Page 1 of 3 123 LastLast
Results 1 to 16 of 35

Thread: Site to Site Network

  1. #1
    Jay
    Jay is offline
    Gentlemen.. we're history Jay's Avatar
    Join Date
    Aug 2006
    Location
    Jita
    Posts
    8,365
    Thanks
    304
    Thanked
    568 times in 409 posts

    Site to Site Network

    I have two offices that I need to connect.

    The main office currently has a Full windows Domain and our new office will be using terminal services to connect.

    What i need to know is what hardware do you provide that will allow me to connect the two offices over a VPN on a standard ADSL connection

    What routers would you suggest I purchase?

  2. #2
    ***** Lurker
    Join Date
    Aug 2005
    Posts
    724
    Thanks
    2
    Thanked
    15 times in 15 posts
    • d3fiant's system
      • Motherboard:
      • GB X58A-UDR3 FB11
      • CPU:
      • Core i7 950
      • Memory:
      • Corsair 12GB DDR3 1600
      • Storage:
      • 2x 120GB OCZ Agility SSD + 500GB SP F3
      • Graphics card(s):
      • GB Windforce GTX670 2GB
      • PSU:
      • 850W Akasa
      • Case:
      • Fractal R3
      • Operating System:
      • Windows 7 x64 HP Retail
      • Monitor(s):
      • 24" 1920x1080 Iiyama LED
      • Internet:
      • 60MB VM
    when you say full domain, what do you mean, keeping in mind active directory expands to thousands of servers and millions of users. Do you mean physically constrained such is network ports etc. You should remember that ADSL is not very good for site to site, while it has very good dl speeds, upload speeds are much lower, u may want to look at SDSL which has the same speed in both directions, like a leased line, but is more expensive. If its just terminal server then ADSL would be ok for 1 or 2 sessions. Also users would not be able to interact with the domain from the other site via this manner unless you have all your backoffice apps running on TS servers. This post is best suited to the help forum rather than the scan forum

  3. #3
    Administrator Moby-Dick's Avatar
    Join Date
    Jul 2003
    Location
    There's no place like ::1 (IPv6 version)
    Posts
    10,665
    Thanks
    53
    Thanked
    384 times in 313 posts
    You could just forward the RDP port for the server to the web , but that does potentiall open up a few security issues.

    If you where to have a second branch domain controller at the branch office , then you could establish an IPSEC / L2TP tunnel between them, in addition to providing local authentication services where needed.

    If you really only want the main network to be visible from the branch office then something like a vigor draytek 2800 can run as a IPSEC Tunnell mode endpoint , to enable secure RDP sessions from branch to main office.

    http://www.draytek.co.uk/products/vigor2800.html
    my Virtualisation Blog http://jfvi.co.uk Virtualisation Podcast http://vsoup.net

  4. #4
    ***** Lurker
    Join Date
    Aug 2005
    Posts
    724
    Thanks
    2
    Thanked
    15 times in 15 posts
    • d3fiant's system
      • Motherboard:
      • GB X58A-UDR3 FB11
      • CPU:
      • Core i7 950
      • Memory:
      • Corsair 12GB DDR3 1600
      • Storage:
      • 2x 120GB OCZ Agility SSD + 500GB SP F3
      • Graphics card(s):
      • GB Windforce GTX670 2GB
      • PSU:
      • 850W Akasa
      • Case:
      • Fractal R3
      • Operating System:
      • Windows 7 x64 HP Retail
      • Monitor(s):
      • 24" 1920x1080 Iiyama LED
      • Internet:
      • 60MB VM
    well that puts my response firmly in the shade, I'll go get my coat

  5. #5
    Administrator Moby-Dick's Avatar
    Join Date
    Jul 2003
    Location
    There's no place like ::1 (IPv6 version)
    Posts
    10,665
    Thanks
    53
    Thanked
    384 times in 313 posts
    Quote Originally Posted by d3fiant View Post
    well that puts my response firmly in the shade, I'll go get my coat
    Its not all bad

    depending on what you are doing , a terminal server connection can be quite lean on bandwidth - it only gets heavy if you are doing a lot of printing back to client connected printers.

    To be able to give a more complete answer , we'd need to know more about the scenario (number of users , types of application etc. )

    EDIT: Also moving this to the Networking forum.
    my Virtualisation Blog http://jfvi.co.uk Virtualisation Podcast http://vsoup.net

  6. #6
    Jay
    Jay is offline
    Gentlemen.. we're history Jay's Avatar
    Join Date
    Aug 2006
    Location
    Jita
    Posts
    8,365
    Thanks
    304
    Thanked
    568 times in 409 posts
    I have about 4 sites that I want to centralise at my HQ. At the moment they are separate sites and to do any work on their server or do the backups i have to drive to the sites or Remote desktop in. Also when a person moves between the sites I need to back their data up and move it to the server on the other sites.

    The way I am looking at it now is that if I setup terminal services on a rack system i have here (decent spec as i know it will need to be!) give the clients dial in VPN access over the internet (for encryption) and allow them have remote desktop over terminal services then I need to back up one server, I no longer need to move data from site to site and it should save m lots of time.

    Each site will only have between 2 and 4 systems (hot desk situation)

    I will first test this with one site and 2 users so HQ's standard ADSL should be ok (512k up). If this all works then I will upgrade HQ to SDSL 2mb/2mb - this is where the main bulk of staff are and they will use the local domain.

    each site will have 4meg Cable (384k up)

    applications will only be Office

    (the reason I posted this in the scan area was so they had the chance to tell me what products I could purchase off them to do this job)
    Last edited by Jay; 10-01-2007 at 11:09 AM.

  7. #7
    Registered+
    Join Date
    Aug 2006
    Location
    North Wales
    Posts
    15
    Thanks
    0
    Thanked
    0 times in 0 posts
    Our VPN is setup using a pair of SonicWall 2040 Firewalls. They're incredibly stable!! Also very easy to setup too!

    We have a pair of 6mb/s ADSL connections. Not great but it works.

    It all makes perfect sense, expressed in Dollars and Cents, Pounds, Shillings and Pence.

  8. #8
    Jay
    Jay is offline
    Gentlemen.. we're history Jay's Avatar
    Join Date
    Aug 2006
    Location
    Jita
    Posts
    8,365
    Thanks
    304
    Thanked
    568 times in 409 posts
    but if i wanted 4 offices to connect to a central office would I need one Sonicwall in the main HQ and then one at each site.

    Then get each site to VPN into the main HQ sonicwall?

    i mean these things a re £1000 each, bit much for about max of about 10 Termainal Service clients
    Last edited by Jay; 10-01-2007 at 11:23 AM.

  9. #9
    Jay
    Jay is offline
    Gentlemen.. we're history Jay's Avatar
    Join Date
    Aug 2006
    Location
    Jita
    Posts
    8,365
    Thanks
    304
    Thanked
    568 times in 409 posts
    Quote Originally Posted by deviantdave View Post
    Our VPN is setup using a pair of SonicWall 2040 Firewalls. They're incredibly stable!! Also very easy to setup too!

    We have a pair of 6mb/s ADSL connections. Not great but it works.
    also if you get chance tell me a bit more about this network

    (number of users, data migration between sites etc)

  10. #10
    Administrator Moby-Dick's Avatar
    Join Date
    Jul 2003
    Location
    There's no place like ::1 (IPv6 version)
    Posts
    10,665
    Thanks
    53
    Thanked
    384 times in 313 posts
    As I previously mentioned , the main problem with Office over a Terminal Service connection is printing back to a printer in the branch office. If your users are heavy printers then this will be a pain point for you. ( I've set up entire firms based on hosted TS infrastructures , so I do know what I'm talking about )

    If you are just looking at a star type design for your VPN ( ie no redundant routing via the branch office - each branch only has a connection to HQ ) then the draytek routers will do it.

    Its always nice to try and keep the endpoints of each VPN from the same vendor ( thus keeping the set of options the same )

    For the size of deployment you are looking at , the drayteks should be up to the job as branch routers - not sure what they do in the way of SDSL products though. They do have an enterprise class firewall , but I have a hunch it'll be overkill.
    my Virtualisation Blog http://jfvi.co.uk Virtualisation Podcast http://vsoup.net

  11. #11
    Jay
    Jay is offline
    Gentlemen.. we're history Jay's Avatar
    Join Date
    Aug 2006
    Location
    Jita
    Posts
    8,365
    Thanks
    304
    Thanked
    568 times in 409 posts
    ok



    so would this work...

    HQ 192.168.0.1 - 100

    Main Network, large rack server. Either SDSL 2mb/2mb or a dedicated lease line, Main DNS, Email servers.

    Site 1 192.168.0.101 - 110

    Standard internet (384k up) Router with DHCP and VPN
    3 PCs, Use Terminal services to the main network

    Site 2 192.168.0.111 - 120

    Standard internet (384k up) Router with DHCP and VPN
    4 PCs, Use Terminal services to the main network

    Site 3 192.168.0.121 - 140

    Standard internet (384k up) Router with DHCP and VPN
    4 PCs, Use Terminal services to the main network

    Now this should allow all the Sites to appear as if they are on the same network, termainal services allows me to store all the data at HQ and will allow people to roam between sites and still get their Profiles when they log on. Also a central email server will be easier to setup.

    I also hope to run the DNS via the main site so i can use 1 content filtering solution


    also what router would you suggest and what internet for the main site (you seem to have not used SDSL)
    Last edited by Jay; 10-01-2007 at 01:53 PM.

  12. #12
    Administrator Moby-Dick's Avatar
    Join Date
    Jul 2003
    Location
    There's no place like ::1 (IPv6 version)
    Posts
    10,665
    Thanks
    53
    Thanked
    384 times in 313 posts
    Each site will be on a different subnet.

    ie 192.168.0 , 192.168.1 , 192.168.2 and 192.168.3 ( assuming a /24 subnet mask )

    The routing policy should be done by the VPN end points.

    I woudl advise very strongly against trying to have roaming profiles over a WAN.

    In fact I'd advise against roaming profiles at all.

    What Mail server are you planning on using ?

    Mapping drives accross the WAN shoudl also be avoided where possible.

    what about printers ?
    my Virtualisation Blog http://jfvi.co.uk Virtualisation Podcast http://vsoup.net

  13. #13
    Jay
    Jay is offline
    Gentlemen.. we're history Jay's Avatar
    Join Date
    Aug 2006
    Location
    Jita
    Posts
    8,365
    Thanks
    304
    Thanked
    568 times in 409 posts
    ok i'll use different subnets

    Well I assumed that the profiles would not be a problem as Terminal services is just like a remote desktop so no actuall data would be sent to and from the sites other than the projected desktops. I would cheat a bit with the profiles though as i would setup a Drive via Active Directory and have their "my documents" folder on this drive (the drive would just be a direct link to their profile). It saves the copying back and forward etc of the "my docs" folder.

    Printing is somthing I will have to think about....

    I am looking at using Scalix as i can run it on Redhat and it has webmail etc.
    Last edited by Jay; 10-01-2007 at 02:00 PM.

  14. #14
    Administrator Moby-Dick's Avatar
    Join Date
    Jul 2003
    Location
    There's no place like ::1 (IPv6 version)
    Posts
    10,665
    Thanks
    53
    Thanked
    384 times in 313 posts
    Terminal Server profiles are not the same as Normal Desktop profiles - you may have problems with that.

    What would users in the branches log into the hotdesk machines as ?

    In fact you might not even want them to be PC's - why not use WinTerms at the Branch offices to prevent users attempting to log into them ( and causing problems ) It would also make replacing a branch 'Pc' easy as you can have some preconfigred winterms in stock to just swap out as required.
    my Virtualisation Blog http://jfvi.co.uk Virtualisation Podcast http://vsoup.net

  15. #15
    Administrator Moby-Dick's Avatar
    Join Date
    Jul 2003
    Location
    There's no place like ::1 (IPv6 version)
    Posts
    10,665
    Thanks
    53
    Thanked
    384 times in 313 posts
    There are a couple of solutions to the printing problem ( data gets sent back to the local client in a particularly uncompressed format , making large print jobs a real problem. )

    I've not come accross that particular mail server before - does it talk to MAPI clients of is it a POP3 / IMAP only job ?
    my Virtualisation Blog http://jfvi.co.uk Virtualisation Podcast http://vsoup.net

  16. #16
    Jay
    Jay is offline
    Gentlemen.. we're history Jay's Avatar
    Join Date
    Aug 2006
    Location
    Jita
    Posts
    8,365
    Thanks
    304
    Thanked
    568 times in 409 posts
    thin clients was somthing I was looking into

    At first (during the test phase) I was just going to use standard PCs with a crippled version of Win XP.

    How are Terminal Service profiles different?

    scalix uses its own MAPI driver, its a fantastic solution as the web based mail is very very good. The only issue I have is that the Mapi is a bit slow. I have also used Samsung Contact and HP open mail.

    How would you do all this?
    Last edited by Jay; 10-01-2007 at 02:12 PM.

Page 1 of 3 123 LastLast

Thread Information

Users Browsing this Thread

There are currently 1 users browsing this thread. (0 members and 1 guests)

Similar Threads

  1. Computer on network has lost connection to network
    By Furton in forum Networking and Broadband
    Replies: 9
    Last Post: 19-08-2011, 04:31 PM
  2. Is this network config wierd? Expert opinion please.
    By notsobig in forum Networking and Broadband
    Replies: 9
    Last Post: 28-11-2006, 12:09 AM
  3. Adding laptops to a wireless network
    By Tringa in forum Networking and Broadband
    Replies: 4
    Last Post: 04-09-2005, 07:09 PM
  4. PCMCIA Network card in old laptop
    By pringle in forum Networking and Broadband
    Replies: 2
    Last Post: 17-08-2005, 01:18 PM
  5. Small Home Network Setup Problems
    By ToxicPanda in forum Help! Quick Relief From Tech Headaches
    Replies: 2
    Last Post: 08-09-2004, 11:36 PM

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •