Educause Security Discussion mailing list archives

Re: Remote Access to Staff Desktops


From: Timothy Payne <tpayne1 () MACALESTER EDU>
Date: Wed, 18 Feb 2009 08:03:18 -0600

We are actually pushing away from RDP for a variety of reasons.
Currently, we are moving ahead with a plan to migrate any requested
applications to our Citrix solution.  This also solves another of our
issues, which is users storing critical data on their desktops.  By
moving the application to the network, we also force the data to
follow to their personal or group drives.

As of now, we have not encountered any programs or users that were
unable to move to the new system.

Tim Payne, CISSP, CCNA
Network Administrator
Macalester College



On Wed, Feb 18, 2009 at 7:28 AM, Di Fabio, Andrea <adifabio () nsu edu> wrote:
We do provide RDP access to Faculty/Staff Desktops but the users still need
to authenticate against our VPN concentrators which limit their access to TCP
port 3389, DNS and a few other ports, prevents brute force attacks from the
Internet, and prevent account lockouts due to brute force.  We limit the
ports they have access to via VPN to avoid infection of the well know and
exploited MS protocols (and others) and because we do not quite trust the end
user machine.


-----Original Message-----
From: The EDUCAUSE Security Constituent Group Listserv on behalf of Tim Lane
Sent: Tue 2/17/2009 23:30
To: SECURITY () LISTSERV EDUCAUSE EDU
Subject: [SECURITY] Remote Access to Staff Desktops

Hi All,



We are receiving an increasing number of requests from staff to remotely
access their desktops, for a variety of reasons.



I would be interested in hearing if any other Universities allow this, and
if so how you are providing secure access, or if you have any
thoughts/comments on the matter.



Thanks,



Tim



Tim Lane

Information Security Program Manager

IT&TS

Southern Cross University

Ph (02) 6620 3290

Mobile 0418 248 571




Current thread: