2395 Views 4 Replies Latest reply: Jun 20, 2010 3:50 PM by tdurick
There are as many 'good' networks as there are network requirements and hardware combinations.
Get a server-grade firewall, if that peplink router can't provide that function.
Figure out what's up with the peplink router.
If the peplink isn't working and if it doesn't have firewall capabilities (I've not read the specs), I'd replace it with a firewall with dual uplinks.
Once you get DHCP going, you'll have two IP subnets, and you'll have to set up subnet routing for your gear. Other than that (and with that external server-grade firewall), the remote connections are straightforward.
The server-grade firewall should have VPN end-point servers for pptp and l2tp, and probably ssl, and probably a DMZ. RADIUS support, likely. For this case, dual uplinks and support for running both.
Stay out of 192.168.0.0/16 for your private stuff.
I'd likely set up the public static IP for the router, the DMZ, and key stuff that needs to be public facing. I might well run the rest of the stuff in a private IP block.
None of which involves Mac OS X.
Well, I understood about 25% of what you just said, but sounded interesting:-) I think, I'll get a consultant for this since this looks to be way over my head and I want it to be working and not spend hours and hours trying to figure this out on my own (or with the help of you guys).
First - we looked at Peplink a while back. What threw us off is the fact that the firewall has no certifications whatsoever like ICSA, WestCoastLabs or EAL. Take a look down the road of Cisco, Juniper, Fortinet or Sonicwall. Can't go wrong with these usually.
Second, dual-wan firewalls typically run outbound traffic only and are of no help on inbound traffic. If you have 2 ISPs use'em! We got an Elfiq and we're very pleased with it.
If you are looking for help getting the network optimized, please just give Peplink support a call. We would be more than happy to help you make sure everything is working well together.
Outbound load balancing should be fully automatic, and it is very easy to check if this is working. To achieve inbound load balancing, we have an integrated DNS server. Thant setup may be a bit more involved to get working. 9 out of 10 times people just need outbound load balancing to speed up their network.
Give us a call between 9-5 Central, and we should be able to get you going quickly. 650.450.9668