supportman Posted January 24, 2022 Posted January 24, 2022 Good morning all, I've just had the pleasure of turning off RDP for the final time which has served us well but its clearly insecure in this day and age. This means as a network admin I also no longer have remote acccess. So while our teachers are now all cloud based and not an issue, what are people to have Admin access to their networks these days? Is there some good software out there that will allow screen sharing and server traversing in a secure way? I'd be interested...
Steve21 Posted January 24, 2022 Posted January 24, 2022 Good morning all, I've just had the pleasure of turning off RDP for the final time which has served us well but its clearly insecure in this day and age. This means as a network admin I also no longer have remote acccess. So while our teachers are now all cloud based and not an issue, what are people to have Admin access to their networks these days? Is there some good software out there that will allow screen sharing and server traversing in a secure way? I'd be interested... RDP behind gateway etc, nothing insecure about that side of things. We have our own one locked down to logins from us only Steve 1
Jonah Posted January 24, 2022 Posted January 24, 2022 Put it behind Azure Application Proxy if you can (licenses, etc.), then scope it to only allow your admin users and enforce MFA/conditional access if required. 1
LeMarchand Posted January 24, 2022 Posted January 24, 2022 RDP behind gateway etc, nothing insecure about that side of things. We have our own one locked down to logins from us only Is that something a thicko like me could do, and does it have MFA? I looked at Direct Access and Always On VPN, but they seemed beyond me (especially the latter and the former seems to be being deprecated). Apologies to @supportman for leaping into the thread. 1
CHiLL Posted January 24, 2022 Posted January 24, 2022 (edited) We still have RDS behind a gateway, but it's more of a last resort for access, as we also have Microsoft's Always-On VPN. The VPN allows staff to use their work issued laptops (which are also BitLockered) from home and the experience is almost exactly the same as if they were in school, with access to all their drives, SIMS, etc. Impero works perfectly well over the VPN too, so I can view and remotely control all VPN connected laptops from home or in work, even the live thumbnails work. The only issues with Impero that we have are if the service dies and Impero needs reinstalling, or the user's Internet connection is horrendous. Is that something a thicko like me could do, and does it have MFA? I looked at Direct Access and Always On VPN, but they seemed beyond me (especially the latter and the former seems to be being deprecated). Apologies to @supportman for leaping into the thread. IIRC, Always-On VPN superseded Direct Access (which was discontinued some time ago). I had absolutely no experience with VPNs when I took on that project in 2019, but I managed to spend a fair amount of time trying it (luckily it was pre-covid, so I had plenty of time to work on it as a side thing between jobs). I followed some great guides online and without them, I wouldn't have been able to do it. Edited January 24, 2022 by CHiLL
FragglePete Posted January 24, 2022 Posted January 24, 2022 Same here - RDS behind a gateway server, also incorporate Multi Factor Authentication with it as well so users need to confirm/deny any connections (requires a separate VM to be running the RADIUS server bit). Has proved very popular for those needing to work from home. Pete
jthompson Posted January 24, 2022 Posted January 24, 2022 RDS Gateway doesn't do anything in and of itself to protect against brute forcing of passwords, so if you're using that, you'll need to supplement it with some kind of MFA to make it safe. That's something the Azure App Proxy approach would allow you to do (i.e. placing the RDS Gateway behind whatever protections you already have on your 365 user accounts). I did once look at using Duo with RDS Gateway, but it seemed a bit too flimsy for me to trust it. IIRC if the Duo service were to stop on the gateway server for any reason, RDS would just be left available as normal without any MFA protection.
Jaan Posted January 24, 2022 Posted January 24, 2022 We have a Sophos XG that allows VPN for our IT admin team. Remote pcs needs the Cert and config on it to be able to connect. Then a 2 step key is required. Password is changes every min.
supportman Posted January 24, 2022 Author Posted January 24, 2022 Yeh I've seen the brute force attacks in real time on the RDP server so am happy its gone now. I don't want to bring it back, even with more security. I really am just looking for an admin only solution, all our staff have no need any more.
EssentialRug Posted January 24, 2022 Posted January 24, 2022 (edited) Yeh I've seen the brute force attacks in real time on the RDP server so am happy its gone now. I don't want to bring it back, even with more security. I really am just looking for an admin only solution, all our staff have no need any more. Would something like splashtop be a good solution for you if just looking for remote access for your IT team? Edited January 24, 2022 by EssentialRug 2
LeMarchand Posted January 24, 2022 Posted January 24, 2022 Would something like splashtop be a good solution for you if just looking for remote access for your IT team? Anyone got anything cheaper/free? Depending on the setup at the school, it's also worth getting a free trial of any solution. I tried Zoho recently and it wouldn't work with our LEA mandated setup.
supportman Posted January 31, 2022 Author Posted January 31, 2022 I tested a lot of the options and found Splashtop to be the best. I like how it works over standard web ports, It's very fast and smooth and 2 factor authentication by default. Not bad at all for £80 a year.
LeMarchand Posted March 24, 2022 Posted March 24, 2022 (edited) Had a bit of spare time, so looking at this again - about to try Splashtop as it's not a bad price. Has anyone tried DWService which I've just tested and works through our filter and can have 2FA, but does seem a bit of a one-man band and lacking in the sort of net chatter that makes you feel confident. (Not that there's anything to make you feel the other way). Or just using Chrome Remote Desktop? Edited March 24, 2022 by LeMarchand
Andycat Posted March 24, 2022 Posted March 24, 2022 Had a bit of spare time, so looking at this again - about to try Splashtop as it's not a bad price. Has anyone tried DWService which I've just tested and works through our filter and can have 2FA, but does seem a bit of a one-man band and lacking in the sort of net chatter that makes you feel confident,. (Not that there's anything to make you feel the other way). Or just using Chrome Remote Desktop? I use DW Service in general for pals but also to my work machine if I need remote access. 1
rogerdnixon Posted March 24, 2022 Posted March 24, 2022 We use Chrome Remote Desktop - works well and Pulseway on important stuff we want to monitor. 1
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now