Connect the client computers to a vpn enabled router. Connect the wan router to a lan freeswan vpn server. Set the server to allow connections to the IP of whatever servers you want the clients to touch for mapping.
I have set this up on 3 wan sites already, and the most you have to worry about are packet keepalive settings for key exchange. Just set it high. The speed beats the hell out of ATM or Frame Relay. You will need to configure your WAN router properly, and will need to either have a network router guy handy or be prepared to tinker with it. And you can't beat the price.. Saving 30K on a Cisco concentrator and 20K and Cisco ACS software is no small feat. Keep that in mind when you run into trouble. It's worth it.
|