SOLVED

VPN Options for Two Azure VM's

%3CLINGO-SUB%20id%3D%22lingo-sub-96950%22%20slang%3D%22en-US%22%3EVPN%20Options%20for%20Two%20Azure%20VM's%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-96950%22%20slang%3D%22en-US%22%3E%3CP%3EHello%20all%2C%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EWe%20are%20running%20two%20Azure%20VM's%20(Windows%20Server%202008R2%20-%20I%20know%20-%20must%20upgrade!)%20-%20currently%20the%20users%20connect%20to%20the%20one%20VPN%20via%20RDP%20-%20with%20those%20default%20RDP%20ports%20changed%20in%20Endpoints.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EI%20can%20secure%20RDP%26nbsp%3Bfurther%20using%20ACL's%20however%20someone%20in%20our%20office%20has%20suggested%20we%20use%20LogMeIn's%20Hamachi%20as%20a%20VPN.%20%26nbsp%3BWe%20currently%20have%20a%20LMI%20Central%20account%20-%20for%20users%20to%20connect%20remotely%20to%20their%20office%20desktops.%20%26nbsp%3BThis%20person%20noticed%20the%20Hamachi%20option%20in%20there%20and%20wants%20to%26nbsp%3Bpossibly%20use%20that.%20%26nbsp%3BI%20reached%20out%20to%20LMI%20and%20they%20say%20Hamachi%20works%20but%20is%20not%20fully%20supported.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EI%20am%20thinking%20why%20not%20just%20use%20Azure's%20Point-to-Site%20VPN%3F%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EHas%20anyone%20used%20Hamachi%20as%20a%20VPN%20for%20clients%20connecting%20to%20a%20VM%20via%20RDP%3F%20%26nbsp%3BIs%20it%20recommended%3F%20%26nbsp%3BI%20suspect%20not%20but%20again%20just%20wanted%20to%20confirm%20so%20can%20pass%20on%20to%20this%20user%20(manager!).%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EThanks%20so%20much!%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-LABS%20id%3D%22lingo-labs-96950%22%20slang%3D%22en-US%22%3E%3CLINGO-LABEL%3EAzure%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3ERDP%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3EVirtual%20Network%3C%2FLINGO-LABEL%3E%3C%2FLINGO-LABS%3E%3CLINGO-SUB%20id%3D%22lingo-sub-101831%22%20slang%3D%22en-US%22%3ERe%3A%20VPN%20Options%20for%20Two%20Azure%20VM's%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-101831%22%20slang%3D%22en-US%22%3E%3CP%3EThank%20you%20very%20much%20for%20this%20info!%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EI%20have%20since%20set-up%20ACL's%20for%20the%20office%20locations...working%20great!%20%26nbsp%3BSome%20users%20work%20from%20home%20occasionally...I%20have%20entered%20their%20IP's%20in%20ACL%20so%20all%20good%20there%20but%20I%20will%20still%20look%20at%20the%20Point-to-Site%20VPN%20for%20those%20times%20their%20IP%20changes%20and%20I'm%20not%20around%20to%20update%20it%20in%20Azure....just%20being%20proactive%20on%20that%20front!%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EDefinitely%20not%20pursing%20Hamachi%20now....phew!%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EThanks%20again%20for%20your%20help!%3C%2FP%3E%3CP%3ECheers!%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-97065%22%20slang%3D%22en-US%22%3ERe%3A%20VPN%20Options%20for%20Two%20Azure%20VM's%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-97065%22%20slang%3D%22en-US%22%3E%3CP%3EHi%20Tammy%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EIf%20we%20just%20clarify%20what%20you%20want%20to%20achieve%3C%2FP%3E%3CUL%3E%3CLI%3EYou%20have%20a%20VNET%20in%20azure%3C%2FLI%3E%3CLI%3EYou%20wish%20for%20clients%20to%20connect%20directly%20to%20this%20VNET%20in%20order%20to%20gain%20access%20to%20servers%20in%20the%20VNET%20using%20Azure%20features.%3C%2FLI%3E%3C%2FUL%3E%3CP%3Eif%20this%20is%20correct%2C%20then%20all%20you%20need%20to%20configure%20is%20Point%20to%20Site%20VPN%2C%20this%20will%20allow%20all%20clients%20to%20connect%20directly%20to%20the%20VNET.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EThat%20being%20said%2C%20if%20you%20have%20different%20coprate%20locations%20that%20need%20to%20access%20these%20servers%20then%20a%20Site%20to%20Site%20VPN%20between%20the%20on%20premise%20endpoint%20and%20your%20VNET%20is%20the%20option%20you%20need%20to%20go%20with.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EI%20have%20not%20used%20Hamachi%20in%20a%20long%20time%2C%20but%20under%20no%20curcimstances%20is%20that%20a%20solution%20i%20personally%20would%20indorse.%3C%2FP%3E%3C%2FLINGO-BODY%3E
Highlighted
Contributor

Hello all,

 

We are running two Azure VM's (Windows Server 2008R2 - I know - must upgrade!) - currently the users connect to the one VPN via RDP - with those default RDP ports changed in Endpoints.

 

I can secure RDP further using ACL's however someone in our office has suggested we use LogMeIn's Hamachi as a VPN.  We currently have a LMI Central account - for users to connect remotely to their office desktops.  This person noticed the Hamachi option in there and wants to possibly use that.  I reached out to LMI and they say Hamachi works but is not fully supported.

 

I am thinking why not just use Azure's Point-to-Site VPN?

 

Has anyone used Hamachi as a VPN for clients connecting to a VM via RDP?  Is it recommended?  I suspect not but again just wanted to confirm so can pass on to this user (manager!).

 

Thanks so much!

2 Replies
Highlighted
Best Response confirmed by Tammy Schwark (Contributor)
Solution

Hi Tammy

 

If we just clarify what you want to achieve

  • You have a VNET in azure
  • You wish for clients to connect directly to this VNET in order to gain access to servers in the VNET using Azure features.

if this is correct, then all you need to configure is Point to Site VPN, this will allow all clients to connect directly to the VNET.

 

That being said, if you have different coprate locations that need to access these servers then a Site to Site VPN between the on premise endpoint and your VNET is the option you need to go with.

 

I have not used Hamachi in a long time, but under no curcimstances is that a solution i personally would indorse.

Highlighted

Thank you very much for this info!

 

I have since set-up ACL's for the office locations...working great!  Some users work from home occasionally...I have entered their IP's in ACL so all good there but I will still look at the Point-to-Site VPN for those times their IP changes and I'm not around to update it in Azure....just being proactive on that front!

 

Definitely not pursing Hamachi now....phew!

 

Thanks again for your help!

Cheers!