Need a VPN solution for small business with multiple offices

Post new topic   Reply to topic    DD-WRT Forum Index -> Advanced Networking
Author Message
wolfpack1221
DD-WRT Novice


Joined: 16 Aug 2017
Posts: 1

PostPosted: Wed Aug 16, 2017 5:46    Post subject: Need a VPN solution for small business with multiple offices Reply with quote
So I am new enough to the aspects of dd-wrt I am trying to use to get stuck and I need some help.

What I have so far.
3 individual sites, each with a ton of devices on the network. Mostly IP Security cameras and a bunch of random wifi clients but only 2-6 PCs i care about connecting to the home office.
A Domain server that has been/will be migrated to a new network for domain stuff only.
A windows VPN server (with an external static IP that grants access to the 192.168.0.X network) I will be using as a "Backup Connection". All company COMPUTERS already have VPN connections functioning within windows and are/will be joined to the domain.
192.168.1.X - Office/Store 1 (formerly the host to the Windows Domain/File Server)
192.168.2.X - Office/Store 2
192.168.3.X - Office/Store 3
192.168.0.X The new central domain network, very few clients will probably be assigned IP's on this network unless using the "Backup Connection". This router if physically located in Office 1 but is using a different one of my ISP assigned static IPs to access the internet
The 192.168.0.1 Domain/Corporate network router already has a PPTP server configured and working on a static external IP Different than the windows VPN server. I can connect with windows VPN connection and other ddwrt routers PPTP Client Service OR PPTP WAN Connection as indicated in the "Connected PPTP Clients status page".

The Root Problem.

Technically if i stick the the windows VPN connections giving all the domain computers 2 NIC's with an IP address at there site and 1 on the corporate network I have no problem at all and everything is fine enough for my needs. BUT the limitations of windows VPN Connections with domain logins gets a little fucky and training my users how to repair/connect a windows VPN Connection coupled with the network login function only being needed for the first user to connect creating an inconsistent workflow that my employees cannot follow very well resulting on many phone calls to walk them through it while customers are waiting to check out.

What I Want.
Hardware VPN bridges at each store that connect to the 192.168.0.1 Router for transmitting information on the corporate network.
I would like each computer to only have the 1 NIC with an IP that Matches the rest of the devices in the store and communicates with the internet through their local modems like usual but can route traffic for the 192.168.0.X subnet over a vpn connection to that network.
Example 192.168.0.XXX <--> 192.168.2.XXX
The different stores do not necessarily need to be able to communicate with each other at this point.<Enter> Example 192.168.2.XXX <--> 192.168.3.XXX

The Road Block.
I think I need to configure static routes on each router to the 192.168.0.1 network and a static route for each network on the 192.168.0.1 router.
I followed this guide http://www.dd-wrt.com/wiki/index.php/Point-to-Point_PPTP_Tunneling_with_two_DD-WRT but the last bit with the static routes dosent appear to be sticking in the routing table. <Enter> After reading http://www.dd-wrt.com/phpBB2/viewtopic.php?p=780678 I believe this has to do with the VPN tunnel needing to be established BEFORE routes apply or something, this concept is new to me.

Questions.
Am I even going about this right? does anybody have any better Ideas?
Is the static routes all I am missing to get this working?
And if so how do I fix it?
Sponsor
Display posts from previous:    Page 1 of 1
Post new topic   Reply to topic    DD-WRT Forum Index -> Advanced Networking All times are GMT

Navigation

 
Jump to:  
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
You cannot attach files in this forum
You cannot download files in this forum