|
|
|
We are today looking at an example of how to construct a large VPN hub/spoke structure for a modest budget. We are going to be using the Billion 7560 router which is a fabulous little device with excellent content management capability and can be obtained as a wireless model (the 7560G) for less than 40 GBPs. One of the many features I really like about this router (apart from great QoS, A brilliant interface and sound design) is that it supports 256-bit AES IPSec encryption with SHA1 group 5. This means we can use the full encryption capability of the DrayTek Vigor 3300 to each and every satellite office. Each system will require access to the server at the head office but not access to any other site. Email will be routed from an Exchange server at head office and each office will use the files and permissions from a DC at the head office. The Billion will support just a few VPNs but the Vigor (depending on what you are reading) can support either 128 or 200. We will just quickly go through the setup for a single instance of a Draytek-Billion VPN. Firstly on the Draytek: Open the IPSec policy page:
Then edit an IPSec Policy: The following values need to be filled: Basic
Local Gateway WAN Interface - which of the four WAN interfaces the VPN will connect through. Be careful here you are using the correct WAN with the correct endpoint IP or domain name as this can make or break a connection. Local Certificate: Choose the correct cert here Security Gateway:
|
|
|
Questions or problems regarding this
Computer Help Forum
should
be directed to
webmaster@ReadAllAboutIT.org.uk
|