPN via a dial up connection.
> 4) Should I upgrade desktop home users to win xp Pro.
>
> Thanks for your help
> David
>
>


Relevant Pages

  • Re: VPN & firewalls question
    ... remote user's overall session "experience" may be slow when using just a VPN ... users are connected because all data will flow in and out of the LAN via the ...
    (microsoft.public.backoffice.smallbiz2000)
  • Re: Gateway to Gateway VPN and SBS Server 2003
    ... Their is a static route on the RMT VPN Router to 192.168.16.0 through ... Communication works perfectly one way from the Servers Lan to any part WAN ... any machine on the remote site. ...
    (microsoft.public.windows.server.sbs)
  • Re: Problems accessing DMZ (different subnet) addresses w/ PPTP VPN
    ... remote user gets an IP in the same IP subnet as the LAN machines). ... route that subnet through the VPN server. ... Persistent Routes: ...
    (microsoft.public.windows.server.networking)
  • Re: VPN & Linksys Router (BEFSR11)
    ... Remote PPP peer or computer is not responding. ... re-installing the VPN or dial in connection, you still get the same problem. ... > I have setup an XP Pro VPN Server behind a router on a network at my work. ...
    (microsoft.public.windowsxp.network_web)
  • Cant acces office LAN via VPN
    ... I can make the connection ... but I cannot in any way acces the remote LAN. ... up the VPN client to use remote DNS. ...
    (microsoft.public.windowsxp.network_web)