Jump to content

Recommended Posts

Posted

Hi

 

We are having Windows 2012 RDWeb server in our network. Our staff use RDWeb Access https://desktop.myorg.co.uk/RDWEB on the school laptop to connect to our RDWeb server and access SIMS and shared drives.

 

I am planning to implement VPN and force staff to use to connect to RDWeb server through VPN.

 

Please can you let me know any VPN that you are using and how staff connect to the school systems from home.

 

Thanks and any help much appreciated.

  • Thanks 1
Posted

Can I ask the thinking behind this? The Remote Desktop Gateway that you're talking about here is designed to be exposed to the internet; the whole idea behind it is to just open port 443 to the internet and use that to publish remote desktop servers. What purpose does putting that behind a VPN serve?

 

If you're really married to the idea, I'd suggest looking at Always On VPN which is built into Windows. The process is then completely transparent to the user, they are automatically connected to the VPN as soon as they connected to the internet.

Posted

The Windows Always on VPN is pretty good, and is completely transparent to the user. NCSC have some recommendations on VPN security - https://www.ncsc.gov.uk/collection/end-user-device-security/eud-overview/vpns.

I’ve found the guides from Richard Hicks to be generally good in terms of setting it up on the client - https://directaccess.richardhicks.com/

 

If you’re creating a setup from scratch, and want security baked in, then the NCSC walled garden architecture provides protocol breaks between user devices and internal systems, so if anybody got into the VPN, they still wouldn’t be able to go very far. There’s some guidance on that at https://www.ncsc.gov.uk/collection/mobile-device-guidance/infrastructure/network-architectures-for-remote-access

Posted
I would certainly question putting RDWeb traffic inside a VPN, you're more or less effectively putting a VPN in a VPN at that point. I mean you do you and all that but it will probably just slow things down without providing a tangible security improvement. If you're concerned about better securing the RDP gateway I'd be ensuring it was protected with MFA.
Posted

We have moved to 0365 and azure in place .

 

Also we have setup MFA for 0365 and all working good, whenever staff login into 0365 OWA outside our network , it sends a approval request to the Microsoft authenticator app on their smart phones and once approved it logs them to 0365.

 

With Azure in place, do i need additional licence to setup MFA for RD Web Access ?

Would be great - any tutorials to setup MFA specific to RD Web access .

 

Many thanks

Posted
There's also DUO, which offers similar functionality; but if you're already using Azure, then Azure MFA is likely to be the cheapest solution and the easiest one to implement.
  • 1 month later...
  • 6 months later...
Posted
I've done the same setup just recently for staff but they get a TLC error when connecting at home. If they connect to their mobile hotspot they can get to the page no problem. Any ideas for a fix?
Posted

I've found issues with Sky where you need to allow the VPN Server through the filtering.

 

Had a case with Virgin doing DNS Hikacking when try to resolve internal resources so had to turn that off.

 

I really wish residental ISPs would stop adding things that get in the way. Particularly at the moment where the is a lot of people WFH.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...