Connecting with VPN

Opinion
Feb 9, 20053 mins

* Help Desk columnist Ron Nutter helps a reader examine the benefits and drawbacks of cross-vendor VPN setups

Nutter helps a reader examine the benefits and drawbacks of cross-vendor VPN setups

We have a client that has an office in Montreal with about 20 stations and an office in Toronto with about 15. They each have a DSL connection to the Internet. Currently Montreal has a Netopia solution for connecting from home users to the office. They would like to connect via VPN from Toronto. They were thinking of simply purchasing a cheaper appliance, such as the Linksys VPN router, for Toronto and using that to connect to Montreal. Their vendor said they wouldn’t implement this as it is unreliable and suggested either purchasing a Netopia for Toronto or going high end with WatchGuard in both offices. We don’t have enough knowledge on VPNs and wanted your opinion on the Linksys solution. Is this really not feasible? Is it necessary to go to a higher solution? Is the Linksys VPN not secure?

Via the Internet

What you want to do is possible. I did something similar for a company I worked for several years ago. Although the processes behind making a VPN are pretty much standardized in terms of protocols, etc., what isn’t standardized is how each vendor chooses to implement the different protocols, the handshaking involved, etc. Where you get into problems is when you have one vendor’s solution at one end and a different vendor’s at the other. This is the situation I dealt with. What we saw is that the VPN worked for the most part but would drop unexplainably. This is where you start delving into the logs that each device generates and see what the errors are telling you.

In the configuration I had, we were using a first-generation Linksys VPN device (before the company was bought by Cisco) at the remote sites and a Nortel Contivity 1500 at the main office. We could get the VPN link to restore by power cycling the Linksys VPN box. The errors we saw indicated that the Nortel box was not accepting the link credentials. and the only way we got the problem fixed was to reset the Linksys end. Eventually, after weeks of working with both vendors, some updated firmware was released and configuration settings were changed. It eventually worked, but it took some effort to get it there. This is what your vendor was thinking about when it said the solution of mixed devices was unreliable.

Other readers of my column may have had better results implementing a cross-vendor VPN solution. Unless you have the time to devote to potentially debugging a problematic VPN link, spend a little more money now and get an identical device for each end of the link. An added bonus is that you will have the same management console for each end. Putting on firmware updates will also be easier since you will be able to get them from the same vendor.

You mentioned that each office has a DSL connection. If you don’t already have it, work with the ISPs at both ends and get a static IP address assigned. This makes it easier to establish and re-establish a VPN connection. If this isn’t an option, you will need to look at some type of dynamic DNS service that can resolve a host name to a changing IP address. Also make sure that the upload and download speeds on the DSL connections are the same. VPN connections are finicky enough at times but with a difference in upload/download speeds with enough usage you might get a timeout on the connection and have problems that you wouldn’t ordinarily see.