Blue to Gold to external VPN?

Comments

6 comments

  • 0
    Comment actions Permalink
  • Avatar
    Rob Knowles

    Thanks. I would love to make this as transparent as possible to my parents. If there's a way to set this up without even telling them that'd be best.

    I started to configure the site-to-site leg using OpenVPN from their Blue to my Gold. I stopped when the setup wizard prompted me to manually configure devices on their LAN to use the overlay subnet. That's not feasible.

    Another consideration is whether they will see any issues with Netflix, etc. coming over this connection and going out to the same 3rd-party VPN as my devices, which are on separate accounts for the same streaming services.

    Am I dreaming?

    0
    Comment actions Permalink
  • Avatar
    Firewalla

    The BLUE is a single interface device, so in order for VPN to work, devices will need to be on the virtual network; there is no way to get around that. (overlay network can also be blue running DHCP mode)

    I do know Netfilx blocks 3rd party VPN, so it may be an issue

    0
    Comment actions Permalink
  • Avatar
    Rob Knowles

    Thank you. Do we feel like the Blue can handle a 3rd-party VPN, a site-to-site back to my Gold (for me to admin their stuff), AND running DHCP for a small residential LAN (50ish devices) on top of its "normal" firewall/filtering duties as well?

    I'm thinking about some "custom" routing as well to play around with this site-to-site stuff (I may have my parents' data back up to a NAS at my house and possibly stash something at theirs for me to back up to just to hit the "Rule of Three" and have something offsite for both of us).

    The Blue was initially just an easy, low-cost quick solution to their security with the bonus that I could manage it for them remotely. Now I'm layering on some extra responsibilities to the device should I consider upgrading?

    0
    Comment actions Permalink
  • Avatar
    Firewalla

    The blue/blue+ units are focused more on augment what you have. If you are going to do complex routing, you really need use the two port devices, they support routing a lot better. (router mode) 

    0
    Comment actions Permalink
  • Avatar
    Rob Knowles

    That's fair. Thanks.

    0
    Comment actions Permalink

Please sign in to leave a comment.