VPN hardware/software requirements

robw53

Member
Join Date
Nov 2009
Location
south yorks
Posts
515
I am looking for some clarification as to the requirements for a VPN system from client to site, our network will consist of two 8000 around the plant, a stratix 8300 in the centre and from this something along the lines of a cisco router 887VA which gives us 20 tunnels, NAT, firewall, etc, then the ADSL line will come straight into this, as well as this do i require a PC to act as a VPN server or any other hardware, software or monthly subscriptions that i need to be aware of when costing for this?

regards

Rob
 
Rob

I would recommend Barracuda Networks for your setup https://www.barracuda.com/

I use SonicWall, Cisco and Tofino and secure crossing for different things but for you I would recommend a barracuda firewall with a seperate VPN appliance as you get features on the VPN applinace that the firewalls built in VPN can't do and are well worth the money IMHO.

IIRC you wanted to have the ability to let contractors VPN into their own network with their respective equipment isolated from all other equipment correct?

In the past sonicwall was my top recomendation for industrial,small case and SMB use. Since SonicWall has been purchased by Dell and all the things Dell is going through I would be cautious to recommend sonicwall at this point. also sonicwall support is primarily forgein based in india and china so there is a language barrier to deal with when you are having issues. barracuda is U.S based support. barracuda customer support far exceeds sonicwall IMHO and I am currently using both in many installations.
 
A VPN applinace will give you everything you need so you don't need a dedicted PC. It can be done that way if you wish but it's harder to manage and less secure.

A VPN appliance like Barracuda will give you 2 factor authentication and 1 time password use. So for you contractor "Big Jim's Conveyors" that supplies your conveyor system you setup his login and his cell # and when he goes to the VPN portal and puts in his password the VPN applince will send him a text on his phone with a one time code to enter before he is connected.

2 factor authentication is much more secure becuase it's based on something you know "your password" and something you have "your cell phone" so if someone cracks your password they still need to have physical access to your cell phone to get in.
 
I have been working with engineers at Barracuda for a firmware upgrade that will report when a VPN user logs in and when he logs out as well as log his duration. Currently no one does this. it has been sked by Barracuda in the past and I have been pushing it so it is scheduled to release in a upcoming firmware this year. A good feature for our industry I feel.

I recommend this if budget permits http://www.techguard.com/products/poliwall-ip-country-blocker/

The Poli wall will block by country so all IP traffic from china will be dropped for example. You can make exclusiosn for specific sites if you need but countries you don't need traffic from block them. This appliance goes in front of your firewall at the perimeter. Stop bad traffic before it hammers your firewall if possible.
 
My layout is like this in basic form.

Internet/ISP Connections/Link Balancer/Poliwall/Firewall|VPN Appliance/Webfilter/Switch/Load Balancer /switch/DMZ/Secure Crossing/Switch/Tofino/Switch/PLC.
 
Sorry I only just replied I didn't get any notifications, I will look into the barracuda equipment. The main reason I asked about the VPN stuff was because our IS department says that to do VPN and setup this for specific VLAN'S is very complex and would cost like £40,000 to achieve and then asked who would manage it once its in, they said you would need a Cisco guy to come in and get it up an running, as I was looking at using a Cisco 88VA VPN appliance, our IS department said they couldn't recommend anything until they knew what equipment we had on the plant, as in PLC, HMI etc.
After doing there hardest to try and put us off doing this they then said that they could install the switches and they would do all the management of them, and they would fully control them and setup any VLAN'S etc or what ever we require. This is not something I want to happen I would prefer we have no IS involment in the way of managing this network.
 
Rob

My recomendation for you is to go with Barracuda or SonicWall as they are much easier than Cisco. I can and will be glad to help you with any of the 3. Barracuda is my top recomendation because of the Dell /SonicWall merger and Barracuda has much better support.

Cisco is great gear but it can be involved. I am working on 2 Cisco Certifications at the moment so I can tell you from experience. Barracuda and SonicWall are just as good if not better and much better priced.

When you need a core switch or a Router the Cisco all the way.
 
cheers, hopefully if i can justify the CER for this project then i can take you up on that offer.:p

does the VPN have to be anything special to allow inter VLAN routing, i know that this is done in the 8300 but didn't know if it needed anything like VLAN Trunking etc

well my plan was to use a sonicwall firewall and a Cisco router/VPN appliance (887VA) but im going to have a good read on the barracuda if you recommend it.

i like the techguard unit, the ability to block IP's by country does sound a briliant idea.

i'm guessing you are not fond of Dell? :confused:

i'm interested in the secure crossing you mentioned i have checked out there website and it sounds good, what does this offer ontop of a firewall with deep packet inspection?

just a general question but if i have multiple devices with the same things like DPI can these run simultaneously?

i have spent probably 20 hours going through videos on youtube, and reading up on different topics which will be needed for this setup, i have been looking at doing some sort of cisco training course, i looked at the CCNA course, is this the sort of thing that would be beneficial or are there other courses that would cover more of the required topics needed for this sort of thing?
 
Last edited:
ive emailed all the listed suppliers above to find out if they have UK agents or anyone in europe so i can get a price.

for a DMZ what would i require in terms of hardware/software so i can put a price on it.
 
cheers, hopefully if i can justify the CER for this project then i can take you up on that offer.:p

does the VPN have to be anything special to allow inter VLAN routing, i know that this is done in the 8300 but didn't know if it needed anything like VLAN Trunking etc

Just has to understand the VLAN Tagging and Trunking Protocols

well my plan was to use a sonicwall firewall and a Cisco router/VPN appliance (887VA) but im going to have a good read on the barracuda if you recommend it.

If you plan to use any Cisco then go Cisco all the way. Be much easier.

i like the techguard unit, the ability to block IP's by country does sound a briliant idea.

Yep why scan and filter and risk traffic you don't need in the first place. This can also be done on most of the newer UTM firewalls also just not as elegant.

I'm guessing you are not fond of Dell? :confused:

PC's Yea, Servers Depends, Owning Sonicwall Nope.

i'm interested in the secure crossing you mentioned i have checked out there website and it sounds good, what does this offer ontop of a firewall with deep packet inspection?

Most firewalls work on the principals of signatures and black listing to some degree. Also firewalls block bad data flow.
secure crossing is white list based so it only passes why is know god and blocks everything else by default. It is made specific to sniff industrial protocols like CIP,Profiinet,Modbus TCP,etc.

just a general question but if i have multiple devices with the same things like DPI can these run simultaneously?

Depends but normally in a different way or in a different zone with more or less restrictions.

i have spent probably 20 hours going through videos on youtube, and reading up on different topics which will be needed for this setup, i have been looking at doing some sort of cisco training course, i looked at the CCNA course, is this the sort of thing that would be beneficial or are there other courses that would cover more of the required topics needed for this sort of thing?

IMPO you would be better served to get some real good understanding of networking before like Network + or something before jumping on CCNA. Cisco certs pay well for a reason because they are difficult to obtain. Cisco is kinda it's own world with it's own language and community in a way. I don't recommend it starting out.
 
ive emailed all the listed suppliers above to find out if they have UK agents or anyone in europe so i can get a price.

for a DMZ what would i require in terms of hardware/software so i can put a price on it.

A DMZ can be done in several different ways for different levels of security and other reasons.

What do you plan to sit in the DMZ? Are you going to have a historian /reports that are accessible from the internet? Are contractors /OEM's going to be servicing it?

Some DMZ setups can simply be done in your firewall and some need 2 firewalls and some need 2 firewalls of different brands it just depends on what you want to stick there and why and how secure does it need to be.
 
For your install and a single ISP you won't need a link or load balancer.

I have all that from my example but we have over 800 plc's and around just shy of 3000 drives and I don't even want to count the HMI's and servers and 95% of it is connected.
 

Similar Topics

I am networking newbie, so please bear with me.. i think i have this but am looking for some clarification. I have a PLC and an HMI running...
Replies
17
Views
4,216
Hi - I am exploring options for cellular enabled hardware VPN / Firewall devices to deploy for remote troubleshooting purposes. I do not have...
Replies
1
Views
780
I am trying to use setup a remote vpn router for external OEM connection. The thing I cannot wrap my head around is the gateway. We use the...
Replies
3
Views
282
Have anyone done this? I don't see why this wouldn't work but I may be missing something too. Getting any recurring account opened is a pain...
Replies
6
Views
1,080
Hello all. When I try to connect to a S7-1200 PLC (Tia Portal v17) which has a CP 1243-1 module that is connected to my clients network I get...
Replies
7
Views
1,561
Back
Top Bottom