PDA

View Full Version : Help setting up VPN



tirebob
06-17-2020, 11:38 AM
Okay, so I now have at home my new iMac up and running with Parallels and Windows 10 and I need to get some sort of VPN connection to my work server at the shop so I can load a new POS system seat license and not have to take over the shop computer while I am using it if that makes any sense at all. I have literally zero experience on working this out and we have no IT team to help, so I was hoping a friendly Beyond might be able to give me guidance in this. Or is it something I need to hire a guy to do? Don't laugh... lol! The learning curve is steep for an old guy like me! I am not an idiot... Just not experienced in this stuff so I am hoping I can learn how to do this for future needs.

Cheers!

Bob

nzwasp
06-17-2020, 11:48 AM
Does your router at your shop support incoming VPN connections?

tirebob
06-17-2020, 11:55 AM
Does your router at your shop support incoming VPN connections?

No clue... I will find out though! Is there any other things I need to find out at the same time?

speedog
06-17-2020, 12:02 PM
Bob is going to become our new networking/techie guy, I can just feel it.

tirebob
06-17-2020, 12:32 PM
Bob is going to become our new networking/techie guy, I can just feel it.

Late to the party, but when I commit, I commit!

tirebob
06-17-2020, 01:32 PM
Does your router at your shop support incoming VPN connections?

Okay it is enabled on my shaw account.

nzwasp
06-17-2020, 01:33 PM
Okay it is enabled on my shaw account.

So its a shaw router or do you have a different device plugged into the shaw router as well?

tirebob
06-17-2020, 04:50 PM
So its a shaw router or do you have a different device plugged into the shaw router as well?

I am not at the office but it should just be a shaw router. I will confirm.

nzwasp
06-17-2020, 05:13 PM
https://support.shaw.ca/t5/internet-discussions/set-up-vpn-router/td-p/534

I think you are going to need another device to do this.

tirebob
06-17-2020, 06:02 PM
https://support.shaw.ca/t5/internet-discussions/set-up-vpn-router/td-p/534

I think you are going to need another device to do this.My guy is going to take pics of what we have tomorrow and send it to me. I will show you when I get them! Thanks!

revelations
06-17-2020, 06:41 PM
Hey Bob, send me a PM

taemo
06-17-2020, 07:28 PM
I hope you have a static IP address with Shaw as it can change randomly preventing you to VPN until you update your settings

tirebob
06-17-2020, 09:41 PM
I hope you have a static IP address with Shaw as it can change randomly preventing you to VPN until you update your settings

No clue... How do I tell?

adam c
06-17-2020, 11:24 PM
Tbh I wouldn’t recommend VPN given the q&a in this thread
Go to my pc or a variant would probably be best

firebane
06-18-2020, 06:44 AM
Tbh I wouldn’t recommend VPN given the q&a in this thread
Go to my pc or a variant would probably be best

Read the other thread and you will see why. Tirebob just needs a trustworthy person to help

adam c
06-18-2020, 07:29 AM
Connecting a home network to a work network is never a good idea, plus if IPs change or tunnel goes down or or or... then he’ll be stuck. I don’t believe Shaw routers do VPN tunnels anyways so that’s also 2 hardware purchases required.
Now if it’s SSLVPN then that’s one purchase instead of 2
Also if the subnets are the same then it’s changing one side or nat translations which further complicates everything

nzwasp
06-18-2020, 07:33 AM
Connecting a home network to a work network is never a good idea, plus if IPs change or tunnel goes down or or or... then he’ll be stuck. I don’t believe Shaw routers do VPN tunnels anyways so that’s also 2 hardware purchases required.
Now if it’s SSLVPN then that’s one purchase instead of 2
Also if the subnets are the same then it’s changing one side or nat translations which further complicates everything

What I understood from his first message he wants to connect his laptop so this would be a client vpn tunnel not a site to site vpn tunnel.

rage2
06-18-2020, 07:46 AM
Upgrade to a VPN router, setup ddns, ip can change all you want. tirebob I’ll volunteer to set you up on a weekend. Only time I have any time. Anyone know if Shaw will flip to bridge mode on a weekend?

taemo
06-18-2020, 08:01 AM
No clue... How do I tell?
it is an extra service for business clients but if rage is going to set you up with ddns then you don't have to worry about it.



Upgrade to a VPN router, setup ddns, ip can change all you want. tirebob I’ll volunteer to set you up on a weekend. Only time I have any time. Anyone know if Shaw will flip to bridge mode on a weekend?

From my experience, work service for business clients are only during weekday business hours.
But something as easy as bridge mode, maybe tech support can do it easily.

You could also get an Asus router with Merlin FW and port forward it from the existing router.

rage2
06-18-2020, 08:09 AM
From my experience, work service for business clients are only during weekday business hours.
But something as easy as bridge mode, maybe tech support can do it easily.

You could also get an Asus router with Merlin FW and port forward it from the existing router.
Well that's a bummer. I'd like to avoid double natting if possible. Who knows what won't be happy with it. I mean, I can do the core setup, if another beyonder wants to do a bridge mode with Shaw on a weekday then final validation.

firebane
06-18-2020, 08:18 AM
Well that's a bummer. I'd like to avoid double natting if possible. Who knows what won't be happy with it. I mean, I can do the core setup, if another beyonder wants to do a bridge mode with Shaw on a weekday then final validation.

Bridge mode is a remote switch they can flip anytime. Just need to talk to them.

tirebob
06-18-2020, 09:20 AM
Upgrade to a VPN router, setup ddns, ip can change all you want. tirebob I’ll volunteer to set you up on a weekend. Only time I have any time. Anyone know if Shaw will flip to bridge mode on a weekend?

Hey rage2 I am so ashamed I let myself fall so far behind on all this shit over the years... Haha! Never learned a thing about computer stuff!

So the service I have is Shaw Security 600 or some shit. I will post some pics of the hardware if it helps.

923729237392374

tirebob
06-18-2020, 09:29 AM
And when I am logged into Meraki I have a page showing this stuff... There is more to the page etc but being the techno peasant I am I don’t want to unwittingly put something out in the public that makes us vulnerable.

Edit - I included a pic of the service description it it means anything useful.

92375
92376

rage2
06-18-2020, 09:32 AM
tirebob PM me your cell number. You're iPhone now so we can chat on our blue bubbles. :rofl:

I'll probably want to get a whole wack of info from you just to do the prep work. And maybe talk to you directly on what the best way to handle this to make it as seamless as possible for you. Probably won't be during the day since my work schedule is ridiculous, so if you're OK we can chat tonight after I get the kids in bed around 9pm.

revelations
06-18-2020, 10:00 AM
Bob if you need a router let me know, Ill donate that spare Nighthawk/Asus router I have kicking around.

No doubt rage and crew will find efficiencies in other parts of the network - esp if it hasn't been touched in years!

adam c
06-18-2020, 11:39 AM
What I understood from his first message he wants to connect his laptop so this would be a client vpn tunnel not a site to site vpn tunnel.

I don't dabble much in the consumer grade equipment, are there devices out there that actually do on demand VPNs like SSL? I know some consumer stuff will do a site to site tunnel but that's where they stop

rage2
06-18-2020, 10:00 PM
Looks like I don't have to do anything. Bob's got Shaw Security, Meraki appliance as shown in screenshot which has a VPN server. Everything is just a config away.

rage2
06-18-2020, 10:18 PM
I don't dabble much in the consumer grade equipment, are there devices out there that actually do on demand VPNs like SSL? I know some consumer stuff will do a site to site tunnel but that's where they stop
Asus routers can handle it out of the box. Vpn server, site to site vpn client, and if you grab the Merlin firmware, it adds policy based routed site to site vpn.

LilDrunkenSmurf
06-19-2020, 08:56 PM
Glad to see Bob got hooked up. I was also about to throw my hat in the ring.

ExtraSlow
06-19-2020, 09:17 PM
Glad to see Bob got hooked up. I was also about to throw my hat in the ring.

For It support, or.....?
.
.
.
.
.
.
Asking for SKR

rage2
06-20-2020, 09:47 AM
VPN connected! :thumbsup:

tirebob
06-20-2020, 09:50 AM
Success!!! rage2 is the man... Thanks everyone for all the guidance through this! I feel a little bit smarter now.

ExtraSlow
06-20-2020, 10:02 AM
My work it guy set me up on a VPN Friday. Took him four minutes.

tirebob
06-20-2020, 10:15 AM
My work it guy set me up on a VPN Friday. Took him four minutes.Honestly, not initially knowing the process with this Shaw Smart security that was the only thing that took a little bit of time. I think that four minutes is all it would take doing it again. Now it is figured out it is cake.

rage2
06-20-2020, 10:23 AM
tirebob setup the vpn server all on his own. I really didn’t do anything aside from pointing him in the right direction for windows 10 client settings.

ExtraSlow
06-20-2020, 10:50 AM
Also, to be clear, I'm not saying I "did" anything. My company already has a vpn that dozens of people use, and I have a work-issued laptop, and an IT guy remoted in to do the work. Just funny timing.