GRitchie Posted February 10, 2015 Posted February 10, 2015 Hello, Working from home for staff Easiest options? FortiClient VPN - Tried it ROBOCOPY (Files on C: ) - Tried it Remote Desktop - Tried it (contemplating this again however) Home Access Plus - Not an option Any ideas................
FN-GM Posted February 10, 2015 Posted February 10, 2015 Microsoft Direct Access. You literally connect the laptop to the internet and it will automatically VPN back to the system. The user has to do nothing at all.
GRitchie Posted February 10, 2015 Author Posted February 10, 2015 Microsoft Direct Access. You literally connect the laptop to the internet and it will automatically VPN back to the system. The user has to do nothing at all. What's this like from an administrators perspective? ie. Setup process? I've heard it's rather awkward/challenging.
FN-GM Posted February 10, 2015 Posted February 10, 2015 I haven't actually done it. I plan on soon. It doesn't look particularly hard. Loads of videos on youtube.
fiza Posted February 10, 2015 Posted February 10, 2015 With Direct Access what if the PC the user is on is already a member of another domain?
FN-GM Posted February 10, 2015 Posted February 10, 2015 Depends on the AD setup. If they are in the same forest or have trusts etc.
fiza Posted February 10, 2015 Posted February 10, 2015 Depends on the AD setup. If they are in the same forest or have trusts etc. Nada - completely separate domains
robjduk Posted February 10, 2015 Posted February 10, 2015 I push remote desktop apps which most staff can use but being asked to put their domain/username stumps half of them (trying not to remember how much more money they are on....) I used and deployed Direct Access however while testing it, errors would sometimes occur and if that happens EVERYTHING becomes bricked. If there is the slightest error, the laptop will refuse to authenticate and update group policy or connect to network shares until it is back online. Now I may have been unlucky and although I would often blame myself, there are not many buttons to press to get it wrong. I have come to the conclusion it is a nice feature for small offices to use but in a school, there is too much at stake if it goes tats up. I know a better man than me would be able to fix it when it goes wrong but I think it is a reason Direct Access has not killed off remote desktops or VPN's.
MatthewL Posted February 10, 2015 Posted February 10, 2015 I would be one for a VPN client which forces the user to connect before they can login on a RDP session with everything available. Can anyone point me to some good guides on Direct Access would like to know a bit more about this.
m25man Posted February 11, 2015 Posted February 11, 2015 For years we have always used Sonicwall SRA Appliances. Not the cheapest option but reliable feature rich. For starters they can RDP to their own desktop PC or a pool of unused machines at evenings or weekends. The SSL VPN feature allows full connections to those who need it. No RDS server needed although it's easy to point to if you want to. Supports HTML5 RDP so running your Windows RDS session or office PC from your iPad is a breeze. Geo Blocking, OTP, SSL Pass Thru, AD Integration & Remote App support to name just a few. They are licensed for concurrent users but you can get spike licenses for the unforeseen problems like transport outages or Snow Days... Once you've got your firewall forwarding Port 443 to an SRA and install a proper SSL Cert your Remote Access headaches are gone. Swear by them, a one stop Remote Access solution but be prepared to splash some cash... Fast, Cheap, Good - Basic rule of IT, pick any two applies.
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now