You can make a VPN connection between a computer running W2K/XP and W2K/XP
with the "server" computer being limited to one connection. I would
recommend trying that first using pptp which is all you can use in the
method I just selected. See the link below to see how it is done in W2K and
the method would be similar to XP.
http://support.microsoft.com/default.aspx?scid=kb;en-us;257333
If you try such, the "server" end will need to configure the firewall NAT
router to allow traffic for port 1723 TCP and forward it to the internal
server. Also protocol 47 for GRE will need to be allowed for each end's
firewall NAT router. This may be referred to as pptp passthrough on many
devices. The other problem you have is dynamic IP addresses. To connect to
the server end [his office] he would need to enter the fully qualified
domain name in for his internet connection such as mycomputer.mydomain.com
OR the current IP address that the ISP has assigned. This may be a problem
if the IP address changes frequently. He may want to try and get static IP
address or use a dynamic dns service. He should be able to at least test it
out with the current dynamic IP as the address may not change frequently.
http://www.no-ip.com/ -- example of a dynamic dns service for internet IP
addresses.
Keep in mind that a VPN as you describe will be VERY slow compared to a
regular lan connection. The speed is limited by the maximum uplink speed of
the connection where the data is coming from which is usually a fraction of
the downlink speed for a consumer type DSL though business users can buy
faster uplink speeds. Also DSL users may need to tweak their MTU settings on
their DSL NAT routers to optimize VPN performance. If he still wants to go
with it a better long term solution would be to purchase and install an
ipsec endpoint device for each end of the VPN connection. I have used the
Netgear FVS318 to do such for example and that device costs around $100 and
is fairly easy to configure. It will replace current NAT routers and do that
function also. --- Steve
http://www.netgear.com/products/details/FVS318.php --- Netgear FVS318