# Alternative's to RRAS.

**URL:** https://forums.speedlife.net/t/alternatives-to-rras/192554
**Category:** PittSpeed Off Topic
**Created:** [September 20, 2007, 1:22pm UTC](https://forums.speedlife.net/t/alternatives-to-rras/192554 "2007-09-20T13:22:33Z")
**Posts on this page:** 20
**Page:** 1

<div class="post-metadata">

### Author: ![yamaha](https://yyz2.discourse-cdn.com/flex034/user_avatar/forums.speedlife.net/yamaha/32/5929_2.png) [@yamaha](https://forums.speedlife.net/u/yamaha)
#### Post date: [September 20, 2007, 1:22pm UTC](https://forums.speedlife.net/t/alternatives-to-rras/192554/1 "2007-09-20T13:22:33Z")

</div>

It’s been well long enough since I have had a chance to work on the RRAS server I implemented a few months ago. Finally, with enough complaints, management wants me to do something about it. I know very little for other software based routing applications, can anyone suggest some to me so I can do some research. I need to be able to do some port forwarding and other small odds and end with it.

Thanks,  
Sean

---

<div class="post-metadata">

### Author: ![fshowcars](https://yyz2.discourse-cdn.com/flex034/user_avatar/forums.speedlife.net/fshowcars/32/5937_2.png) [@fshowcars](https://forums.speedlife.net/u/fshowcars)
#### Post date: [September 20, 2007, 1:49pm UTC](https://forums.speedlife.net/t/alternatives-to-rras/192554/2 "2007-09-20T13:49:35Z")

</div>

what is the purpose? remote access/VPN and simple nat’ing? i’m unsure as to why you’re lokoing soley for software solutions… these days any lower cost firewall has most of those abilities, ive worked with junipers and ciscos (their lowest end being linksys’s)… depends on what you want and need…

how much are you spending?  
how many users are you talking about?  
are you dealing with phone lines?  
anything moreso than VPN access and internal forwarding?  
are you integrating with anything?

---

<div class="post-metadata">

### Author: ![85TransAm](https://avatars.discourse-cdn.com/v4/letter/8/e68b1a/32.png) [@85TransAm](https://forums.speedlife.net/u/85TransAm)
#### Post date: [September 20, 2007, 1:51pm UTC](https://forums.speedlife.net/t/alternatives-to-rras/192554/3 "2007-09-20T13:51:50Z")

</div>

i thought you ment those things women wear to keep the titties up…

---

<div class="post-metadata">

### Author: ![yamaha](https://yyz2.discourse-cdn.com/flex034/user_avatar/forums.speedlife.net/yamaha/32/5929_2.png) [@yamaha](https://forums.speedlife.net/u/yamaha)
#### Post date: [September 20, 2007, 2:05pm UTC](https://forums.speedlife.net/t/alternatives-to-rras/192554/4 "2007-09-20T14:05:33Z")

</div>

> [@things shops tell newbs or unaware people](https://forums.speedlife.net/t/things-shops-tell-newbs-or-unaware-people/32352/92):
>
> what is the purpose? remote access/VPN and simple nat’ing? i’m unsure as to why you’re lokoing soley for software solutions… these days any lower cost firewall has most of those abilities, ive worked with junipers and ciscos (their lowest end being linksys’s)… depends on what you want and need…
> 
> how much are you spending?  
> how many users are you talking about?  
> are you dealing with phone lines?  
> anything moreso than VPN access and internal forwarding?  
> are you integrating with anything?

Main purpose is for VPN and Remote Access. I’m not to familiar with hardware firewalls. Money is not so much an option, anything under 2,500 dollars. Users are limited to 15, no phone lines are being used. Thoughts?

---

<div class="post-metadata">

### Author: ![fshowcars](https://yyz2.discourse-cdn.com/flex034/user_avatar/forums.speedlife.net/fshowcars/32/5937_2.png) [@fshowcars](https://forums.speedlife.net/u/fshowcars)
#### Post date: [September 20, 2007, 2:17pm UTC](https://forums.speedlife.net/t/alternatives-to-rras/192554/5 "2007-09-20T14:17:03Z")

</div>

get a cheap cisco firewall… check out their site and download some pdfs… you’ll find plenty of info!

---

<div class="post-metadata">

### Author: ![fshowcars](https://yyz2.discourse-cdn.com/flex034/user_avatar/forums.speedlife.net/fshowcars/32/5937_2.png) [@fshowcars](https://forums.speedlife.net/u/fshowcars)
#### Post date: [September 20, 2007, 2:17pm UTC](https://forums.speedlife.net/t/alternatives-to-rras/192554/6 "2007-09-20T14:17:34Z")

</div>

> [@Looking for any news about my former employer (Premium Auto)](https://forums.speedlife.net/t/looking-for-any-news-about-my-former-employer-premium-auto/32565/10):
>
> i thought you ment those things women wear to keep the titties up…

and that would further prove what an idiot you are.

this is on-topic… do not respond.

---

<div class="post-metadata">

### Author: ![Swarzkopf](https://avatars.discourse-cdn.com/v4/letter/s/7feea3/32.png) [@Swarzkopf](https://forums.speedlife.net/u/Swarzkopf)
#### Post date: [September 20, 2007, 4:50pm UTC](https://forums.speedlife.net/t/alternatives-to-rras/192554/7 "2007-09-20T16:50:28Z")

</div>

We use Cisco PIX firewall’s VPN functionality to provide remote access. Seems to work grat. Cisco makes a nice desktop client application that you can deploy to your staff’s laptops that integrates nicely with the PIX based VPN as well. We have our PIX configured to forward all authentication requests to one of our domain controllers running IAS (a Microsoft RADIUS implementation if your not familiar) so we’re still using Active Directory authentication for all attempted VPN connections.

We have roughly ~400 users who connect to our network on a regular basis using this setup and it works like a champ.

---

<div class="post-metadata">

### Author: ![1st\_v-dub](https://avatars.discourse-cdn.com/v4/letter/1/ee7513/32.png) [@1st\_v-dub](https://forums.speedlife.net/u/1st_v-dub)
#### Post date: [September 20, 2007, 5:52pm UTC](https://forums.speedlife.net/t/alternatives-to-rras/192554/8 "2007-09-20T17:52:49Z")

</div>

do the pix’s have a web interface or are they soley IOS configured. That would be my only worry as the IOS isn’t completely intuitive especially if you have never seen it. other than the config, they are solid boxes.

can you configure a linux distro for vpn and remote access? like are you just doing port forwarding and nat? if so that might be one of the easier and cheaper solutions. Get a machine with 2 nics and check out smoothwall. [http://www.smoothwall.org/](http://www.smoothwall.org/)

This may be totally what you don’t want to do though. I’m tired from dealing with this crap all day.

---

<div class="post-metadata">

### Author: ![noahTHEpurdy](https://avatars.discourse-cdn.com/v4/letter/n/87869e/32.png) [@noahTHEpurdy](https://forums.speedlife.net/u/noahTHEpurdy)
#### Post date: [September 20, 2007, 6:09pm UTC](https://forums.speedlife.net/t/alternatives-to-rras/192554/9 "2007-09-20T18:09:09Z")

</div>

> [@Shannonille (full course): Saturday, July 14th (evening $78)](https://forums.speedlife.net/t/shannonille-full-course-saturday-july-14th-evening-78/31811/8):
>
> do the pix’s have a web interface or are they soley IOS configured. That would be my only worry as the IOS isn’t completely intuitive especially if you have never seen it. other than the config, they are solid boxes.

Psssh. CiscoIOS is easy peasy. And by typing a ? you can work yourself through commands you are not familiar with.

> [@Shannonille (full course): Saturday, July 14th (evening $78)](https://forums.speedlife.net/t/shannonille-full-course-saturday-july-14th-evening-78/31811/8):
>
> can you configure a linux distro for vpn and remote access? like are you just doing port forwarding and nat? if so that might be one of the easier and cheaper solutions. Get a machine with 2 nics and check out smoothwall. [http://www.smoothwall.org/](http://www.smoothwall.org/)

That’d be another option but I think his best bet is simply a Cisco PIX; cheap, compact, and everything’s there.

---

<div class="post-metadata">

### Author: ![whitey](https://yyz2.discourse-cdn.com/flex034/user_avatar/forums.speedlife.net/whitey/32/5911_2.png) [@whitey](https://forums.speedlife.net/u/whitey)
#### Post date: [September 20, 2007, 6:17pm UTC](https://forums.speedlife.net/t/alternatives-to-rras/192554/10 "2007-09-20T18:17:37Z")

</div>

You can do up to 50 users on a PIX 506e and those can be had for about 900. Or you could use an ASA 5505, not sure off the top of my head but its easy 25-50 users. If you think you are going to grow over 50 users then you would have to jump to a PIX 515e.I think the ultimate solution would be deploying a Juniper SSL VPN. All of those pieces can be integrated with AD or LDAP.

---

<div class="post-metadata">

### Author: ![Swarzkopf](https://avatars.discourse-cdn.com/v4/letter/s/7feea3/32.png) [@Swarzkopf](https://forums.speedlife.net/u/Swarzkopf)
#### Post date: [September 20, 2007, 6:30pm UTC](https://forums.speedlife.net/t/alternatives-to-rras/192554/11 "2007-09-20T18:30:47Z")

</div>

> do the pix’s have a web interface or are they soley IOS configured. That would be my only worry as the IOS isn’t completely intuitive especially if you have never seen it. other than the config, they are solid boxes.

Yep, nice web GUI…don’t know that I’ve ever used it though. Seems everyone uses the CLI.

> I think the ultimate solution would be deploying a Juniper SSL VPN.

This is a solution that seems to be growing in popularity. I’m not familiar with it…but it’s hot right now for sure. From what I’ve read it’s very easy to deploy and manage.

---

<div class="post-metadata">

### Author: ![Swarzkopf](https://avatars.discourse-cdn.com/v4/letter/s/7feea3/32.png) [@Swarzkopf](https://forums.speedlife.net/u/Swarzkopf)
#### Post date: [September 20, 2007, 6:32pm UTC](https://forums.speedlife.net/t/alternatives-to-rras/192554/12 "2007-09-20T18:32:24Z")

</div>

> Psssh. CiscoIOS is easy peasy. And by typing a ? you can work yourself through commands you are not familiar with.

Keep in mind that the PIX firewall’s IOS isn’t exactly the same as standard Cisco IOS.

---

<div class="post-metadata">

### Author: ![whitey](https://yyz2.discourse-cdn.com/flex034/user_avatar/forums.speedlife.net/whitey/32/5911_2.png) [@whitey](https://forums.speedlife.net/u/whitey)
#### Post date: [September 20, 2007, 6:56pm UTC](https://forums.speedlife.net/t/alternatives-to-rras/192554/13 "2007-09-20T18:56:03Z")

</div>

> [@Swarzkopf"](#):
>
> This is a solution that seems to be growing in popularity. I’m not familiar with it…but it’s hot right now for sure. From what I’ve read it’s very easy to deploy and manage.

its growing in popularity because it’s easy. Think of it as VPN but without the client. The end user just needs there web browser to create a connection. no more troubleshooting the VPN client or dealing with the users uninstalling the software. We are evaluating the Juniper product right now and are really impressed.

---

<div class="post-metadata">

### Author: ![yamaha](https://yyz2.discourse-cdn.com/flex034/user_avatar/forums.speedlife.net/yamaha/32/5929_2.png) [@yamaha](https://forums.speedlife.net/u/yamaha)
#### Post date: [September 27, 2007, 1:20pm UTC](https://forums.speedlife.net/t/alternatives-to-rras/192554/14 "2007-09-27T13:20:47Z")

</div>

The office bought a SonicWall TZ170 SP. The main interest in this router is for its dual wan capabilities. We will be able to use two DSL lines as one per say. I have a question about just using the router for security, port forwarding, and VPN. Can I use my existing DHCP server and disable the DHCP feature on the router without issues and just forward the gateway of the node computers to the router?

---

<div class="post-metadata">

### Author: ![whitey](https://yyz2.discourse-cdn.com/flex034/user_avatar/forums.speedlife.net/whitey/32/5911_2.png) [@whitey](https://forums.speedlife.net/u/whitey)
#### Post date: [September 27, 2007, 2:42pm UTC](https://forums.speedlife.net/t/alternatives-to-rras/192554/15 "2007-09-27T14:42:44Z")

</div>

Sonic Wall??? ewwwwww Dual DSL lines? roflcopter Where the hell is your office that the best connection you get is two DSL lines?

You should have no issues running DHCP off your current server

---

<div class="post-metadata">

### Author: ![yamaha](https://yyz2.discourse-cdn.com/flex034/user_avatar/forums.speedlife.net/yamaha/32/5929_2.png) [@yamaha](https://forums.speedlife.net/u/yamaha)
#### Post date: [September 27, 2007, 3:05pm UTC](https://forums.speedlife.net/t/alternatives-to-rras/192554/16 "2007-09-27T15:05:49Z")

</div>

> [@WTT: D series DC Sport header for oem](https://forums.speedlife.net/t/wtt-d-series-dc-sport-header-for-oem/32700/3):
>
> Sonic Wall??? ewwwwww Dual DSL lines? roflcopter Where the hell is your office that the best connection you get is two DSL lines?
> 
> You should have no issues running DHCP off your current server

You don’t want to know where the office is locatd at. You and I both know you can find out. Dual DSL lines are better then nothing. We looked into T1 and bonded T1, but they did not want to fork out that much a month. ADSL2 was non existent there too. I’m sure everything will work out fine.

---

<div class="post-metadata">

### Author: ![Tonyklem](https://avatars.discourse-cdn.com/v4/letter/t/57b2e6/32.png) [@Tonyklem](https://forums.speedlife.net/u/Tonyklem)
#### Post date: [October 7, 2007, 2:19am UTC](https://forums.speedlife.net/t/alternatives-to-rras/192554/17 "2007-10-07T02:19:11Z")

</div>

> [@FS: BSeries Swap, Rims, Seats](https://forums.speedlife.net/t/fs-bseries-swap-rims-seats/21349/31):
>
> You don’t want to know where the office is locatd at. You and I both know you can find out. Dual DSL lines are better then nothing. We looked into T1 and bonded T1, but they did not want to fork out that much a month. ADSL2 was non existent there too. I’m sure everything will work out fine.

FiOS? 🙂

---

<div class="post-metadata">

### Author: ![77rednecktruck](https://yyz2.discourse-cdn.com/flex034/user_avatar/forums.speedlife.net/77rednecktruck/32/5966_2.png) [@77rednecktruck](https://forums.speedlife.net/u/77rednecktruck)
#### Post date: [October 7, 2007, 6:39pm UTC](https://forums.speedlife.net/t/alternatives-to-rras/192554/18 "2007-10-07T18:39:06Z")

</div>

I really dislike sonicwall products, but it’s better than a snapgear which one of my clients has. Cisco is the way to go for routers/firewalls. The old pix’s were easy to set up and worked really well.

---

<div class="post-metadata">

### Author: ![yamaha](https://yyz2.discourse-cdn.com/flex034/user_avatar/forums.speedlife.net/yamaha/32/5929_2.png) [@yamaha](https://forums.speedlife.net/u/yamaha)
#### Post date: [October 8, 2007, 4:47am UTC](https://forums.speedlife.net/t/alternatives-to-rras/192554/19 "2007-10-08T04:47:10Z")

</div>

Fios will not be here for another 4+ years. The Sonicwall seems to be doing a good job so far. We have it for a ninty day test period. I’m going to borrow a older Cisco unit from a buddy and test that out to see which one I like more.

---

<div class="post-metadata">

### Author: ![whitey](https://yyz2.discourse-cdn.com/flex034/user_avatar/forums.speedlife.net/whitey/32/5911_2.png) [@whitey](https://forums.speedlife.net/u/whitey)
#### Post date: [October 8, 2007, 5:32am UTC](https://forums.speedlife.net/t/alternatives-to-rras/192554/20 "2007-10-08T05:32:06Z")

</div>

> [@automatic transmission with paddle shifters..](https://forums.speedlife.net/t/automatic-transmission-with-paddle-shifters/32858/19):
>
> Fios will not be here for another 4+ years. The Sonicwall seems to be doing a good job so far. We have it for a ninty day test period. I’m going to borrow a older Cisco unit from a buddy and test that out to see which one I like more.

nothing like staying on the brink of technology!

I am not sure how you can work in a shop like that, I would go nuts!

[Next page](https://forums.speedlife.net/t/alternatives-to-rras/192554.md?page=2)
