IPsecuritas vs. VPN tracker vs. Apple VPN

Hi all,

I am new to VPN, but we just setup our office server (G5 2.0 dual-core / leopard server) which connects 12 clients. We also have a Sonicwall TZ180 as our firewall. Some employees want to connect from their home computers to the office server.

Does anybody know which of the 3 (IPsecuritas, VPN tracker, Apple VPN) is the best solution for connecting through VPN?

From what I understand VPN is kind of slow, but we would like to transfer Adobe Illustrator and Indesign files. Is this possible?

Thank you!

Mac Pro Quad 2.66 -- Power Mac G5 Dual 1.8 -- 17" Powerbook G4, Mac OS X (10.5.3)

Posted on Sep 23, 2008 3:56 AM

Reply
20 replies

Sep 23, 2008 4:13 AM in response to noice_T

I have a SonicWall Pro2040 and TZ170. I have Global VPN's working with both Firewalls.

To answer your questions:
• Apple VPN doesn't work with SonicWalls, at all, don't waste your time trying.
• IP Securitas works but is a bit flaky and tends to work on and off. It also connects in a way that prevents your client from gaining an IP address which makes things difficult when using ARD for example.
• VPN Tracker is very expensive but works very well, however, if you need to traverse mulitiple sites, as I do, it can get even more expensive. The player version works fine for most users. VPN tracker is also easy to configure unlike IP Securitas.

My advice is to bite the bullet and pay for VPN Tracker.

Sep 23, 2008 5:36 AM in response to huwjenkins

Hi huwjenkins,

Thanks for the reply~

OK no Apple VPN I guess ^^ I hear a lot of mixed reviews between both IP Securitas vs. VPN tracker though. I guess I should just try both, is that possible? (sorry VPN noob...) Or maybe just buy one VPN tracker license first and test it out. It does have a nice, simple looking interface. Maybe it is time to bite the bullet...

Thanks~
noiceT

Sep 27, 2008 12:13 AM in response to noice_T

You can also forward VPN traffic through the firewall to the OS X VPN server and let it do the work. We do it with with TZ 170's. If the VPN isn't configured in the SonicWall you can forward three UDP ports to the OS X server: UDP 500, 4500 and 1701 (1701 not neccessary). If you have mutiple public IPs you can use one-to-one NAT for this and still have working site to site VPN and IPSec client connections working.

SonicWall with standard firmware woun't let you forward GRE/PPTP, but L2TP should work fine (as long as you use OS X VPN client). With Windows clients use SonicWall VPN client. With enhanced firmware also PPTP can be forwarded.

SonicWall "kind of" works with Apple L2TP client, but probably only when the client connects from a public IP, so when/if you are behind NAT when connecting it woun't work. Also Apple L2TP VPN client doesn't support XAUTH so it has to be turned off.

L2TP is easier than a IPSec VPN client to configure and use.

Sep 27, 2008 3:30 PM in response to Leif Carlsson

The Apple software "just works" between client & server, however, you do need a router/firewall that can correctly forward the appropriate protocols (not just ports).

I was not able to get IPSecuritas to work with a couple different routers, and it also badly pegged my machine in terms of CPU usage. It's been effectively a non-starter for me.

VPN tracker should only be necessary to connect remotely from a Mac OS X computer to a 3rd-party device.

In terms of pricing and features, I tend to use the Zyxel Zywall 2 Plus (and up), and they sell a Windows-only client. VPNTracker works quite well with the Zyxel products.

Oct 4, 2008 11:09 AM in response to davidh

We just implemented VPN Tracker with a Sonicwall 2040. Tracker is very easy to set up (they have many tech sheets showing how to exactly configure a given VPN gateway device).

I am having issues with VPN Tracker resolving our internal DNS server though. My MacBook keeps resolving to our ISP's. At this point, I do not know if this is the VPN tracker, Macbook, or the Sonicwall. Strangely, I can access the internal server ARD.

The speed so far has been fine.

Oct 10, 2008 7:11 AM in response to davidh

I had loads of problems back in early 10.4 server days where when a user authenticated to Apple's Server L2TP implementation it used to freeze all of our AFP connections for about 3 mins. This maybe resolved now, I'm not sure, but I feel good about my IP distribution being controlled solely from one place, my SonicWall, rather than a mixture Sonicwall and Mac OS X Server.

If only I could get RADIUS Server in 10.5.5 work with our Sonicwall and so I could use XAUTH with my client VPN connections against our ODM rather than a risky PSK that people take with them when they leave.

Jan 27, 2009 6:50 AM in response to noice_T

Trying to get IPsecuritas to work with a SonicWall TZ 180. The wizard has Sonicwall TZ 170, but the connection it generates doesn't work.

Does anyone have a working TZ180 configuration?

I also tried updating the templates, but it will not allow the update to take place. It says template update failed. Make sure you have administrator's permissions.

Btw it keeps failing on Phase 2 of the negotiations. The visible portion of the Phase 2 configuration appears identical to what is in the TZ 180 configuration, but something else isn't right.

This thread has been closed by the system or the community team. You may vote for any posts you find helpful, or search the Community for additional answers.

IPsecuritas vs. VPN tracker vs. Apple VPN

Welcome to Apple Support Community
A forum where Apple customers help each other with their products. Get started with your Apple Account.