Geekzone: technology news, blogs, forums
Guest
Welcome Guest.
You haven't logged in yet. If you don't have an account you can register now.


lchiu7

6476 posts

Uber Geek

Trusted

#204695 13-Oct-2016 11:44
Send private message

In one place where I worked VPN was enabled as follows:

 

- VPN client on the desktop

 

- second factor authentication via cell phone app 

 

Two end-user scenarios

 

1. Work laptop. Connect to VPN, authenticate and start working as if in the office

 

2. Home PC. Connect to VPN, authenticate and then RD to your work machine.

 

That worked okay but for users who did not have a laptop they had to leave their desktops on all the time with power saving mode disabled.

 

To try to make life easier I setup the following environment as a proof of concept.

 

Grabbed a spare PC (new as it happened with Core i7 16 GB 500GB SSD) and put Windows Server 2012R on it and joined to the domain.

 

Enabled Remote Desktop Services role, installed Office and then published the core Office applications (Outlook, Word, Excel, PPT)

 

Then a user could connect to the VPN as per 2, then fire up IE and point to the Remote Desktop Services server URL (obviously not a public one) and work.

 

The VPN software (can't remember which) I think disabled split tunnelling.

 

This seemed like a reasonable robust solution security wise but not being a security expert wouldn't mind some more qualified people to point out any security issues that might exist?

 

Obviously solution 2 means IT doesn't have control over the endpoint but given they are using Remote Desktop Services on a browser with split tunnelling disabled, I would think the risks of unauthorised access are low?

Thanks





Staying in Wellington. Check out my AirBnB in the Wellington CBD.  https://www.airbnb.co.nz/h/wellycbd  PM me and mention GZ to get a 15% discount and no AirBnB charges.


Create new topic

gzt

gzt
17122 posts

Uber Geek

Lifetime subscriber

  #1650567 13-Oct-2016 16:44
Send private message

Random question. Why use IE? Is it not simpler to use the Windows RDP client? I'm thinking activex is deprecated for a while and ActiveX and security were never happy playmates at the best of times.



Mattmannz
471 posts

Ultimate Geek


  #1650575 13-Oct-2016 16:59
Send private message

Install the Essentials role and use the built in SSTP VPN and also the easy to manage access anywhere. Port forward 443 to the server. Make sure you have password rotation on.


lchiu7

6476 posts

Uber Geek

Trusted

  #1650578 13-Oct-2016 17:05
Send private message

gzt: Random question. Why use IE? Is it not simpler to use the Windows RDP client? I'm thinking activex is deprecated for a while and ActiveX and security were never happy playmates at the best of times.

 

 

 

It was a while ago but perhaps it was the RDP client we used. I think you pointed your browser to the server and then it downloaded the client for your environment. 





Staying in Wellington. Check out my AirBnB in the Wellington CBD.  https://www.airbnb.co.nz/h/wellycbd  PM me and mention GZ to get a 15% discount and no AirBnB charges.


Create new topic





News and reviews »

Air New Zealand Starts AI adoption with OpenAI
Posted 24-Jul-2025 16:00


eero Pro 7 Review
Posted 23-Jul-2025 12:07


BeeStation Plus Review
Posted 21-Jul-2025 14:21


eero Unveils New Wi-Fi 7 Products in New Zealand
Posted 21-Jul-2025 00:01


WiZ Introduces HDMI Sync Box and other Light Devices
Posted 20-Jul-2025 17:32


RedShield Enhances DDoS and Bot Attack Protection
Posted 20-Jul-2025 17:26


Seagate Ships 30TB Drives
Posted 17-Jul-2025 11:24


Oclean AirPump A10 Water Flosser Review
Posted 13-Jul-2025 11:05


Samsung Galaxy Z Fold7: Raising the Bar for Smartphones
Posted 10-Jul-2025 02:01


Samsung Galaxy Z Flip7 Brings New Edge-To-Edge FlexWindow
Posted 10-Jul-2025 02:01


Epson Launches New AM-C550Z WorkForce Enterprise printer
Posted 9-Jul-2025 18:22


Samsung Releases Smart Monitor M9
Posted 9-Jul-2025 17:46


Nearly Half of Older Kiwis Still Write their Passwords on Paper
Posted 9-Jul-2025 08:42


D-Link 4G+ Cat6 Wi-Fi 6 DWR-933M Mobile Hotspot Review
Posted 1-Jul-2025 11:34


Oppo A5 Series Launches With New Levels of Durability
Posted 30-Jun-2025 10:15









Geekzone Live »

Try automatic live updates from Geekzone directly in your browser, without refreshing the page, with Geekzone Live now.



Are you subscribed to our RSS feed? You can download the latest headlines and summaries from our stories directly to your computer or smartphone by using a feed reader.