Google Groups no longer supports new Usenet posts or subscriptions. Historical content remains viewable.
Dismiss

sbs2003 and remote office connection

0 views
Skip to first unread message

Thomas

unread,
Feb 12, 2005, 11:53:28 AM2/12/05
to
Hi,

A customer would like to connect the main office (sbs 2003 std) with their
remote office (new srv 2003 std), so that the remote office has connection
to the exchange server at main office, but store files locally.
I found a nice document about "Connecting a remote office to a small
business 2000 network" at
www.microsoft.com/technet/prodtechnol/sbs/2000/maintain/remotofc.mspx
Although this one is about sbs2000, I suppose the process is quite the same
with sbs2003.
But I would like to have some comments (or better; answers!) about the
following questions:
- I am very new with these permanent vpn connections, and I'm not sure I
understand the link between the configuration steps that should be done
using RRAS, and the vpn routers themselves (like cisco soho routers).
I mean: if these cisco (or other) routers are specialized with vpn
connections, do we still need to configure the vpn connection with RRAS? Or
is it:
Use RRAS if you have a "simple" router, but forget about RRAS if you have
vpn routers, as all connection parameters will be configured in the two
routers...
- Also, if we have to choose one, what is the best option: vpn through RRAS,
or vpn router ?
- Does somebody have a "simple" procedure on how to create such connection
between two sites?
- Did somebody ever used a vpn connection to connect a 2003 srv to a 2003
sbs ? Aren't there too many bottlenecks? Also, what kind of connection
should be used (this is in Europe, Belgium, so we have ADSL connections, but
not always so fast).

Many questions; I know... But the problem is that I do not want to test it
AFTER the hardware is purchased (imagine that this remote connection just
work too slowly); and I cannot test it before!

Thanks in advance,

Thomas

Wes

unread,
Feb 12, 2005, 12:15:14 PM2/12/05
to
Hi Thomas,

If you are only wanting to use the Exchange Server from your remote office
and those clients are using Windows XP Professional, I would initially opt
for using Exchange over the Internet. If you get your remote clients to
connect using the Remote Web Workplace, they can view instructions for
setting up Outlook 2003 to connect to your Exchange server over the
Internet.

This should be the simplest solution but will not allow your remote clients
to store and access files at your main office. For this, you can either use
a dial on-demand VPN connection between the two servers or a
router-to-router VPN. If the requirement to access files is rare, then you
could just rely on the client side VPN connection (you can download the
Connection Manager from RWW). You will need to make sure that you use
different IP ranges for each site, e.g. 192.168.16.2./24 for the SBS 2003
and 192.168.17.2 /24 for the Server 2003.

I have found the following information very useful in setting up a Main
office - Branch Office scenarios.


Connecting a Remote Office to a Small Business Server 2000 Network (Also
works with SBS 2003)
http://www.microsoft.com/technet/prodtechnol/sbs/2000/maintain/remotofc.mspx


Deploying Windows Server 2003 Terminal Server to Host User Desktops in a
Windows Small Business Server 2003 Environment
http://www.microsoft.com/technet/prodtechnol/sbs/2003/deploy/adstrmsr.mspx

Setting up a VPN Infrastructure for Remote Access and Site-to-Site Routing
http://www.microsoft.com/technet/community/chats/trans/network/vpn1120.mspx

Virtual Private Networking with Windows Server 2003: Deploying Site-to-Site
VPNs
http://www.microsoft.com/technet/prodtechnol/windowsserver2003/technologies/networking/vpndpls2.mspx

Virtual Private Networking with Windows Server 2003: An Example Deployment
http://www.microsoft.com/technet/prodtechnol/windowsserver2003/technologies/networking/vpnexamp.mspx

Virtual Private Networks for Windows Server 2003
http://www.microsoft.com/windowsserver2003/technologies/networking/vpn/default.mspx

816105 HOW TO: Create or Move a Global Catalog in Windows Server 2003
http://support.microsoft.com/?id=816105

Planning Global Catalog Server Placement
http://www.microsoft.com/resources/documentation/WindowsServ/2003/all/deployguide/en-us/Default.asp?url=/resources/documentation/windowsserv/2003/all/deployguide/en-us/dssbd_topo_dljo.asp

244474 How to force Kerberos to use TCP instead of UDP
http://support.microsoft.com/?id=244474

Disable "Slow Link Detection".

Modify the default user profile to include the registry value
GroupPolicyMinTransferRate with DWORD value of "0":

A. Under "HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\System",
create a value named as GroupPolicyMinTransferRate and give the value data
0.

B. Under "HKEY_CURRENT_USER\SOFTWARE\Policies\Microsoft\Windows\System",
create a value named as GroupPolicyMinTransferRate and give the value data
0.

C. Restart the client computer to take effect.

227260 How a Slow Link Is Detected for Processing User Profiles and Group
Policy
http://support.microsoft.com/?id=227260

Kind regards,

Wes


"Thomas" <thomas> wrote in message
news:%23MOIiNS...@TK2MSFTNGP12.phx.gbl...

Thomas

unread,
Feb 13, 2005, 1:29:50 PM2/13/05
to
Thanks for this detailed explanation and all the links... I will have a look
at these documents.
Regarding outlook rpc over http, do you mean this can work even if the
remote clients are not part of the domain? This should be the case here, as
the domain on the server 2003 would be different from the one on the sbs
2003...
And regarding the vpn, could you explain me the following:
- what is the best, a router to router vpn, or the dial on-demand vpn? The
budget is not that important, what we need is something that just work. I am
still trying to understand the difference between RRAS and a vpn router.
I suppose a hardware vpn router works better and faster than a software vpn
connection (like the one we use when configuring rras).
My experience is that, when I connect to the SBS at the office from my
laptop which is at home, using a ADSL connection (upload 194 kbps, download
3360 kbps) on both sides, the result is that the logon script executes very
slowly, and opening or saving simple word documents can take ages. Is it
because we own only rubbish routers (these are only speedtouch adsl modems)
? Or maybe a config problem (I see you posted something about slow link
detection, maybe this will help?)
So I'd like to know if a better router will help that kind of connection to
go faster...

Thanks for your kind help!

Thomas

thl atnospam nextservices.be

"Wes" <wes...@online.ntlworld.com> wrote in message
news:uRAVyaS...@TK2MSFTNGP12.phx.gbl...

Wes

unread,
Feb 13, 2005, 6:18:43 PM2/13/05
to
Hi Thomas,

Yes, RPC over HTTP will work when the remote clients are not part of the
domain but you will need to have an account on the SBS domain.

SBS will not trust any other domains and you cannot have child domains so
you probably aren't going to benefit from setting up a VPN between the two
sites:
http://www.microsoft.com/WindowsServer2003/sbs/techinfo/overview/generalfaq.mspx

When you are talking about upload and download speeds, you need to bear in
mind that both ends will be uploading to each other and therefore, both ends
will be limited to the others maximum upload speed, i.e. 194 kbps at best.

Kind regards,

Wes

"Thomas" <thomas> wrote in message

news:ekfiDof...@TK2MSFTNGP12.phx.gbl...

GrahamS

unread,
Feb 14, 2005, 4:52:28 AM2/14/05
to
Hi Thomas.

I have recently completed a similar operation (last week in fact), so
thought you might be interested in my experience.

We have SBS2003 in the main office. We have set up a remote office with 10
users. Like you, I wanted them to access files locally, but use exchange for
mail. They also needed access to an accounts package in the main office.

As far as your specific questions:

If you use dedicated VPN routers you need not bother with RRAS. Just
rememeber to to set the IP address of the relevant router as the default
gateway on the relevant subnet. My VPN is managed by an external security
company, so I nfind that nice and straightforward.

As far as bottlenecks, not had any problems so far , but we have a
reasonably meaty 1MB SDSL link. I have used an ADSL link in a remote office
previosuly (minus the W2K3 server) and had many moans from users about
speed.

I am in the UK and am using SDSL. This is fairly new to the UK, so could not
tell you how widespread it is in Europe.

If you have any more questions I can try and answer from my experience on
this, but can't claim to be an expert on this. Jeff Middleton kindly helped
me out, you may want to find my post of 13 Jan in this group and Jeff's
comprehensive reply.

Good luck
Graham

"Thomas" <thomas> wrote in message
news:%23MOIiNS...@TK2MSFTNGP12.phx.gbl...

Thomas

unread,
Feb 15, 2005, 3:16:20 AM2/15/05
to
Thanks Wes and Graham for your so kind help...
I am still thinking about the ideal solution (very difficult; as SDSL
connections are still very expensive in Belgium and France, around
500?/month for a guaranteed speed of 256 Kbps and 1024 peak)
Graham, I already had a look at your post (dated 13 Jan) a few days ago ;-)
So what is your feeling about the current situation ? If I understand, you
installed a W2K3 server at the remote office, and a SBS2003 at the main
office? Does such a connection just act as a "long cable" between the two
sites ? I mean, can you just ping every workstation at each location, use
remote web workplace and so on ?

Kind regards,

Thomas

"GrahamS" <gra...@THESEBITS.schoeys.com.WRONG> wrote in message
news:u2fyoqnE...@TK2MSFTNGP10.phx.gbl...

GrahamS

unread,
Feb 15, 2005, 4:39:19 AM2/15/05
to
At present the situation is working well. The traffic use means that at
present the performance across the VPN is very good. As all files are
accessed locally in the offices the only real traffic is exchange, AD
'chatter' and some terminal services sessions. We actually still have an
ADSL line that the main office uses for mail and internet, so as to keep
traffic off of the SDSL

As far as use is concerned the VPN is invisible to users, so yes you can
ping machines across it, use resources at each end, etc. You just need to
get the configuration right. Things like remembering to give the other
subnet access to your internal websites in IIS on the SBS box, and setting
the VPN routers as the default gateways for their respective subnets.

Also one thing which I discovered when getting it working is that the
intersite mesaging service is turned off in SBS by default (or it was on
mine), you need to set this to auto if you are wanting to use the remote
W2K3 box as a domain controller.

I have had experience of using ADSL VPN's into an SBS box (with no W2K3
server in the remote office) but the performance was nowhere near as good as
with SDSL. File access was the main problem, so if you have a local file
server this may not be an issue.

As far as cost is concerned we pay 200GBpounds per month per connection for
1MB links (about 290Euros). This has become much cheaper in the past 12
months as competition in the UK is increasing in the market.

One other option to consider is the possibility of combining ADSL lines. The
VPN solution I am using does have the ability to 'bond' ADSL lines. That is
have 2 ADSL lines at each office to increase the upspeed. However the
hardware I use is managed by a security company and is not an out of the box
solution But you may want to look at whether anyone in your area is doing
anything similar, or indeed whether any commercial products offer this
option.

Hope this helps
Graham


"Thomas" <thomas> wrote in message

news:ekJwjazE...@TK2MSFTNGP10.phx.gbl...

Thomas

unread,
Feb 15, 2005, 5:16:32 AM2/15/05
to
Hi Graham,

I won't disturb you too long, but could you please give me some more info?
I'm very happy to find somebody that implemented the same solution I'm
expecting to set up, so I won't let you go!!!!
- what was your final choice: use the W2K3 as a DC, or not ? I think using
it as a DC will reduce vpn traffic, but I'm not sure how complicated it is
to implement. Maybe it's only following the wizard to add Domain Controller
Role, and then make it a global catalog server...
- which document did you find the most useful in order to make the
connection between the two sites? I had a look at the "Connecting a remote
office to a small business server 2000 network", but of course some of the
steps are not the same with 2K3.
- Also, when looking at your post dated 13 Jan, I see some explanations
about adding static routes using the "route add" command. Did you really had
to go so-deep in the configuration of each workstation and server? I thought
the concept of a site-to-site connection was to make a central gateway to
another network...

Have a nice day !

Thomas


"GrahamS" <gra...@THESEBITS.schoeys.com.WRONG> wrote in message

news:%23pny8H0...@TK2MSFTNGP09.phx.gbl...

GrahamS

unread,
Feb 15, 2005, 6:32:25 AM2/15/05
to
Hi Thomas

See inline below

"Thomas" <thomas> wrote in message

news:ujcvtd0E...@TK2MSFTNGP10.phx.gbl...


> Hi Graham,
>
> I won't disturb you too long, but could you please give me some more info?
> I'm very happy to find somebody that implemented the same solution I'm
> expecting to set up, so I won't let you go!!!!
> - what was your final choice: use the W2K3 as a DC, or not ? I think using
> it as a DC will reduce vpn traffic, but I'm not sure how complicated it is
> to implement. Maybe it's only following the wizard to add Domain
Controller
> Role, and then make it a global catalog server...

The W2K3 box is a DC. It is also a DNS server and DHCP server.

For DC follow the instructions from Jeff re DCPROMO.

Configure your sites in AD Sites and services. Make the W2K3 box a global
catalog

Add the new zone to the reverse lookup zone in DNS on the SBS box

Install DNS on the W2K3 box - Do NOT follow the wizards that pop up, cancel
them - it will replicate from the SBS box.
On the W2K3 box NIC leave the primary DNS pointing at the SBS box, secondary
at itself.

Install DHCP on the W2K3 box, set scope options (DNS, Gateway etc) -
remember to authorise the DHCP in AD


> - which document did you find the most useful in order to make the
> connection between the two sites? I had a look at the "Connecting a remote
> office to a small business server 2000 network", but of course some of the
> steps are not the same with 2K3.

I looked at the same document, but to be honest i got most help from this
Newsgroup. I also use the Mark Minasi Windows server book as a reference

> - Also, when looking at your post dated 13 Jan, I see some explanations
> about adding static routes using the "route add" command. Did you really
had
> to go so-deep in the configuration of each workstation and server? I
thought
> the concept of a site-to-site connection was to make a central gateway to
> another network...

If you are using a hardware VPN you do not need to create static routes.
Just set the router IP address as the default gateway address on the server
and in DHCP, or your static settings, whichever way you go.

One point to note on this though, I found that if you use the administrator
account to log on to the W2K3 box it will run it's login script,
unfortunately this changes the default gateway to whatever the default
gateway is on the main subnet every time you login!

Happy to be of help - I have had plenty from this newsgroup in the past

Graham

0 new messages