Setup site to site vpn
-
Hello Everyone,
I'm currently working for a Non-profit Organization, and it has a total of six locations with five satellite offices. My boss wanted to connect the other five satellite offices to the main office, without costing the Organization much money. I've been researching and reading a lot of articles on the internet to find a cost effective way in doing this, and finally I decided to opt for the open source option.
I've heard and read a lot of good thing about pfsense and m0n0wall open source firewall on the internet about setting up a site to site vpn to connect satellite offices to become one network. However, I'm new pfsense and m0nowall therefore I don't know which open source firewall is better that I should go with to accomplish this task. Please, give me some advice and input. Thanks
-
pfSense of course
(Well, if you're going to ask the question on the pfSense forums… ;) )
You may want to read the sticky at the top of the OpenVPN section - the tutorial that includes site-to-site setup details.
-
Hi Cry Havok,
Thanks for your prompt reply. I don't know if you can answer my next question or not, but I'll ask you anyway since you are the only person reply to my post. If I setup pfsense with OpenVPN or IPsec site to site VPN, will it be able to handle the workload for my remote user to authenticate to my domain at the main office. Should I setup OpenVPN site to site VPN or IPsec site to site VPN? Thanks again
-
Yes|No|Maybe
Without ANY information on the hardware you're intending to use, the bandwidths available at each site or how much traffic you expect, there's no way to provide you with an answer. I'd generally advise that you set up authentication servers at each site. That way you only have to cope with the authentication syncs (password changes, new users), which can be handled even over a dialup. More importantly, it means people can continue working when they can't connect to the main site (such as when your power goes out, or somebody puts a digging machine through your Internet connection).
As for OpenVPN or IPSec, either IMO - pick the one that you're more comfortable with managing and setting up.
-
I'd generally advise that you set up authentication servers at each site. That way you only have to cope with the authentication syncs (password changes, new users), which can be handled even over a dialup. More importantly, it means people can continue working when they can't connect to the main site (such as when your power goes out, or somebody puts a digging machine through your Internet connection).
That's very good point. I will consider this kind of setup when I actually setup the site to site vpn. Thank you very much