kennysarmy Posted June 5, 2015 Posted June 5, 2015 Wondering what my options are and rough costs if anyone has already set this up. No. of teacher who would require access is circa. 85.
localzuk Posted June 5, 2015 Posted June 5, 2015 (edited) We have Remote Desktop Server set up, with the Web Gateway part set up also. Cost is about £300 per year for us for the RDS CALs under EES. Plus the servers running it (not an extra cost for us, as its a virtual server setup). Edited June 5, 2015 by localzuk
Steve21 Posted June 5, 2015 Posted June 5, 2015 We just have remote access setup etc for all programs rather than just SIMs as part of our EES. 101x WinRmtDsktpSrvcsCAL ALNG LicSAPk OLV E 1Y Acdmc AP UsrCAL £5.59 £564.35 ^ Lazy to do maths but yeah as an example Steve
kennysarmy Posted June 5, 2015 Author Posted June 5, 2015 We just have remote access setup etc for all programs rather than just SIMs as part of our EES. 101x WinRmtDsktpSrvcsCAL ALNG LicSAPk OLV E 1Y Acdmc AP UsrCAL £5.59 £564.35 ^ Lazy to do maths but yeah as an example Steve Whilst that's great - that's only the licence costs - what about the setup? New hardware, installation etc? 1
Steve21 Posted June 5, 2015 Posted June 5, 2015 Whilst that's great - that's only the licence costs - what about the setup? New hardware, installation etc? It's on our Virtual so nothing You using physical? Steve
kennysarmy Posted June 5, 2015 Author Posted June 5, 2015 We have Remote Desktop Server set up, with the Web Gateway part set up also. Cost is about £300 per year for us for the RDS CALs under EES. Plus the servers running it (not an extra cost for us, as its a virtual server setup). We also have a virtual infrastructure - so what exactly is the route for staff at home - do you have a test user I could try? - - - Updated - - - It's on our Virtual so nothing You using physical? Steve No virtual - how many concurrent users can it support?
localzuk Posted June 5, 2015 Posted June 5, 2015 (edited) For staff at home, they go to our RDS server web page, they log in using their network username/password and click "SIMS.Net" and log in a second time. Then, they get the SIMS login box and they log in using that. Yes, its 3 logins, but it works and staff are happy with it. Can't give a test user sadly. We've never seen more than 3 staff logged in at once using it, even during reporting season, out of 30+ teachers. Uses a few GB of RAM, and we have the hard disk image hosted on an array of SSDs (along with our internal student RDS server farm and our SIMS server). Edited June 5, 2015 by localzuk
kennysarmy Posted June 5, 2015 Author Posted June 5, 2015 We also have a virtual infrastructure - so what exactly is the route for staff at home - do you have a test user I could try? - - - Updated - - - No virtual - how many concurrent users can it support? If it's so easy why do schools go with full blown citrix thin client solutions?
Steve21 Posted June 5, 2015 Posted June 5, 2015 Depends if you want RemoteApps or Full Remote Desktop, but example: (Which is linked off website) Steve
kennysarmy Posted June 5, 2015 Author Posted June 5, 2015 Depends if you want RemoteApps or Full Remote Desktop, but example: [ATTACH=CONFIG]30832[/ATTACH] [ATTACH=CONFIG]30833[/ATTACH] (Which is linked off website) Steve Thanks. To start with just remote access to SIMS.net I could n't pick your brains as to which resource you used to do the installation? or is it just following the standard MS articles? I'll give this a go next week. I presume I need some firewall rules amending by SWGfL too, to allow remote access inbound to a new virtual server.... And is it then just a case of installing SIMS.net on the Remote Desktop Server? Cheers
Steve21 Posted June 5, 2015 Posted June 5, 2015 Sorry what I meant was we have both setup but "currently" they're using the full Remote Desktop, rather than Apps. That'll change over Summer as we left it as just Remote Desktop currently as that's what they were used to from XP days So they also have full RD as such: Just normal setup so depends how you do it. As in if you're using the web-based portal it's 443 as it's web server, than internal. Or 3389 for RDP direct to full server etc. In answer to your citrix question pre-2012R2 it's not been so snazzy/easy, but nowadays I have been wondering the same. Was debating trying it internally as thin clients too We're running 2 servers (1 as gateway, 1 as a session but obviously can add more sessions if you want). Install the programs as RemoteApps and shazzam! (If only it was that easy haha) Steve
fiza Posted June 5, 2015 Posted June 5, 2015 I used this guide when I set mine up Remote Desktop Services in Windows Server 2012, Step-by-Step Guides - Concurrency, Inc. 1
Steven_Cleaver Posted June 7, 2015 Posted June 7, 2015 Just wondering if anyone is using Dual Factor Authentication with this as our LEA sort of weren't happy when we were talking about Remote Access to MIS systems so had to build Dual Factor into our own system and I know another school in the borough are using Azure for dual factor. Obviously is only a consideration and is entirely up to the school.
jmak Posted June 7, 2015 Posted June 7, 2015 Just wondering if anyone is using Dual Factor Authentication with this as our LEA sort of weren't happy when we were talking about Remote Access to MIS systems so had to build Dual Factor into our own system and I know another school in the borough are using Azure for dual factor. Obviously is only a consideration and is entirely up to the school. Our LA run a server farm and host SIMS for us. It's an RDP solution - main point of this post is to confirm that 2FA is implemented and definitely should be enforced. There's no way that the level of information held on SIMS should be accessible without 2FA.
fiza Posted June 7, 2015 Posted June 7, 2015 Our users have to authenticate to the rds server and then again to login to sims. Would that not be good enough?
richbrowncardiff Posted June 7, 2015 Posted June 7, 2015 Hi all, sorry to jump in but I'm in negotiations with our LA to do this very setup. does anyone know how it works (As in the firewall requirements can we just open up 443 for the remote apps or do we need to allow rdp as well through the firewall?) i think we may need a vpn in the loop first to add further security as sims traffic is going to be vulnerable i'd imagine??
nickbro Posted June 7, 2015 Posted June 7, 2015 With the Remote Desktop Gateway you are effectively doing an SSTP tunnel anyhow, so no real need to put a VPN in the way to slow things down further. Our two factor authentication is 1, user with SIMS rights on the AD network, and 2, separate SIMS credentials. Since the traffic is going over HTTPS it's encrypted, not only with the RDP encryption but then again with the HTTPS encryption through the RDP gateway 1
richbrowncardiff Posted June 7, 2015 Posted June 7, 2015 Thanks @nickbro i will look further into this and see what we can do to make it work without too much being opened up. The amount of change requests and back and forth may send me over the edge!
Max_Power Posted June 8, 2015 Posted June 8, 2015 We've used Citrix for quite a while here, 2010 I think we got it (Xenapp). Serious improvements have been made by the looks of it with Remote Desktop Gateway since that time and were possibly looking to make the transition. We have a high number of iPad users and the Citrix app works well for them being able to launch SIMS as an individual "app" or full desktop mode and access that way. What's the experience like for iPad users using the Remote Desktop stuff do you use the official Microsoft app from the app store? https://itunes.apple.com/gb/app/microsoft-remote-desktop/id714464092?mt=8
vikpaw Posted June 9, 2015 Posted June 9, 2015 With the Remote Desktop Gateway you are effectively doing an SSTP tunnel anyhow, so no real need to put a VPN in the way to slow things down further. Our two factor authentication is 1, user with SIMS rights on the AD network, and 2, separate SIMS credentials. Since the traffic is going over HTTPS it's encrypted, not only with the RDP encryption but then again with the HTTPS encryption through the RDP gateway Just mentioning this in case Dual Factor is forced on your as a requirement, but is there anything to stop the SIMS credentials matching the AD credentials? Even if there was, they are both the same factor in the sense it's 'something you know' and if written down or lost etc. your system is open. You'd need to add another factor like something they have e.g. phone / laptop, that it's tied down to by MAC perhaps, or via an app that provides a code. So even if the credentials were lost a malicious user couldn't gain entry. That's my understanding anyway. With regards to remote access - the other options are off the shelf products which provide remote access to SIMS, via their own interfaces which are usually much easier on the eye, though way more costly.
jmak Posted June 9, 2015 Posted June 9, 2015 ^^ This. Dual factor is something you know and something you have - not two things you know. You can do your own risk assessment as there is no law specifying what you must do, but strong guidance from the ICO is to implement dual factor authentication for the level of confidentiality of data held in SIMS.
fiza Posted June 9, 2015 Posted June 9, 2015 Just looking further into this and Microsoft Azure MFA would fit the bill but depends how much you want to pay. £.085 per authentication upto 10 authentications or £0.85 per user per month for unlimited authentications. Pricing – Multi-Factor Authentication (MFA) | Microsoft Azure
Steven_Cleaver Posted June 9, 2015 Posted June 9, 2015 Just mentioning this in case Dual Factor is forced on your as a requirement, but is there anything to stop the SIMS credentials matching the AD credentials? Even if there was, they are both the same factor in the sense it's 'something you know' and if written down or lost etc. your system is open. You'd need to add another factor like something they have e.g. phone / laptop, that it's tied down to by MAC perhaps, or via an app that provides a code. So even if the credentials were lost a malicious user couldn't gain entry. That's my understanding anyway. With regards to remote access - the other options are off the shelf products which provide remote access to SIMS, via their own interfaces which are usually much easier on the eye, though way more costly. Is the way I sort of take it so something you have and something you know, we use Encrypted App First Factor and Username and Password second Factor as our LEA were not keen on us accessing SIM's without Dual Factor although this was a few years ago now and they have mellowed a bit, but the solution they were offering was expensive.
edutech4schools Posted June 9, 2015 Posted June 9, 2015 (edited) At all my primary schools we use remote desktop with a gateway, its great for Sims etc. I use a connection profile on an encrypted USB key, they have to use a domain joined laptop that is part of the remote laptops group, the user must also be part of the remote users group and thats before they even get to any login boxes. It has been working at all my schools like this for over 4 years now and everyone loves it. EDIT - oh and the laptop must have the correct certificates or it gets refused. Edited June 9, 2015 by edutech4schools 1
vikpaw Posted June 9, 2015 Posted June 9, 2015 Insisting on school provided devices is a good way to create an easy two factor auth .
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now