DrayTek UK Users' Community Forum

Help, Advice and Solutions from DrayTek Users

Newbie help with VPN and 2830

  • dansw
  • Topic Author
  • User
  • User
More
13 Jan 2016 16:23 #1 by dansw
Newbie help with VPN and 2830 was created by dansw
Hi, please bear with me I am pretty new to VPN hence the 'daft' questions that follow!

I look after a small LAN at work with a couple of Win2008 servers. We have a Draytek 2830 that manages our broadband and some of our external database developers RDP into one of our servers based on rules that only allow their fixed ip in.

Based on this I wanted to be able to access the servers, or maybe my own workstation, from my home Windows 7 PC. Unfortunately I am not on a static IP at home so cannot have a rule based on a dynamically assigned ip. So, for the first time, I've started to look at VPN.

I have seen the various Draytek tutorials on this subject. I quite like the ease of SSL VPN Tunnel:

http://www.draytek.com/index.php?option=com_k2&view=item&id=2035&Itemid=293&lang=en

My questions are:

1. Is this way preferred/more secure/easier than the others available i.e PPTP, IPsec Tunnel and L2TP with IPsec Policy in SSL VPN >> Remote Dial-in User?

2. Regarding the selections above I see that sometimes they are all ticked. I assume that once I have chosen the one I am happy with, only that one needs to be ticked? I was worried about any dependencies they might have on each other?

3. This might be the thickie question :oops: but with RDP and port forwarding you can remotely access a specific machine so the external user comes in on a particular port that forwards it to the relveant IP and subsequent login of the machine. With VPN, how do you get to a machine on the rmeote LAN this way? So if I wanted to specifically connect to the server from my PC at home, I would establish the VPN..then what?

Thanks in advance for any advice!

Dan

Please Log in or Create an account to join the conversation.

More
13 Jan 2016 20:36 #2 by erudit
Replied by erudit on topic Re: Newbie help with VPN and 2830
Simple answer SSL should be the easiest VPN and most reliable as it uses a port that should be available from all over the world and on internet café internet, they are all capable of providing secure connectivity to your office premises.

Once you are connected to the VPN all of your internet traffic will be redirected to the work router.

if you where to open remote desktop while connected to the vpn and type in one of the servers at work this should connect without any further configuration.

Regards

Matt

Please Log in or Create an account to join the conversation.

  • dansw
  • Topic Author
  • User
  • User
More
14 Jan 2016 09:22 #3 by dansw
Replied by dansw on topic Re: Newbie help with VPN and 2830
Thanks for the clarification Matt, I shall now proceed to give that a go. And can I safely ubntick the other protocols I won't be using?

Thanks

Dan

Please Log in or Create an account to join the conversation.

  • dansw
  • Topic Author
  • User
  • User
More
19 Jan 2016 17:02 #4 by dansw
Replied by dansw on topic Re: Newbie help with VPN and 2830
Thanks, I got connected last night but I had to use the Smart VPN Client as the latest Java Security Cofiguration for Windows 8 didn't have the exact TLS/SSL options as indicated in the aforementioned tutorial. I was then able to RDP to one of the servers by inputting its LAN IP address. A lot easier than I thought!

Please Log in or Create an account to join the conversation.

  • dansw
  • Topic Author
  • User
  • User
More
28 Jan 2016 10:03 #5 by dansw
Replied by dansw on topic Re: Newbie help with VPN and 2830
Hi again, is there any way to have split tunneling? I only realised last night when testing SSL VPN using Smart VPN that all traffic goes to the VPN so my local internet ceases to work....?

Please Log in or Create an account to join the conversation.

  • dansw
  • Topic Author
  • User
  • User
More
29 Jan 2016 10:07 #6 by dansw
Replied by dansw on topic Re: Newbie help with VPN and 2830
OK, for reference the SmartVPN client should do this when you un-tick 'Use default gateway on remote network'.

Please Log in or Create an account to join the conversation.