ML
    • Recent
    • Categories
    • Tags
    • Popular
    • Users
    • Groups
    • Register
    • Login

    How does DirectAccess compare to Pertino

    IT Discussion
    directaccess windows 2012 r2 vpn networking
    11
    46
    12.1k
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • Bill KindleB
      Bill Kindle @Josh
      last edited by

      @Josh TBH, I haven't seen very many people post about it in the forums either.

      scottalanmillerS 1 Reply Last reply Reply Quote 0
      • scottalanmillerS
        scottalanmiller @Bill Kindle
        last edited by

        @Bill-Kindle said:

        @Josh TBH, I haven't seen very many people post about it in the forums either.

        No, DA has gotten nearly a complete snub in the SMB world because of the cost, complexity and limitations.

        1 Reply Last reply Reply Quote 1
        • C
          Carnival Boy @Carnival Boy
          last edited by

          @Carnival-Boy said:

          @JaredBusch said:

          Read the above posts discussing the subject. I would never have deployed hamachi as you did for security purposes. Yes, it works, but I do not like the method.
          Then again, I do not like a VPN gateway for users either since it does the same thing. For IT staff yes, but not users.

          I did, but I don't understand them 😞

          Seriously, if anyone could explain, in simple terms, the security risks in Hamachi (or similar VPN) I would be really, really grateful.

          1 Reply Last reply Reply Quote 0
          • scottalanmillerS
            scottalanmiller
            last edited by

            It's not the security risk of the VPN but of a gateway component. When you have a VPN that simply exposes a tunnel then anything that gets onto the network at one end has access to everything at the other end.

            What Pertino is trying to do is bring a higher level of control and security assurance often to people lacking network engineers. If you have a gateway, this blinds Pertino's software to what is going onto the network and it lacks the ability to identify and cut off a foreign attacker that without a gateway it does naturally.

            It is not that a gateway is insecure, it is that it lacks the lock down, visibility and control features that only a full mesh can provide.

            RoguePacketR C 2 Replies Last reply Reply Quote 1
            • NaraN
              Nara @scottalanmiller
              last edited by

              @scottalanmiller said:

              Pertino has automatic load balancing across the country (or globe.) DA does not include that ability although with some effort you could build your own.

              DirectAccess can be set up to select servers by geolocation.

              scottalanmillerS 1 Reply Last reply Reply Quote 0
              • scottalanmillerS
                scottalanmiller @Nara
                last edited by

                @Nara said:

                @scottalanmiller said:

                Pertino has automatic load balancing across the country (or globe.) DA does not include that ability although with some effort you could build your own.

                DirectAccess can be set up to select servers by geolocation.

                That's cool, is that a new feature added in later versions?

                1 Reply Last reply Reply Quote 0
                • NaraN
                  Nara
                  last edited by

                  I set up DirectAccess over the weekend, and it only took me about 40 minutes. Server 2012's implementation is absurdly quick and easy for a basic single-server deployment. It even creates the necessary GPOs for you. All you need to do is select the group of computers it applies to and tweak any related DNS resolution table entries. If you want to go into a more advanced deployment, it could potentially get a bit more involved.

                  It's location-aware and doesn't enable itself when it can see the corporate network. The moment I switched over to an external network, DA engaged. If you have software assurance on your computers, you really should be considering this. While I haven't tested any quirky legacy applications with it, typical file services and use cases seem to work fine. If you test it and don't like it, you can use the same wizard to pull out the entire configuration, GPOs and all.

                  Having used both, they're really for different environments. Pertino's good for accessing other computers directly. DirectAccess is good for accessing infrastructure. If you're in a workgroup setup, Pertino would be great. You get the unstructured cross-communication that you'd expect. If you're on a domain, DirectAccess shines. You get timely connectivity to your environment when you need it, and don't need to modify any of your other servers or devices. I'm sure that as both technologies evolve and mature, things may change, but for now, that's how I've experienced it.

                  1 Reply Last reply Reply Quote 3
                  • scottalanmillerS
                    scottalanmiller
                    last edited by

                    I assume that there is no means of using DA with Macs, for example?

                    NaraN 1 Reply Last reply Reply Quote 0
                    • RoguePacketR
                      RoguePacket @scottalanmiller
                      last edited by

                      @scottalanmiller said:

                      What Pertino is trying to do ....

                      Still don't have a firm "knowing" of what Pertino is, but that has been more helpful than anything thus far.

                      1 Reply Last reply Reply Quote 0
                      • C
                        Carnival Boy @scottalanmiller
                        last edited by

                        @scottalanmiller said:

                        It is not that a gateway is insecure, it is that it lacks the lock down, visibility and control features that only a full mesh can provide.

                        So what's the difference between Pertino's mesh and Hamachi in mesh mode?

                        The biggest problem I had trying to implement DA in Server 2008 was that I wasn't running Forefront UAG, and Microsoft made it very complicated to implement without it. Is that still the case with 2012?

                        scottalanmillerS 1 Reply Last reply Reply Quote 0
                        • scottalanmillerS
                          scottalanmiller @Carnival Boy
                          last edited by

                          @Carnival-Boy said:

                          @scottalanmiller said:

                          So what's the difference between Pertino's mesh and Hamachi in mesh mode?

                          At the moment they are pretty similar. Pertino's product is current and not many years abandoned though. Hamachi was abandonware when we moved off of it four or five years ago.

                          Hamachi isn't cross platform so if you have Linux or smartphones you are just out of luck which is hugely limiting today. Not sure if there is even Mac support. Pertino handles windows, Mac, Linux, android and iOS is on the way. After those I will be pushing them for FreeBSD.

                          But all this for hamachi is the last part of the story. With hamachi we are just waiting for things to spin down as they no longer push or develop the platform. With Pertino things are just spinning up and what you see today is just the tip of the iceberg.

                          Pertino's strength is in their vision and in how the platform is implemented. There is a lot of performance and robustness built in from day one.

                          1 Reply Last reply Reply Quote 0
                          • NaraN
                            Nara @scottalanmiller
                            last edited by

                            @scottalanmiller said:

                            I assume that there is no means of using DA with Macs, for example?

                            Not at present. You can, however, use the same RAS servers for VPN. Perhaps if/when Macs gain more traction in the mainstream business market, we'll see that shift.

                            1 Reply Last reply Reply Quote 0
                            • 1
                            • 2
                            • 3
                            • 3 / 3
                            • First post
                              Last post