Re: Router Choices

Tech-Archive recommends: Repair Windows Errors & Optimize Windows Performance



On Fri, 23 Mar 2007 14:39:36 -0700, Russ Grover \(SBITS.Biz\) wrote:

Leythos

I don't know why you keep pushing the user PPTP VPN with Firewalls, when
the SBS PPTP Connector is so easy?
Laugh.

Now if you are connecting two BRANCH offices and not user accounts yes.

But for SIMPLE easy to manage PPTP VPN SBS Rocks at this IMO.
(A Monkey can set it up.)

I guess we all have different Opinions... ;)

Because I don't like users VPN'ing into the server directly - as SBS sits,
there is only one layer of authentication, and that's a problem as far as
I'm concerned.

When remote access is needed to the LAN, I never do a Win based server
endpoint, I always setup VPN to an appliance in front of the server, since
I also never install one without a Firewall capable of VPN Endpoint, it's
easy - I also create a user/password for the firewall that the user
doesn't match on the domain - so, the user account is different and the
password in the firewall they don't control....

This has passed more security audits than I can shake a stick at, even got
a "most secure network we've reviewed" from a homeland security audit team
and two SOX audit teams...

Also, if the server is down, the remote support people can still get into
the network via the VPN Appliance, not a chance if you use SBS for the
end-point.





--

Leythos

spam999free@xxxxxxxxxx (remove 999 for proper email address)
.



Relevant Pages

  • Re: VPN not connecting
    ... did you select "enable firewall" so your firewall ... Merv Porter [SBS MVP] ... > The errors I mentioned are when I create the connection manually on my ... When I create a VPN connection ...
    (microsoft.public.windows.server.sbs)
  • RE: VPN & SQL Issue
    ... hardware firewall on SBS domain, and the SBS 2000 and SBS 2003 locate in ... Now let us describe the issue more clear, it seems to be problem of the VPN ... the hardware firewall then we get a IP address which should be in the same ... what's the difference between allowing INBOUND HTTP ...
    (microsoft.public.windows.server.sbs)
  • RE: Router/Firewall Recommendation
    ... How many nodes behind the SBS box? ... Do you want just firewall services or ... If just firewall/IPSec VPN endpoint I'd go ... We had an issue with our Netgear RP614 router (sits between my SBS ...
    (microsoft.public.windows.server.sbs)
  • Re: Connecting to XP sp2 machines by VPN
    ... For PPTP VPN, you need two protocols: TCP, port 1723--which you know all about, and GRE. ... As I understand it, both the XP firewall and the Windows firewall --only require that you open port 1723--they then take care of the GRE stuff automagically. ... Don't open up any of those other protocols you see being dropped, unless there is clear evidence of functionality you need thich is connected to those ports. ... "Jim Behning SBS MVP" wrote: ...
    (microsoft.public.windows.server.sbs)
  • Re: Another VPN Issue...Say it aint so...
    ... VPN as implemented by MS, is, or should be, a relatively simple beastie. ... The SBS server has two nics and not three. ... need a router on the LAN side of your SBS? ... "I have ran CEICW two ways, once with firewall enable and once without ...
    (microsoft.public.windows.server.sbs)