• Visitors can check out the Forum FAQ by clicking this link. You have to register before you can post: click the REGISTER link above to proceed. To start viewing messages, select the forum that you want to visit from the selection below. View our Forum Privacy Policy.
  • Want to receive the latest contracting news and advice straight to your inbox? Sign up to the ContractorUK newsletter here. Every sign up will also be entered into a draw to WIN £100 Amazon vouchers!

VPN Setup - Client and Host

Collapse
X
  •  
  • Filter
  • Time
  • Show
Clear All
new posts

    VPN Setup - Client and Host

    In the "Office" in Spain I want to set up a VPN with the "Office" in the UK so that for all intensive purpose Spain and the UK are presenting the same Public facing IP, I want to configure this at the router level in Spain so that anything attached to it automatically comes through to the UK, ideally so the LAN's can see each other freely as the main idea is to RDP to a server in the UK and then use that to pay HMRC etc as I am worried about the signal dropping out as we are half way up a mountain in the Sierra Nevada, if an RDP session drops no biggie, if a browser session drops while I am in the middle of paying Hector, biggie!!

    In Spain I am hoping to use an Asustex TR-AC66U Router to connect back to the UK, but what is the best software to host the VPN server, ideally I would like to also connect my MacBook Pro/iOS Devices while I am on the road as well as the Spanish router so I can use Time Machine when I am away from the office.

    Firstly is the possible (I assume so) secondly how is the best way to approach it?
    Originally posted by Stevie Wonder Boy
    I can't see any way to do it can you please advise?

    I want my account deleted and all of my information removed, I want to invoke my right to be forgotten.

    #2
    Not sure you can have the same public facing IP on both routers but you can certainly get a VPN between two sites.

    I prefer to use OpenVPN running on a server or individual PC and punch holes through the firewalls on the routers rather than use IPSec or other VPN facilities on routers directly as I've found the latter unreliable over mobile / 3G connections and suchlike and I think home class routers often aren't up to the job in terms of CPU/memory etc. I've used this to allow myself to VPN back home from all over the place.

    I've always gone with static routing, so basically, set up a host in wherever that communicates via the VPN tunnel to a host in the UK (that's one subnet), configure both hosts to route traffic between the VPN subnet and their local LAN subnets and then set up suitable static routes on the routers at both ends to tell them the local VPN host is a gateway to the LAN subnet at the other end of the pipe. You can also run the Open VPN client on a host PC and connect directly to the VPN in the case that you only need a single client, it's almost the same setup but the routing is a bit simpler.

    You can of course set up a direct router-router IPSec or SSL tunnel between two sites but as I say home class routers seem to struggle a bit with this so you might have to spend a bit of cash to get a reliable solution.
    Last edited by doodab; 21 February 2014, 17:25.
    While you're waiting, read the free novel we sent you. It's a Spanish story about a guy named 'Manual.'

    Comment


      #3
      Originally posted by doodab View Post
      Not sure you can have the same public facing IP on both routers but you can certainly get a VPN between two sites.

      I prefer to use OpenVPN running on a server or individual PC and punch holes through the firewalls on the routers rather than use IPSec or other VPN facilities on routers directly as I've found the latter unreliable over mobile / 3G connections and suchlike and I think home class routers often aren't up to the job in terms of CPU/memory etc. I've used this to allow myself to VPN back home from all over the place.

      I've always gone with static routing, so basically, set up a host in wherever that communicates via the VPN tunnel to a host in the UK (that's one subnet), configure both hosts to route traffic between the VPN subnet and their local LAN subnets and then set up suitable static routes on the routers at both ends to tell them the local VPN host is a gateway to the LAN subnet at the other end of the pipe. You can also run the Open VPN client on a host PC and connect directly to the VPN in the case that you only need a single client, it's almost the same setup but the routing is a bit simpler.

      You can of course set up a direct router-router IPSec or SSL tunnel between two sites but as I say home class routers seem to struggle a bit with this so you might have to spend a bit of cash to get a reliable solution.
      I'm not adverse to spending money on a business class setup if needed, I know I can do host to client on each machine but I was looking for something a bit more hardcore, ideally I don't want anyone to know the "other" office is out side the UK no matter what device is attached to it
      Originally posted by Stevie Wonder Boy
      I can't see any way to do it can you please advise?

      I want my account deleted and all of my information removed, I want to invoke my right to be forgotten.

      Comment


        #4
        Originally posted by SimonMac View Post
        I'm not adverse to spending money on a business class setup if needed, I know I can do host to client on each machine but I was looking for something a bit more hardcore, ideally I don't want anyone to know the "other" office is out side the UK no matter what device is attached to it
        You need to have a look at routers that will do a reliable site to site VPN then. I don't know about the Asustek ones, thay might be fine but I found various netgears and linksys I tried just didn't handle the site to site IPSec VPN well at all. Draytek ones seem to have a good rep but I've not actually tried them myself. As I say gave up on IPSec and went with OpenVPN (which is free) running on a couple of PCs and it was rock solid. Client co use it as well, though I'm not sure that's much of an endorsement

        If you want useful Cisco or similar kit you're looking at quite an outlay, so I'd probably avoid that. I did get a couple of cheap second hand ciscos working in a lab setup but they were old ones that would only support 8mb DSL cards and no wireless, and they are relatively complex to set up (and I say that having some previous IOS configuration experience).
        While you're waiting, read the free novel we sent you. It's a Spanish story about a guy named 'Manual.'

        Comment


          #5
          Originally posted by doodab View Post
          You need to have a look at routers that will do a reliable site to site VPN then. I don't know about the Asustek ones, thay might be fine but I found various netgears and linksys I tried just didn't handle the site to site IPSec VPN well at all. Draytek ones seem to have a good rep but I've not actually tried them myself. As I say gave up on IPSec and went with OpenVPN (which is free) running on a couple of PCs and it was rock solid. Client co use it as well, though I'm not sure that's much of an endorsement

          If you want useful Cisco or similar kit you're looking at quite an outlay, so I'd probably avoid that. I did get a couple of cheap second hand ciscos working in a lab setup but they were old ones that would only support 8mb DSL cards and no wireless, and they are relatively complex to set up (and I say that having some previous IOS configuration experience).
          The Cisco RV220W sounds like it does very thing needed and that's only £150 if I bridge the router given to my by my Spanish IP and use the Cisco for PPPoE
          Last edited by SimonMac; 21 February 2014, 18:07.
          Originally posted by Stevie Wonder Boy
          I can't see any way to do it can you please advise?

          I want my account deleted and all of my information removed, I want to invoke my right to be forgotten.

          Comment


            #6
            Originally posted by SimonMac View Post
            The Cisco RV220W sounds like it does very thing needed and that's only £150
            It may well do. I have one of their small business switches and it's excellent for the money. I'd check the reviews though as I know some of their older small business stuff was rebranded linksys after the buyout and it had issues like the config pages only working with IE6. I expect they have ironed those sort of problems out now though.

            I was looking at it a few years ago now to be fair, so the options were quite limited, My lab setup was with a couple of 2650XM or similar I got off ebay when I went through a "cisco lab" phase and I'd have needed a couple of 1800 or 8xx if I wanted wireless and ADSL2+ which would have set me back the best part of a grand at the time (would be worth **** all now probably)
            While you're waiting, read the free novel we sent you. It's a Spanish story about a guy named 'Manual.'

            Comment


              #7
              Originally posted by doodab View Post
              It may well do. I have one of their small business switches and it's excellent for the money. I'd check the reviews though as I know some of their older small business stuff was rebranded linksys after the buyout and it had issues like the config pages only working with IE6. I expect they have ironed those sort of problems out now though.

              I was looking at it a few years ago now to be fair, so the options were quite limited, My lab setup was with a couple of 2650XM or similar I got off ebay when I went through a "cisco lab" phase and I'd have needed a couple of 1800 or 8xx if I wanted wireless and ADSL2+ which would have set me back the best part of a grand at the time (would be worth **** all now probably)
              Problem is not sure of the setup of the Spanish ISP (might be a microwave link rather than DSL) so not sure what I can use as oner rather than sit behind another router as a bridge
              Originally posted by Stevie Wonder Boy
              I can't see any way to do it can you please advise?

              I want my account deleted and all of my information removed, I want to invoke my right to be forgotten.

              Comment


                #8
                Originally posted by SimonMac View Post
                Problem is not sure of the setup of the Spanish ISP (might be a microwave link rather than DSL) so not sure what I can use as oner rather than sit behind another router as a bridge
                Some places use different DSL flavours as well i.e. VDSL rather than ADSL and so on. The ideal is to have a separate modem that presents you with an Ethernet connection IMO.

                Having said that you should be able to plug a router with an ethernet WAN port into a LAN port on an existing router and use it as "just a modem". You might need to faff about with the port forwarding / DMZ on the first router to get everything working though. And switch all the NAT, firewall off etc as well.
                Last edited by doodab; 21 February 2014, 18:27.
                While you're waiting, read the free novel we sent you. It's a Spanish story about a guy named 'Manual.'

                Comment


                  #9
                  Originally posted by doodab View Post
                  Some places use different DSL flavours as well i.e. VDSL rather than ADSL and so on. The ideal is to have a separate modem that presents you with an Ethernet connection IMO.

                  Having said that you should be able to plug a router with an ethernet WAN port into a LAN port on an existing router and use it as "just a modem". You might need to faff about with the port forwarding / DMZ on the first router to get everything working though. And switch all the NAT, firewall off etc as well.
                  Most routers require the public facing IP to be used which is why if it's behind another router that needs to be bridged
                  Originally posted by Stevie Wonder Boy
                  I can't see any way to do it can you please advise?

                  I want my account deleted and all of my information removed, I want to invoke my right to be forgotten.

                  Comment


                    #10
                    Originally posted by SimonMac View Post
                    Most routers require the public facing IP to be used which is why if it's behind another router that needs to be bridged
                    Yes so easiest way to do that (IMO) with a router with an ethernet WAN port is to plug the WAN port on the second router into a LAN port on the first one and have it pick up an IP address from the first one, then set up forwarding on the first one so that all traffic to the WAN IP on the first router is forwarded to that LAN address, effectively just passing everything through the first router as if it's "just a modem" albeit with NAT as well. That way all outgoing traffic appears to come from the WAN IP and you can let the second router handle the NAT & firewall duties etc for your actual devices and it should be able to tunnel out for VPN as well.

                    The best bet is to replace the old router with a new one ideally though.
                    While you're waiting, read the free novel we sent you. It's a Spanish story about a guy named 'Manual.'

                    Comment

                    Working...
                    X