T
T
Tanairan Trezelnikov2018-04-23 09:53:54
VPN
Tanairan Trezelnikov, 2018-04-23 09:53:54

What is the best way to organize communication between two remote offices?

Good day, dear ones!
Given:
Two offices of the same company, one in Moscow, the second in Vladimir.
Both have 100Mbps internet access.
Task: to organize communication between branches for convenient document exchange and remote control (it is planned to deploy ActiveDirectory).
Restrictions:
It is impossible to organize a small separate room for a server room, at most you can hang a switching cabinet with a switch, UPS and one or two HP microservers (2-core Gen10).
Suggested Solution:
Rent a dedicated server (8 cores, 64GB RAM, 2TB HDD, 1GB/s channel) in Europe (Germany or the Netherlands, since several dedicated servers are already in use within one hoster), where Proxmox will be deployed. Several virtual machines will live on Prokmoks: 2 domain controllers, Zimbra mail server, Asterisk, Zabbix, Jira, Jabber.
In total, about 50 people will use this, mostly programmers, there are no plans for a large load on AD, the exchange of documents through balls inside the branch, or through services that are not related to AD.
In each of the branches on the microserver, deploy the RODC and the local file server.
Install Mikrotik in the branches, which will be connected to a dedicated server using VPN (openvpn or ipsec).
From the dedicated server side, either Proxmox itself or a virtual machine with pfSense will be responsible for the tunnel.
Set up routing accordingly.
Ping from branches to already existing dedicated servers from 44 to 46ms
Question:
Is the proposed connection scheme flawed in terms of AD operation, will it affect the speed of user login and other operations? Is the circuit defective in terms of equipment?
This is the first time I am organizing such an interaction between offices, so I ask you to correct or suggest a better solution with the initial data, nuances that you should pay more attention to.
Thank you in advance!

Answer the question

In order to leave comments, you need to log in

5 answer(s)
I
Ivan, 2018-04-23
@Tanairan

All right. True, if there are only 2 offices, then perhaps it is easier to set up a VPN right at the head office? Eliminate the round-trip...
For simple AD queries and small files on the balls, this is enough for you. Why heavier than the type of large files, databases, etc. there may be speed drops.

C
CityCat4, 2018-04-23
@CityCat4

Yes. And tomorrow there will be a cart on your hosting and RTK will happily ban it :) And that's it - the business got up ... in the position of a company machine gun :)
Not to mention the fact that putting "internal" servers on hosting is just asking for a leak .

D
d-stream, 2018-04-23
@d-stream

Pulling flies and cutlets on different sides of the plate:
1. Transport - cisco, microtics, provider options - it doesn't matter. The main thing is to implement the availability of heads and branches
2. AD - in fact, since 2000, Microsoft products have everything for building forests, sites - just choose the model you like with the degree of authoritarianism (head-forest or trusts)
Well, as already noted - DFS for "joint" work. Of course there are nuances...

D
Dmitry Entelis, 2018-04-24
@DmitriyEntelis

Any scheme with an AD domain controller outside of its own infrastructure is flawed by definition.
I wouldn't want to spread politics here, but do you read the news?
Do you really believe that the actions of the RKN have the goal of blocking the telegram?
In my opinion, the scheme with any resources outside the Russian Federation in the current situation is defective in the square.

V
Vladimir Dementiev, 2018-05-03
@SayMAN83

Raise your AD in each office, use VPN to connect between offices. AD nodes can be "friends", ie. make trusted.
In reality, Internet providers periodically and extremely unexpectedly fail.
By placing the AD server outside the office network, you will have to prepare for the fact that if the Internet goes down, work in the office will stop. Since access to many services will be lost.

Didn't find what you were looking for?

Ask your question

Ask a Question

731 491 924 answers to any question