Good Morning,
A newbie question - in these days of increase remote access to HQ, what is the best VPN service (or combination of) protocol to for staff remote access back to the office from their business laptops. Appreciate it's very much a 'it depends question' but I'm trying to understand whether SSL L2TP or L2TP IPsec or what is a better combination than their current SSL L2TP. Or is this the best/most efficient?
I've been experimenting with different combination and believe the Sophos IPsec client seems to present the most user friendly endpoint solution for (staff) connecting back to HQ (using macOS10.15 and 10.15 ; Windows 10 Pro).
In total, there are now about 30 staff currently connecting back to HQ via SSL L2TP using their PCs built-in VPN client. The XG firewall is running V18 MR3. There is a mix of VPN demands - designer mainly access large 3D cad files or RDP to their desktops and working with large 30 cad files (about 5-30GB); managers are accessing excel spreadsheets; accountant access MYOB on server; management is accessing mainly documents and customer database stuff. There are no web base portal services hosted within the environment; all web present solutions are cloud hosted. The business has 100/100 internet service. All staff are on O365 accounts.
With my investigation, I believe it is possible to have split tunnel so only RDP or SMB or similar traffic is directed into HQ and everything else (including cloud services like dropbox, SAP, etc) gets directed by Sophos IPSec client straight out via (individual) home internet connections. Is this a good idea or does it add too much overhead? Has anyone undertaken similar investigations and found a magic combination of security, performance, etc (and yes, there is always a compromise)
I've got a few conflicting opinions on this topic - and very little clarity because 'it depends' - and would appreciate additional comment (from a more specialised community) for a better understanding of where to go.
Thank you - in advance for your insight.
Have a great day,
Fred
This thread was automatically locked due to age.