Network Connections Hardware and Operating System VPN Package

169

11.3.3 VPN Package

The Cisco PIX Firewall is implemented at these locations for connections to the central office and to provide network security against Internet-based attacks. These branch offices also use PPTP for their remote access users, and for incoming connections from the small branch offices. Users run PPTP client on their Windows NT, Windows 95, or Macintosh workstations.

11.4 Small Branch Offices

Small branch office sites host very few resources to share—certainly not major web pages that are expected to get lots of hits—but they need continuous and reliable access to the larger offices.

11.4.1 Connection

The smaller branch offices maintain either dedicated or dynamic ISDN connections to their Internet service providers. Some offices use the same national service provider as the corporate office, while others use providers who maintain upstream connections through the same networks as the corporate office. Though this does not affect the basic functionality of the VPN, it does increase the speed and reliability of the connection between sites.

11.4.2 Hardware and Operating System

Small branch offices use the Ascend Pipeline 50 ISDN router for their Internet connection. The Ascend supports PPTP, and routes Internet traffic for up to 255 IP addresses. A Windows NT or Unix server is utilized at each site to validate incoming PPTP users and to connect to the VPN.

11.4.3 VPN Package

A PPTP server and client are used at each site for accessing the VPN.

11.5 Remote Access Users

Remote access users include those on the road and those working off-site.

11.5.1 Connection

A variety of connection methods are used, from ISDN to analog phone lines and modems. Again, the best scenario is to have all remote access users connect through the same national provider as the rest of the corporate network or through a provider who is on the same network.

11.5.2 Hardware and Operating System

Individual users can have a variety of platforms, from Windows NT or Windows 95 workstations to Unix to MacOS. ISDN routers, terminal adapters, or analog modems could all be in use.