VPN layout question

Chris Dahms <[email protected]> Tue, 26 Oct 2004 13:11:30 -0700
Newsgroups gmane.comp.security.vpn
Message-ID <[email protected]>
Hi,

I work for a small doctors office that has three locations across long 
island and we are looking to overhaul our network connection in 
conjunction with upgrading our practice management software. Currently 
we have a 'vpn' of sorts setup by point to point frame relay from two of 
the offices to the main office. The hardware 8+ years old and failing, 
so we need to replace everything.

The network needs to provide secure communication between all three 
offices. The practice management software we uses resides on one server 
at our main location, and needs to be able to securely communicate with 
the other two offices.

My question is with regard to the network toplogy. I was under the 
impression we could get a T1 to each site, buy cisco 2600 series routers 
for each office with a VPN module card, and set it up so that office 1 
was on say 192.168.1.x, office 2 on 192.168.3.x and office 3 on 
192.168.4.x and then when office 1 wanted to communicate with office 2, 
the packets from office 1 would be encrypted and routed by the vpn 
module over to the router at office 2 and sent to the appropriate 
machine. Then as a backup we could have dsl at each location hooked into 
the router, and if the t1 when down it would fail over to the dsl.

The network consultants we contract with are recommending point to point 
t1's from each smaller office to the main office with the network 
server, and then having each office have a seperate t1 for an internet 
connection, in addition to the dsl failover. When I asked about the 
design I had in mind, they replied it was unsecure/unreliable but failed 
to explain why.

My question is: is the network toplogy I have in mind feasible/reliable, 
or do we need point to point internet connections between the offices to 
establish the vpn ?

thanks,
chris