Re: Logon/rename via VPN



Brian <Brian@xxxxxxxxxxxxxxxxxxxxxxxxx> wrote:
1. I have only one user on the remote LAN because she works from her
home. Defnitely not worth setting up another server.

Yeah, I guess I can seethat.

2.I know my method works, because I have another client who has a T-1
at their host site (35 LAN stations) with two remote sites on < 1Mb
DSL's and 4 remote LAN stations each. The remote users are able to
work without a problem, other than the obvious delay opening files
from the shared folders on the DC. The difference in my current case
may be that the host site has a DSL that averages about 600k (the
remote site has a cable connection at 6 Mb/768k).

ADSL, I'm presuming. This will never be pretty.

3. I need a VPN for two reasons

a. The remote user needs to print to her house from the host LAN
(using MAS90, a ProvideX-based accounting package), hosted on the DC,
to a multi-function laser printer at the remote office (her house).
As I am sure you are aware, support for many multi-function printers
is very shaky or nonexistent via RDP,

Yep....which is why I strongly discourage them. However, you can often find
a comparable DeskJet driver for any HP inkjet multifunction, and so on.

so I elected to have the TS
print directly to her IP-based networked printer. This works just
fine with no delays.

Well, yes, but you shouldn't need a VPN for that. Printer redirection to a
network printer isn't a problem per se....

b. The user needs remote access to both Outlook

.....RPC over HTTP will be useful there

& shared files hosted
on the server.

This won't be pretty, as mentioned....

I know I can leave off the domain membership & just
write a batch file for the user to map the drives (instead of using
the AD login script), but I'm not sure that would be much different.

Yes, it will make a big difference.

4. She does run MAS90 via a terminal server at the host site, but I
don't really want to get into trying to license Word & Excel for the
terminal server,

Understood, but if you want good performance for any sort of file access,
I'd think this was the most logical path.

and she needs realtime access to those types of
files in her home folder & shared folders on the server.

Realtime meaning ?

The bottom line? Everything works fine except the logon process.

Whichis understandable.

Internet access using the DC as her DNS server is perfectly fast;
file access from the DC is slow but adequate. The logon process,
though, takes a good five minutes. At the moment, my first step may
just be to get the host site upgraded to a cable connection at over
1Mb.

That might help, but I'd still be skeptical.

Someone told me there is a way to have "authentication lite" for
remote stations to speed up the logon process, but I have been unable
to find anything on this.

Not sure what they referred to. There are various things you can tweak via
group policy, but I'm not sure what you'll be able to do with this.


<snipped for length>


.



Relevant Pages

  • Re: Logon/rename via VPN
    ... Defnitely not worth setting up another server. ... T-1 at their host site with two remote sites on < ... 1Mb DSL's and 4 remote LAN stations each. ... to a multi-function laser printer at the remote office (her ...
    (microsoft.public.windows.server.networking)
  • Re: Logon/rename via VPN
    ... Defnitely not worth setting up another server. ... T-1 at their host site with two remote sites on < ... 1Mb DSL's and 4 remote LAN stations each. ... to a multi-function laser printer at the remote office (her ...
    (microsoft.public.windows.server.networking)
  • Re: Logon/rename via VPN
    ... at their host site with two remote sites on < 1Mb ... DSL's and 4 remote LAN stations each. ... The remote user needs to print to her house from the host LAN ... will make much difference with file access, ...
    (microsoft.public.windows.server.networking)
  • SecurityFocus Microsoft Newsletter #152
    ... MICROSOFT VULNERABILITY SUMMARY ... Real Networks Helix Universal Server Remote Buffer Overflow ... ... NEW PRODUCTS FOR MICROSOFT PLATFORMS ...
    (Focus-Microsoft)
  • SecurityFocus Microsoft Newsletter #140
    ... Cafelog b2 Remote File Include Vulnerability ... Webfroot Shoutbox Remote Command Execution Vulnerability ... Pablo Software Solutions Baby POP3 Server Multiple Connection... ... Microsoft Windows XP Nested Directory Denial of Service... ...
    (Focus-Microsoft)