Educause Security Discussion mailing list archives

Re: Remote Access to Staff Desktops


From: Mark Monroe <markm196 () NETSCAPE NET>
Date: Wed, 18 Feb 2009 09:14:52 -0600

We allow it only through VPN. For Users who say they need ssh open
without vpn, they can have it open only if they implement technology on
their box that will blacklist  any ip  address after  3 failed attempts
and any ip address that  tries to use root. I have not opened any yet
outside systems run by core IT staff. I guess they didn't really need it.

Mark Monroe


Gary Flynn wrote:
Tim Lane wrote:

We are receiving an increasing number of requests from staff to
remotely access their desktops, for a variety of reasons.

I would be interested in hearing if any other Universities allow
this, and if so how you are providing secure access, or if you have
any thoughts/comments on the matter.

When someone requests exposure of a remote control or shell service
( e.g. RDP, VNC, SSH, telnet ) we will grant it but only after
recommending they use our VPN instead.




Current thread: