Welcome, Register for free! or Login below:
EduGeek.net RSS Feeds Register FAQ Members Social Groups User Map Calendar Search Today's Posts Mark Forums Read

Internet Related/Filtering/Firewall

Internet Related forum sponsored by
Internet Related Forum Sponsored by Smoothwall

Woes with your internet connection or maybe having filtering issues (that are not security related) post them here.

Go Back   EduGeek.net Forums > Technical > Internet Related/Filtering/Firewall
Reply
 
LinkBack Thread Tools Search Thread
Sponsored Links
Old 26-11-2009, 12:19 PM   #1
 
gjames's Avatar
 
Join Date: Oct 2008
Location: Leicestershire
Posts: 8
uk
Thanks: 0
Thanked 0 Times in 0 Posts
Rep Power: 0 gjames is an unknown quantity at this point
Default Remote access and Two Factor Authentication

Hi,

I have been looking into remote access and two factor authentication and I thought I'd post to try and find out what other people use. The RSA securID keyfobs seem popular but are expensive. I have stumbled across something called a yubikey (Yubico) but don't really know anything about it. What do others do to provide secure remote access?

TIA

Glenn
  Reply With Quote
Old 26-11-2009, 12:28 PM   #2
 
plexer's Avatar
 
Join Date: Dec 2005
Location: Norfolk
Posts: 6,044
uk
Thanks: 99
Thanked 349 Times in 304 Posts
Rep Power: 84 plexer has a brilliant future plexer has a brilliant future plexer has a brilliant future plexer has a brilliant future plexer has a brilliant future plexer has a brilliant future plexer has a brilliant future plexer has a brilliant future plexer has a brilliant future plexer has a brilliant future plexer has a brilliant future plexer has a brilliant future
Default

The Yubikey has to be physically pluuged in whereas the secure ID solution just requires you to type in the rolling 6 digit number so should be supported on a larger variety of devices.

Ben
  Reply With Quote
Old 26-11-2009, 12:30 PM   #3
 
plexer's Avatar
 
Join Date: Dec 2005
Location: Norfolk
Posts: 6,044
uk
Thanks: 99
Thanked 349 Times in 304 Posts
Rep Power: 84 plexer has a brilliant future plexer has a brilliant future plexer has a brilliant future plexer has a brilliant future plexer has a brilliant future plexer has a brilliant future plexer has a brilliant future plexer has a brilliant future plexer has a brilliant future plexer has a brilliant future plexer has a brilliant future plexer has a brilliant future
Default

Other alternatives include using their mobile phones and having a single use pin sent via text.

Ben
  Reply With Quote
Old 26-11-2009, 12:31 PM   #4
 
plexer's Avatar
 
Join Date: Dec 2005
Location: Norfolk
Posts: 6,044
uk
Thanks: 99
Thanked 349 Times in 304 Posts
Rep Power: 84 plexer has a brilliant future plexer has a brilliant future plexer has a brilliant future plexer has a brilliant future plexer has a brilliant future plexer has a brilliant future plexer has a brilliant future plexer has a brilliant future plexer has a brilliant future plexer has a brilliant future plexer has a brilliant future plexer has a brilliant future
Default

Two-Factor Authentication using mobile phones
  Reply With Quote
Old 26-11-2009, 02:13 PM   #5
 
Willott's Avatar
 
Join Date: Dec 2008
Location: Nottingham
Posts: 145
uk uk england
Thanks: 16
Thanked 31 Times in 29 Posts
Rep Power: 10 Willott has a spectacular aura about Willott has a spectacular aura about Willott has a spectacular aura about
Default

I have been thinking about this on 2 fronts - 1st for staff (with staff laptops) and secondly for students.

For staff, I have VPN setup, with the first factor being machine specific (SSL Client Certificate unique to machine - if machine is compromised it can be revoked) and the second being user specific (domain username and password).

For students (and staff without laptops), I'm thinking of having Squid setup in front of a Terminal Services Gateway, having authentication on the squid box which authenticates to a local database (1st factor - change password/pin in squid database if need be), then the user authenticating against the TS Gateway with domain credentials (and so showing them where they can logon to) - the second factor. This is only a theoretical idea of how I may do things here, it's most likely going to be the project for next year or the year after (along with a few more TSs so I can actually handle a large number of students being on - and hopefully a 100Mb net connection so we can handle a large number of students!).

The 2 factor using mobile phones for single use pin looks interesting - may consider adding in something like that (that sends pin to predefined mobile number and links to a username in squid).

Cheers

Will
  Reply With Quote
Old Yesterday, 10:11 AM   #6
 
plexer's Avatar
 
Join Date: Dec 2005
Location: Norfolk
Posts: 6,044
uk
Thanks: 99
Thanked 349 Times in 304 Posts
Rep Power: 84 plexer has a brilliant future plexer has a brilliant future plexer has a brilliant future plexer has a brilliant future plexer has a brilliant future plexer has a brilliant future plexer has a brilliant future plexer has a brilliant future plexer has a brilliant future plexer has a brilliant future plexer has a brilliant future plexer has a brilliant future
Default

Anyone else using 2 factor auth for anything?

There is a new software product out along with the Yubikey called authlite for ad windows login.

2 Yubikeys with authlite licences are $62.50

Ben
  Reply With Quote
Old Yesterday, 10:16 AM   #7
 
plexer's Avatar
 
Join Date: Dec 2005
Location: Norfolk
Posts: 6,044
uk
Thanks: 99
Thanked 349 Times in 304 Posts
Rep Power: 84 plexer has a brilliant future plexer has a brilliant future plexer has a brilliant future plexer has a brilliant future plexer has a brilliant future plexer has a brilliant future plexer has a brilliant future plexer has a brilliant future plexer has a brilliant future plexer has a brilliant future plexer has a brilliant future plexer has a brilliant future
Default

If you order them via/for school and have a vat number 2 keys with authlite licences would be $57 (£36) with recorded delivery.

Orders for the uk are fullfilled from their uk shipping office.

Ben
  Reply With Quote
Reply

EduGeek.net Forums > Technical > Internet Related/Filtering/Firewall

Similar Threads
Thread Thread Starter Forum Replies Last Post
Securing Windows server 2003 Remote Desktop access for access through the internet albertwt Windows Server 2000/2003 20 20-08-2009 09:40 PM
Two factor authentication k-mart Windows 0 28-10-2006 04:28 PM


Tags
ras , rsa , two factor , yubikey


Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools Search Thread
Search Thread:

Advanced Search

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT +1. The time now is 01:13 PM.
Powered by vBulletin® Version 3.8.4
Copyright ©2000 - 2010, Jelsoft Enterprises Ltd.
SEO by vBSEO 3.3.2 ©2009, Crawlability, Inc.
Copyright EduGeek.net




website uptime

© 2005 - 2009 EduGeek.net
SERVER: 4
no new posts