Re: site to site VPN - need suggestions on VPN routers and folder synchronization



As others have mentioned, the Watchguard firewalls are very good.
It's been a while since I've set up site-to-site VPNs with a
Watchguard, but as I recall, you must have static public IP addresses
assigned to each firewall in order to build the IPSEC VPN.

You can build similar infrastructure with Cisco routers and firewalls.
Either the ASA or the PIX should have the features you need. In this
case, you can build GRE tunnels in addition to IPSEC, which would
allow you to tunnel non-IP protocols over the VPN.

If you're into homebrew, check out OpenVPN. It's much easier to set
up compared to IPSEC or GRE, although Watchguard does a pretty good
job of taking the pain out of VPN. I'm running OpenVPN on Linux and
FreeBSD firewalls, with hardware that includes Linksys WRT54G access
points and recycled Nokia servers. The only downside to homebrew is
the lack of dedicated cryptographic hardware, so if you decide to
build instead of buy, make certain your firewalls have strong enough
CPUs to handle the encryption and compression algorithms employed by
your VPN software (whether OpenVPN, IPSEC, etc.)

Best wishes,
Matthew

--
"Rogues are very keen in their profession, and know already much more
than we can teach them respecting their several kinds of roguery."
- A. C. Hobbs in _Locks and Safes_ (1853)
.



Relevant Pages

  • RE: Firewall Hardware Recommendations
    ... WatchGuard has you pay for VPN lic's. ... Is the PIX fast? ... What cisco firewall do you currently have and what version OS ...
    (Security-Basics)
  • Re: Keine Verbindung zu Watchguard Soho 6 tc
    ... > Auf der Watchguard steht folgendes im Event Log: ... > No Matching IPSec Policy found for 217.5.... ... Hast Du fuer die Firebox denn auf VPN upgedatet? ... untertsuetzt die IMHO keine VPN Branch Verbindung? ...
    (microsoft.public.de.german.isaserver)
  • Re: Branch Office MVBASE network access
    ... the "X Core" range supports up to 50 VPN links to branches. ... The watchguard also has various options. ... All the users use a thin client winterm ... Each of the factories just has a Cisco 1700 and an 8 or 16 port hub! ...
    (comp.databases.pick)
  • Re: Firebox 1000 WG and VPN problem. Assistance request. TIA.
    ... of time with watchguard today and came to the same conclusion...this ... It's too bad that you've had to do that, but with many boxes that's really ... Check in the knowledgebase for the search terms "overlapping subnets vpn" to ...
    (comp.security.firewalls)
  • [fw-wiz] Windows VPN/RRAS traffic through watchguard
    ... I thought with firewalls, traffic is either allowed or it's not ... Watchguard have been configured to allow PPTP VPN (Windows-based PPTP ... a VPN "connection" is established from the Internet into the ISA ...
    (Firewall-Wizards)