Jump to content

Recommended Posts

Posted

Hi All,

 

Our head has requested that we provide SIMS.net access for our teaching staff from home but do not want to stump up for the cost of SIMS learning gateway. Has anyone else setup a similar system because I just need a few pointers. Can this be setup through RemoteApp? Some hand holding would be greatly appreciated.

Posted

No, preferably not. Once you provide VPN connection, it allows the end user access to your network, so they should see the sims server and be able to run SIMS as though they are at school. The speed can be a pain though and it often affects their local browsing of internet if not configured right.

 

You might be better off with Terminal Services, or depending on what functionality they require from home, a product from TASC, which is cheaper than SLG and gives you some powerful features.

  • Thanks 1
Posted
Hi Quackers,

 

Do I install and configure the Windows vpn service on the actual SIMS.net server. Have you done this at your school?

 

We just have a HyperV VM for it. If you want a play plenty of youtube videos for step by step to get one up and running quickly to sample it like Tutorial How to Install VPN Server 2008 R2 - YouTube

 

We have Terminal Services, VPN , and 2X/Terminal Services so many options for staff to choose.

  • Thanks 1
Posted

We use Teachers Web Folder from Bromcom, Allow most staff to do what they need without using the VPN service.

 

There is also a VPN service provided by our LEA internet connection, which is very reliable and staff can connect using Terminal Services to that, if they need full fat SIMS but the majority use TWF, and the PE staff like TWF as we have the mobile interface so they can do their registers in the middle of the field on their phones :-)

  • Thanks 1
Posted
We use our FortiGate for VPN handling, ontop of that we just use RDWeb just means people don't have a remote desktop open only the application they were after, which obviously is a lie because it has a RD session open in the background.
Posted

We use Remote desktop to the Sims Server. But staff are only allowed to connect with a school owned device not their own personal device.

 

Harriuk

  • Thanks 2
Posted

Hey guys sorry to throw a spanner in the works and this applies to me as well we had a data protection official from our local authority in a few weeks back and it was basically a information gathering session between me and our bm and one of the topics that came up was how do you make sure that when members of staff at home are given the potential of access to the system how do you stop people from shoulder looking etc/ leaving the application open to preying eyes etc when they are /not infront of the their system when at home.

 

And you know what I most produced a brick lol but you cant and the thing is yes its ok to open the system up to let staff have access to sims from home but remember they have to understand the consequences if sensitive information is leaked

 

Just something to think about

  • Thanks 1
Posted
Use our own remote access solution built around RDP but with encrypted App for dual factor Authentication for Staff so they can access SIM's, works well as logs everything as well.

 

What encrypted app do you use for 2 factor auth? And how did you set it up?

Posted (edited)
What encrypted app do you use for 2 factor auth? And how did you set it up?

It is just a piece of software we have developed with someone else you can just download a piece of software onto device memory stick, pc or laptop and can generate a unique key for this that when you run the app the first time copy in the key and it registers against some software on the Server each key is unique and encrypted. Then double click the app and it does first factor then username and password second factor. We have a client on each PC and this controls if you can access this with single or dual factor so all SIM's machines require Dual Factor, if that makes sense and is controlled by the software on the server.

 

Very rough explanation.

Edited by Steven_Cleaver
Posted
how do you make sure that when members of staff at home are given the potential of access to the system how do you stop people from shoulder looking etc/ leaving the application open to preying eyes etc when they are /not infront of the their system when at home.

 

And you know what I most produced a brick lol but you cant and the thing is yes its ok to open the system up to let staff have access to sims from home but remember they have to understand the consequences if sensitive information is leaked

 

... and this is why we removed our remote SIMS access that was on our RDS servers. We were asked to give access by the Head of School but it was overruled by the Exec Head. The argument goes along the lines of "I trust my staff but I don't necessarily trust whoever is in their house".

 

Think carefully before allowing access unless you can create a well locked down, very little information shown (no photos, addresses, contacts etc.) user that they can access from outside the school that still allows them to do what they need to do.

 

HBJB

Posted
We have terminal server set-up which does work well but there is a per user connection cost, so have now set up openVPN on a cheap desktop machine on a linux server. Each staff laptop (which is encrypted) is configured to access the vpn and so far it has been a great success for sims and network shares and outlook, all for free apart from cost of a machine.
Posted

Think carefully before allowing access unless you can create a well locked down, very little information shown (no photos, addresses, contacts etc.) user that they can access from outside the school that still allows them to do what they need to do.

 

HBJB

 

We've never had a problem with it.

 

The only people who use our remote access use their staff laptops which have pretty strong passwords on them, then they have to use the VPN (A different password) then two more passwords before they can get anywhere.

I know that sounds like the situation where people would write the passwords down but believe me I've never seen people with such good memories.

 

The only thing we're concerned about with relation to SIMS is installing the application on devices that are taken out of the school, we outright refuse to do it.

Posted
We've never had a problem with it.

 

The only people who use our remote access use their staff laptops which have pretty strong passwords on them, then they have to use the VPN (A different password) then two more passwords before they can get anywhere.

I know that sounds like the situation where people would write the passwords down but believe me I've never seen people with such good memories.

 

The only thing we're concerned about with relation to SIMS is installing the application on devices that are taken out of the school, we outright refuse to do it.

 

I think the point is more, logging in and leaving the laptop unattended, or someone just looking over the shoulder of the staff member.

 

People trust their family and friends but that doesn't mean to school necessarily should do.

Posted
I think the point is more, logging in and leaving the laptop unattended, or someone just looking over the shoulder of the staff member.

 

People trust their family and friends but that doesn't mean to school necessarily should do.

 

I get your point here, We've made it a point to be harsh about the whole "Lock your computer" situation, Then again I do agree with the statement the school has no reason to trust someones family members.

Posted
I think the point is more, logging in and leaving the laptop unattended, or someone just looking over the shoulder of the staff member.

 

People trust their family and friends but that doesn't mean to school necessarily should do.

 

Exactly - it's not about passwords or the fact that it's a school laptop - it's about them potentially having it on screen and walking away to make the dinner or having someone look over their shoulder. You cannot guarantee that the data is safe.

 

HBJB

Posted
another preventative measure we have in place is a fairly tight 5 min idle timeout on RD connections. Does it stop someone looking over your shoulder? No. Does it mean that you can leave the computer and no-one see Sims? Of course not. But it does cut down the window of time in which it can happen. This, coupled with a separate Remote Access AUP tied to the schools disciplinary policy, means that we have got the risk factor down to what we view as an acceptable level.
Posted

You can create quite a simple two factor auth system using code from Google and the Google Authenticator app, I've not done it but all you need is a simple front end to do the first auth with which then passes you on to a second login page. At least this would work well for a web based system.

 

I actually use GA with my hotmail account !

 

As for security of information this is a valid point and organisations need to have security and more importantly a policy, in place. Most modern MISes have web based access and that is full access, no locked down version. It's only SIMS where we try to find these work arounds, but even with their SLG product I don't think the access is locked down. It's up to the school to think about this, and as IT Pros our job to inform them of the need for this, even though the buck stops at the Head or whoever is higher up.

Posted
You can create quite a simple two factor auth system using code from Google and the Google Authenticator app, I've not done it but all you need is a simple front end to do the first auth with which then passes you on to a second login page. At least this would work well for a web based system.

 

I actually use GA with my hotmail account !

 

As for security of information this is a valid point and organisations need to have security and more importantly a policy, in place. Most modern MISes have web based access and that is full access, no locked down version. It's only SIMS where we try to find these work arounds, but even with their SLG product I don't think the access is locked down. It's up to the school to think about this, and as IT Pros our job to inform them of the need for this, even though the buck stops at the Head or whoever is higher up.

 

So correct me if I'm wrong then.

 

Our staff need to have one of our laptops before they can connect remotely. They need to enter their Network credentials to access the Remote App, they also have a separate SIMS username and Password before they can access SIMS. What's the thoughts around that scenario?

 

harriuk

Posted

If they can only access through the laptop that is the first factor (physical) then the uname and pword is second (mental??) so that's good.

To mitigate social engineering / careless practise you just need a policy to ensure they are made aware of risks and that they use best practice such as locking machine, not printing out, ideally not downloading data to laptop unless it's encrypted and password protected etc.

Posted
If they can only access through the laptop that is the first factor (physical) then the uname and pword is second (mental??) so that's good.

To mitigate social engineering / careless practise you just need a policy to ensure they are made aware of risks and that they use best practice such as locking machine, not printing out, ideally not downloading data to laptop unless it's encrypted and password protected etc.

 

Excellent, that's what I thought!, Our legacy laptops only allow them to save into their N: Drive, nowhere else, this is synced offline and encrypted. Our newer laptops are totally encrypted. As for the Risks we have a pop up on the gateway that explains these risks.

 

Thanks for the info.

 

harriuk

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...