A customer would like to connect the main office (sbs 2003 std) with their
remote office (new srv 2003 std), so that the remote office has connection
to the exchange server at main office, but store files locally.
I found a nice document about "Connecting a remote office to a small
business 2000 network" at
www.microsoft.com/technet/prodtechnol/sbs/2000/maintain/remotofc.mspx
Although this one is about sbs2000, I suppose the process is quite the same
with sbs2003.
But I would like to have some comments (or better; answers!) about the
following questions:
- I am very new with these permanent vpn connections, and I'm not sure I
understand the link between the configuration steps that should be done
using RRAS, and the vpn routers themselves (like cisco soho routers).
I mean: if these cisco (or other) routers are specialized with vpn
connections, do we still need to configure the vpn connection with RRAS? Or
is it:
Use RRAS if you have a "simple" router, but forget about RRAS if you have
vpn routers, as all connection parameters will be configured in the two
routers...
- Also, if we have to choose one, what is the best option: vpn through RRAS,
or vpn router ?
- Does somebody have a "simple" procedure on how to create such connection
between two sites?
- Did somebody ever used a vpn connection to connect a 2003 srv to a 2003
sbs ? Aren't there too many bottlenecks? Also, what kind of connection
should be used (this is in Europe, Belgium, so we have ADSL connections, but
not always so fast).
Many questions; I know... But the problem is that I do not want to test it
AFTER the hardware is purchased (imagine that this remote connection just
work too slowly); and I cannot test it before!
Thanks in advance,
Thomas
If you are only wanting to use the Exchange Server from your remote office
and those clients are using Windows XP Professional, I would initially opt
for using Exchange over the Internet. If you get your remote clients to
connect using the Remote Web Workplace, they can view instructions for
setting up Outlook 2003 to connect to your Exchange server over the
Internet.
This should be the simplest solution but will not allow your remote clients
to store and access files at your main office. For this, you can either use
a dial on-demand VPN connection between the two servers or a
router-to-router VPN. If the requirement to access files is rare, then you
could just rely on the client side VPN connection (you can download the
Connection Manager from RWW). You will need to make sure that you use
different IP ranges for each site, e.g. 192.168.16.2./24 for the SBS 2003
and 192.168.17.2 /24 for the Server 2003.
I have found the following information very useful in setting up a Main
office - Branch Office scenarios.
Connecting a Remote Office to a Small Business Server 2000 Network (Also
works with SBS 2003)
http://www.microsoft.com/technet/prodtechnol/sbs/2000/maintain/remotofc.mspx
Deploying Windows Server 2003 Terminal Server to Host User Desktops in a
Windows Small Business Server 2003 Environment
http://www.microsoft.com/technet/prodtechnol/sbs/2003/deploy/adstrmsr.mspx
Setting up a VPN Infrastructure for Remote Access and Site-to-Site Routing
http://www.microsoft.com/technet/community/chats/trans/network/vpn1120.mspx
Virtual Private Networking with Windows Server 2003: Deploying Site-to-Site
VPNs
http://www.microsoft.com/technet/prodtechnol/windowsserver2003/technologies/networking/vpndpls2.mspx
Virtual Private Networking with Windows Server 2003: An Example Deployment
http://www.microsoft.com/technet/prodtechnol/windowsserver2003/technologies/networking/vpnexamp.mspx
Virtual Private Networks for Windows Server 2003
http://www.microsoft.com/windowsserver2003/technologies/networking/vpn/default.mspx
816105 HOW TO: Create or Move a Global Catalog in Windows Server 2003
http://support.microsoft.com/?id=816105
Planning Global Catalog Server Placement
http://www.microsoft.com/resources/documentation/WindowsServ/2003/all/deployguide/en-us/Default.asp?url=/resources/documentation/windowsserv/2003/all/deployguide/en-us/dssbd_topo_dljo.asp
244474 How to force Kerberos to use TCP instead of UDP
http://support.microsoft.com/?id=244474
Disable "Slow Link Detection".
Modify the default user profile to include the registry value
GroupPolicyMinTransferRate with DWORD value of "0":
A. Under "HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\System",
create a value named as GroupPolicyMinTransferRate and give the value data
0.
B. Under "HKEY_CURRENT_USER\SOFTWARE\Policies\Microsoft\Windows\System",
create a value named as GroupPolicyMinTransferRate and give the value data
0.
C. Restart the client computer to take effect.
227260 How a Slow Link Is Detected for Processing User Profiles and Group
Policy
http://support.microsoft.com/?id=227260
Kind regards,
Wes
"Thomas" <thomas> wrote in message
news:%23MOIiNS...@TK2MSFTNGP12.phx.gbl...
Thanks for your kind help!
Thomas
thl atnospam nextservices.be
"Wes" <wes...@online.ntlworld.com> wrote in message
news:uRAVyaS...@TK2MSFTNGP12.phx.gbl...
Yes, RPC over HTTP will work when the remote clients are not part of the
domain but you will need to have an account on the SBS domain.
SBS will not trust any other domains and you cannot have child domains so
you probably aren't going to benefit from setting up a VPN between the two
sites:
http://www.microsoft.com/WindowsServer2003/sbs/techinfo/overview/generalfaq.mspx
When you are talking about upload and download speeds, you need to bear in
mind that both ends will be uploading to each other and therefore, both ends
will be limited to the others maximum upload speed, i.e. 194 kbps at best.
Kind regards,
Wes
"Thomas" <thomas> wrote in message
news:ekfiDof...@TK2MSFTNGP12.phx.gbl...
I have recently completed a similar operation (last week in fact), so
thought you might be interested in my experience.
We have SBS2003 in the main office. We have set up a remote office with 10
users. Like you, I wanted them to access files locally, but use exchange for
mail. They also needed access to an accounts package in the main office.
As far as your specific questions:
If you use dedicated VPN routers you need not bother with RRAS. Just
rememeber to to set the IP address of the relevant router as the default
gateway on the relevant subnet. My VPN is managed by an external security
company, so I nfind that nice and straightforward.
As far as bottlenecks, not had any problems so far , but we have a
reasonably meaty 1MB SDSL link. I have used an ADSL link in a remote office
previosuly (minus the W2K3 server) and had many moans from users about
speed.
I am in the UK and am using SDSL. This is fairly new to the UK, so could not
tell you how widespread it is in Europe.
If you have any more questions I can try and answer from my experience on
this, but can't claim to be an expert on this. Jeff Middleton kindly helped
me out, you may want to find my post of 13 Jan in this group and Jeff's
comprehensive reply.
Good luck
Graham
"Thomas" <thomas> wrote in message
news:%23MOIiNS...@TK2MSFTNGP12.phx.gbl...
Kind regards,
Thomas
"GrahamS" <gra...@THESEBITS.schoeys.com.WRONG> wrote in message
news:u2fyoqnE...@TK2MSFTNGP10.phx.gbl...
As far as use is concerned the VPN is invisible to users, so yes you can
ping machines across it, use resources at each end, etc. You just need to
get the configuration right. Things like remembering to give the other
subnet access to your internal websites in IIS on the SBS box, and setting
the VPN routers as the default gateways for their respective subnets.
Also one thing which I discovered when getting it working is that the
intersite mesaging service is turned off in SBS by default (or it was on
mine), you need to set this to auto if you are wanting to use the remote
W2K3 box as a domain controller.
I have had experience of using ADSL VPN's into an SBS box (with no W2K3
server in the remote office) but the performance was nowhere near as good as
with SDSL. File access was the main problem, so if you have a local file
server this may not be an issue.
As far as cost is concerned we pay 200GBpounds per month per connection for
1MB links (about 290Euros). This has become much cheaper in the past 12
months as competition in the UK is increasing in the market.
One other option to consider is the possibility of combining ADSL lines. The
VPN solution I am using does have the ability to 'bond' ADSL lines. That is
have 2 ADSL lines at each office to increase the upspeed. However the
hardware I use is managed by a security company and is not an out of the box
solution But you may want to look at whether anyone in your area is doing
anything similar, or indeed whether any commercial products offer this
option.
Hope this helps
Graham
"Thomas" <thomas> wrote in message
news:ekJwjazE...@TK2MSFTNGP10.phx.gbl...
I won't disturb you too long, but could you please give me some more info?
I'm very happy to find somebody that implemented the same solution I'm
expecting to set up, so I won't let you go!!!!
- what was your final choice: use the W2K3 as a DC, or not ? I think using
it as a DC will reduce vpn traffic, but I'm not sure how complicated it is
to implement. Maybe it's only following the wizard to add Domain Controller
Role, and then make it a global catalog server...
- which document did you find the most useful in order to make the
connection between the two sites? I had a look at the "Connecting a remote
office to a small business server 2000 network", but of course some of the
steps are not the same with 2K3.
- Also, when looking at your post dated 13 Jan, I see some explanations
about adding static routes using the "route add" command. Did you really had
to go so-deep in the configuration of each workstation and server? I thought
the concept of a site-to-site connection was to make a central gateway to
another network...
Have a nice day !
Thomas
"GrahamS" <gra...@THESEBITS.schoeys.com.WRONG> wrote in message
news:%23pny8H0...@TK2MSFTNGP09.phx.gbl...
See inline below
"Thomas" <thomas> wrote in message
news:ujcvtd0E...@TK2MSFTNGP10.phx.gbl...
> Hi Graham,
>
> I won't disturb you too long, but could you please give me some more info?
> I'm very happy to find somebody that implemented the same solution I'm
> expecting to set up, so I won't let you go!!!!
> - what was your final choice: use the W2K3 as a DC, or not ? I think using
> it as a DC will reduce vpn traffic, but I'm not sure how complicated it is
> to implement. Maybe it's only following the wizard to add Domain
Controller
> Role, and then make it a global catalog server...
The W2K3 box is a DC. It is also a DNS server and DHCP server.
For DC follow the instructions from Jeff re DCPROMO.
Configure your sites in AD Sites and services. Make the W2K3 box a global
catalog
Add the new zone to the reverse lookup zone in DNS on the SBS box
Install DNS on the W2K3 box - Do NOT follow the wizards that pop up, cancel
them - it will replicate from the SBS box.
On the W2K3 box NIC leave the primary DNS pointing at the SBS box, secondary
at itself.
Install DHCP on the W2K3 box, set scope options (DNS, Gateway etc) -
remember to authorise the DHCP in AD
> - which document did you find the most useful in order to make the
> connection between the two sites? I had a look at the "Connecting a remote
> office to a small business server 2000 network", but of course some of the
> steps are not the same with 2K3.
I looked at the same document, but to be honest i got most help from this
Newsgroup. I also use the Mark Minasi Windows server book as a reference
> - Also, when looking at your post dated 13 Jan, I see some explanations
> about adding static routes using the "route add" command. Did you really
had
> to go so-deep in the configuration of each workstation and server? I
thought
> the concept of a site-to-site connection was to make a central gateway to
> another network...
If you are using a hardware VPN you do not need to create static routes.
Just set the router IP address as the default gateway address on the server
and in DHCP, or your static settings, whichever way you go.
One point to note on this though, I found that if you use the administrator
account to log on to the W2K3 box it will run it's login script,
unfortunately this changes the default gateway to whatever the default
gateway is on the main subnet every time you login!
Happy to be of help - I have had plenty from this newsgroup in the past
Graham