What's new

Reliable non-limiting solution?

  • SNBForums Code of Conduct

    SNBForums is a community for everyone, no matter what their level of experience.

    Please be tolerant and patient of others, especially newcomers. We are all here to share and learn!

    The rules are simple: Be patient, be nice, be helpful or be gone!

Schnibly

New Around Here
Hi All--

I'm looking for a new router/firewall/all in one that can address my needs. The most important of which is stability/performance for VPN connections. I am doing a lot more remote work which requires me to VPN back into my own network for access to my lab, infrastructure etc. Having to explain to my spouse to reboot a specific piece of equipment isn't something I want her to have to worry about. :D

I've debated going the AC87u route for simplicity but am starting to look at more robust SMB solutions including pfsense, Sophos, fortigate, watchguard, barracuda, cisco RV series, and sonicwall. And getting overwhelmed.

I have dual home connections (family on cable and fiber optic for my business) so managing them both under one device would be nice but definitely not a requirement. I have a separate WAP and will most likely be putting in some ubiquiti ap's in my house in the near future to upgrade.

I need a solid solution that can handle VPN traffic and the few internal VLANs that I run internally. Next big requirement--something that's user friendly and quick to setup and be up and running but that I won't find I'm limited by a few years down the road. That's one of my pet peeves and regardless if I ever do use it I hate trying to do something after a purchase then being limited by the solution that I've chosen. Networking is the biggest of the technology black holes for me and one that I'm not an expert in. I know a bit more than the average joe but by no means an expert.

Budget is open at this time but ideally in the sub 1k range.

What would you recommend if you were in my place? Thanks in advance for the advice--it's much appreciated!
 
Isn't your VPN connection a router-pass-through? Rather than terminated in the router?

If pass-through and terminated on the PC with a specific corporate approved VPN client, most any consumer router will suffice. Most smart corporations' IT policy requires use of a certain VPN client on the PC and often, two-factor authentication (RSA token or smart phone app) and some require a Smart Card or CAC-like card.
 
Thanks stevech. I guess I wasn't very clear, my apologies--I'm talking about a VPN connection back into my own home network (containing my lab and infrastructure) with my own devices (and a VPN client whether that be openvpn or some other flavor for laptop, tablet etc) and utilizing a security device as my endpoint.
 
I have been running a Sophos (virtual machine) for around or so and have had no real issues with it (that weren't caused by me doing stupid things on the ESX host). It does support VPN termination and works pretty well. I've done speed tests (internal gig connected hosts) and it's managed to give nearly line rate except when you turn on the IPS it bogs down to ~300Mb, but that could just be a flaw in my testing. I'd recommend that route and if you don't end up liking it, you can always just download a different system and try that one instead!
 
Thanks stevech. I guess I wasn't very clear, my apologies--I'm talking about a VPN connection back into my own home network (containing my lab and infrastructure) with my own devices (and a VPN client whether that be openvpn or some other flavor for laptop, tablet etc) and utilizing a security device as my endpoint.
A VPN wholly within your own LAN?
 
If you want something not limited than you'll need to go beyond user friendly. Mikrotik is one example that lets you set up a network in any way you like and if you want VPN throughput than the PPC CPU variants and CCRs will do that for you.

Theres a mikrotik demo at demo.mt.lv if you want to see how user friendly it is. They have their own program downloadable from the router thats a bit like the web based one but with additional information and safe mode incase you screw things up which basically undoes all your changes from when you enabled safe mode if you lose connection to the routerboard. For a lot less than 1K you can get a CCR1016 that has 16 TILE cores which should give you 300Mb/s of VPN throughput per link/core. Unlike many BSD based firewalls or routers mikrotik has L2 firewall but is only wirespeed for L2 firewall if you get a CCR model.
 
Similar threads
Thread starter Title Forum Replies Date
S Non-existent hostname Routers 1

Similar threads

Latest threads

Sign Up For SNBForums Daily Digest

Get an update of what's new every day delivered to your mailbox. Sign up here!
Top