Petri IT Knowledgebase Forums
 

Petri.co.il forums Home Forums Start Page Forums Frequently Asked Questions FAQ Member List Members List
Go Back   Petri IT Knowledgebase Forums > Microsoft Networking Services > Active Directory
Petri.co.il is happy to award auglan the title of Most Valuable Member !!!
Register Calendar Calendar Search Petri IT Knowledgebase Forums Search Todays Posts Today's Posts Mark Forums Read

Notices

multi site - no vpn

multi site - no vpn

this thread has 5 replies and has been viewed 1966 times

Closed Thread
 
Thread Tools Search this Thread Display Modes
  #1  
Old 22nd January 2007, 12:04
may_east may_east is offline
Casual
Casual
 
 Join Date: Jan 2007
  6 month star 12 month star
 Posts: 3
 Reputation: may_east is on a distinguished road (10)
Default multi site - no vpn

Hi.

excuse me as i am a newbie .

My client is an organization that has multiple branches around the world.
the connection between the branched - it's owned by the same person. that's it.
each branch has it's own IT people (sometimes outsourced, sometimes in the organization).
each branch has it's own firewall (multiple vendors) and AD.

My client would like to encrypt emails going withing the organization.
So an Exchange 2007 solution came in mind.

we do NOT want to make a single AD that would cater for all the branched, but rather a parallel AD just for the Exchange solution.

The problem: this is a multi-site configuration for the Exchange - were we need 5-7 exchage servers around the world.

now... the problem:

creating a multi-site VPN is not a realistic option right now.
because: to many types of FWs, not trained enough people at the brached (with this kind of work), we do not need VPN to share users/files/printers whatsover. just need it for the Exchange.

Is there a solution to create such a solution for multi-site without VPN that could work reliably ?

Thanks.

May.
  #2  
Old 25th January 2007, 02:30
guyt's Avatar
guyt guyt is offline
[MSFT]
Guru
 
 Join Date: Nov 2003
  6 month star 12 month star
 Location: Israel
 Posts: 1,766
  Send a message via MSN to guyt
 Reputation: guyt is a name known to allguyt is a name known to allguyt is a name known to allguyt is a name known to allguyt is a name known to allguyt is a name known to all (592)
Default Re: multi site - no vpn

The only option I can think of given the consraints is Hosted Exchange - you might want to do some research about providers that can provide the geographic coverage you require.
__________________
Guy Teverovsky
http://blogs.technet.com/b/isrpfeplat/
"Smith & Wesson - the original point and click interface"
  #3  
Old 26th January 2007, 16:25
NeilM NeilM is offline
Casual
Casual
 
 Join Date: Jan 2007
  6 month star 12 month star
 Posts: 7
 Reputation: NeilM is on a distinguished road (10)
Default Re: multi site - no vpn

I was going to suggest the same, it would remove a lot of the headaches such as MIIS or IIFp etc. for sharing address books and calendars etc.
  #4  
Old 28th January 2007, 22:04
may_east may_east is offline
Casual
Casual
 
 Join Date: Jan 2007
  6 month star 12 month star
 Posts: 3
 Reputation: may_east is on a distinguished road (10)
Default Re: multi site - no vpn

we are now checking another option:
putting a FW box (that can do VPN) BEHIND the FW that is in place in each branch.
if possible, it will be in the DMZ port of the existing FW.

this way we could do the VPN for the active directory, while not touching the existing FW rules.

what do you think ?
  #5  
Old 29th January 2007, 01:07
Dumber's Avatar
Dumber Dumber is offline
Moderator
 
 Join Date: Dec 2003
  6 month star 12 month star
 Location: The Netherlands
 Posts: 8,067
 Reputation: Dumber is a splendid one to beholdDumber is a splendid one to beholdDumber is a splendid one to beholdDumber is a splendid one to beholdDumber is a splendid one to beholdDumber is a splendid one to beholdDumber is a splendid one to behold (820)
Default Re: multi site - no vpn

I think you need to setup a Site-to-site vpn.
I'm don't know what kind of firewalls you got and which one you want to purchase.
__________________
Marcel
Netherlands
http://www.phetios.com
http://blog.nessus.nl

MCITP(EA, SA), MCSA/E 2003:Security, CCNA, SNAF, DCUCI, CCSA/E/E+ (R60), VCP4/5, NCDA, NCIE - SAN, NCIE - BR, EMCPE
No matter how secure, there is always the human factor.
  #6  
Old 29th January 2007, 12:15
may_east may_east is offline
Casual
Casual
 
 Join Date: Jan 2007
  6 month star 12 month star
 Posts: 3
 Reputation: may_east is on a distinguished road (10)
Default Re: multi site - no vpn

Hi, of course site-to-site.

we currently have a mix between the branches.
sonicwall, cisco, 3com, fortigate, checkpoint ...

the whole idea of creating a VPN without using the existing hardware is:
we do not want to change anything in them, as they work now, and we are afraid that changing the setup will cause lots of problems. there are places in the world that they have their own VPN between the locations within the country, and we do not want to mess things up.

paying for additional hardware (as long as the solution works) is money better spent than solving problems from remote
Closed Thread


Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump

Similar Threads
Thread Thread Starter Forum Replies Last Post
AD Multi Domain design Anderso Active Directory 1 28th November 2006 17:46
exchange with multi domain. milo974 Exchange 2000 / 2003 1 7th February 2006 23:09
One IP Address 4 Multi Purpose? habibalby Misc 6 26th October 2005 00:34
multi session user alitoday Windows Server 2000 / 2003 1 14th October 2004 18:09
multi user per pc koroknoy Windows Server 2000 / 2003 15 10th May 2004 10:42


All times are GMT +3. The time now is 20:49.

Steel Blue 3.5.4 vBulletin Style ©2006 vBEnhanced
Powered by vBulletin® Version 3.8.4
Copyright ©2000 - 2013, Jelsoft Enterprises Ltd.
 

Valid XHTML 1.0!   Valid CSS!

Copyright 2005 Daniel Petri