VPN

Discussion in 'Networks' started by kat731, Aug 2, 2007.

  1. kat731
    Honorary Member

    kat731 Megabyte Poster

    826
    9
    74
    Hi all,

    could someone help me with a guide to accessing my work via remote VPN?
    My IT manager dosent know, so i guess i could help him too.

    I have all the IP addresses etc, would i have to put a static on my home router?

    All help appeciated.

    Kat
     
    Certifications: BA (Hons), A+
    WIP: 70-685 77-884
  2. zebulebu

    zebulebu Terabyte Poster

    3,748
    330
    187
    Hi Kev

    Establishing a VPN connection is not a simple process. You need to make sure you're properly NATed at both ends, have opened the requisite ports on your firewall, have firewalls which don't mung IPSec traffic and decide whether you are going to used a software based approach, or an SSL browser-based one.

    I don't suppose there's any chance of you providing us with all the necessary information on your network configuration (nor should you - you'd be sacked straightaway for doing it!) so you'll just have to do a bit of reading and decide which way you want to go.

    Of course, providing you can establish an HTTP connection to your machine from the net you could always just install something like LogMeIn on it and access it that way - all communication is made securely over SSL via LogMeIn's servers and, provided you are sensible about choosing passwords, there is arguably less security risk in connecting remotely that way than there would be if you installed a misconfigured VPN
     
    Certifications: A few
    WIP: None - f*** 'em
  3. hbroomhall

    hbroomhall Petabyte Poster Gold Member

    6,624
    117
    224
    You could do a *simple* VPN by using VNC which has the nice property of being free. Run it over SSH (i.e. use Putty to do this) and it is pretty secure.

    This should work in most situations, unless the firewalls at your place are very tight.

    Harry.
     
    Certifications: ECDL A+ Network+ i-Net+
    WIP: Server+
  4. zebulebu

    zebulebu Terabyte Poster

    3,748
    330
    187
    Like at my place?

    :)
     
    Certifications: A few
    WIP: None - f*** 'em
  5. kat731
    Honorary Member

    kat731 Megabyte Poster

    826
    9
    74
    Thanks Stu, H,

    Thought it would be complex.. Think i'll leave VPN to the Astaro guys who are coming back soon to put our 4 remote sites back on VPN. I'll look at Logmein and VNC, Would be ok to put Logmein on the server?

    Kat
     
    Certifications: BA (Hons), A+
    WIP: 70-685 77-884
  6. Arroryn

    Arroryn we're all dooooooomed Moderator

    4,015
    193
    209
    Hey Kev,

    When you say you want to access work, to what kind of extent do you mean?

    i.e., do you want to just pick up emails from your Exchange server, or do you need to access servers, databases, and a full shebang of information?
     
    Certifications: A+, N+, MCDST, 70-410, 70-411
    WIP: Modern Languages BA
  7. kat731
    Honorary Member

    kat731 Megabyte Poster

    826
    9
    74
    Actually i noticed Symantec PC Anywhere on the server today, do you think the last IT manager may have been using that for his home connection?

    Kat
     
    Certifications: BA (Hons), A+
    WIP: 70-685 77-884
  8. kat731
    Honorary Member

    kat731 Megabyte Poster

    826
    9
    74
    Hey Dawn,

    the shebang would be good...

    Kev
     
    Certifications: BA (Hons), A+
    WIP: 70-685 77-884
  9. hbroomhall

    hbroomhall Petabyte Poster Gold Member

    6,624
    117
    224
    It is possible.

    VNC is a sort of free equivalent of PCA.

    Harry.
     
    Certifications: ECDL A+ Network+ i-Net+
    WIP: Server+
  10. hbroomhall

    hbroomhall Petabyte Poster Gold Member

    6,624
    117
    224
    The whole point of things like PCA and VNC is that you have your work screen transmitted to your home PC screen. So anything you would do on the work machine you could do (up to a point) at home.

    The main problem is speed. Because of the amount of data that has to be shipped anything fast moving (e.g. a video) won't work.

    Harry.
     
    Certifications: ECDL A+ Network+ i-Net+
    WIP: Server+
  11. Sparky
    Highly Decorated Member Award 500 Likes Award

    Sparky Zettabyte Poster Moderator

    10,718
    543
    364
    Have some users at work requested remote access yet? Only a matter of time if they haven’t! :biggrin

    There are many options and it also depends on what firewall you are running. Do you still have the Sonicwall in place? If so it has its own VPN client software which is fairly straight forward to set up.

    Once you have established a connection from home you can then remote desktop onto your servers. 8)
     
    Certifications: MSc MCSE MCSA:M MCSA:S MCITP:EA MCTS(x5) MS-900 AZ-900 Security+ Network+ A+
    WIP: Microsoft Certs
  12. Steve.L

    Steve.L Byte Poster

    105
    4
    22
    Hi Kat

    There's a brilliant little tool that makes setting up a Vpn an absolute synch, I use it all the time works gr8 and you can use remote desktop to do what you need to do after connecting (yeah its a real vpn :) its called Hamachi, just google it, and best of all its totally free for your own use.

    Hth

    Steve.L
     
    Certifications: N+, MCP, MCTS, RHCT, VCP4 and 5, RHCSA
    WIP: ccna
  13. kat731
    Honorary Member

    kat731 Megabyte Poster

    826
    9
    74
    Thanks guys, will check that thing Steve.
    Spark, just logged onto sonicwall and yes i see the vpns, the old it manager is still there, could you help me figure out how i configure it for my home pc? thanks Spark. I'll keep playing and searching in the meantime.

    Kat
     
    Certifications: BA (Hons), A+
    WIP: 70-685 77-884
  14. Sparky
    Highly Decorated Member Award 500 Likes Award

    Sparky Zettabyte Poster Moderator

    10,718
    543
    364
    Ok, select VPN and then go into the properties of the ‘GroupVPN’ Select IKE with pre-shared key, at the bottom of the Window type a random pre-shared key. Save changes and make sure the group VPN is enabled.

    Go into users and create a new user. Make sure all options are enabled except ‘limited user’ (or something like that).

    Click on network>settings and make a note of the WAN IP.
    You now need the Sonicwall Global VPN software; you can download that from mysonicwall.com. You should have a username and password when you registered the firewall. If not create an account and download the VPN client software however there is a CD included with the firewall which has all the software included but it is probably out of date.

    On your PC at home install the Global VPN software. Once installed start the new connection wizard, give the connection a friendly name and put your WAN IP address in as well. Once connected you will be prompted for the pre-shared key, type it in and then you will be prompted for a username and password. The first time you connect you have to type your username and password twice, just a Sonicwall thing!

    Try to ping your server by IP address, if you get a response then fire up remote desktop and away you go! :biggrin
     
    Certifications: MSc MCSE MCSA:M MCSA:S MCITP:EA MCTS(x5) MS-900 AZ-900 Security+ Network+ A+
    WIP: Microsoft Certs
  15. kat731
    Honorary Member

    kat731 Megabyte Poster

    826
    9
    74
    Spark, always there for me!!!

    Will try on Monday and post.
    Met my old IT Manager for a drink after work, he said be better to use the Astaro with L2TP. So, got alot of playing to do Monday.

    Kat
     
    Certifications: BA (Hons), A+
    WIP: 70-685 77-884
  16. Sparky
    Highly Decorated Member Award 500 Likes Award

    Sparky Zettabyte Poster Moderator

    10,718
    543
    364
    Yeah, depends how your network is setup. The Sonicwall will only support one VPN connection out the box unless you add a license for extra users. 8)
     
    Certifications: MSc MCSE MCSA:M MCSA:S MCITP:EA MCTS(x5) MS-900 AZ-900 Security+ Network+ A+
    WIP: Microsoft Certs

Share This Page

Loading...
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.