Jump to content

Recommended Posts

Posted

I am looking at the possibility of setting up a VPN so teachers can access files from home. Any idea's of cost and how easy it is to set up? Its not something I've thought of to be honest.

 

Anything to look out for? Any advise?

 

Thanks!

Posted
VPN would mean you would need to encrypt all the laptops (whatever the staff use), I would go for terminal server, Windows 2008 comes with HTTPS support.
Posted

We haven't got 2008. We're still on Server 2003 r2.

They want to access files, and sims from home. I'm not sure how it all works to be honest. :o

Posted (edited)

Secure Communications, Secure Networking, Secure Application Access, SSL VPN, High Assurance IPSec VPN Encryptor, Hardware Security Modules, HSM, Terminal Services, Windows Remote Access, Public Key Infrastructure, Identity Based Access Control, IBAC

 

There is a free version, basically it's the same sort of idea as is built into W2K8, but it's Java based rather then .net.

 

Might be worth looking at getting 1 w2k8 server, then setting it up with ts gateway with HTTPS.

 

Sorry I can't remember the free version url, I know it's on sourceforge.

 

The problem with VPN is that you'll have to support staff home pc etc with office, sims etc, then you've got the whole security thing, where hdd must be encrypted. Personally, go for the "thin client" idea. David Hicks I think might be able to help more, I know he (and someone else) was looking at having SIMS on a terminal server (then remoting into it).

Edited by matt40k
Posted
Why does providing a vpn for external use mean the need to encrypt the laptops?

 

Ben

 

Because having access to files on laptops which are unencrypted is a breach of the data protection rules that we're supposed to be following now.

Posted
but if the files were on a drive located in the school that was accessed through the VPN...?

 

If you just work on that remote drive, then you should be fine, so long as nothing is copied to the local machine.

Posted

just because you have access via a vpn doesn't mean the laptops have to be encrypted.

 

According to the BECTA guidelines laptops containing sensitive information should be encrypted, also there are no deadlines as far as I can see on when encryption should be implemented.

 

That will be next I am sure.

 

VPN or thin client access allows the same access to info.

 

VPN probably requires an additional login process or maybe 2 factor authentication.

 

Ben

Posted

Thin client will have zero files other then maybe a few dll.

 

VPN, for sims, will have your a number of files around your local machine. Capita won't recommend this.

 

Basically look in: My SIMS Documents

 

Also, if I run a report, that say, exports all the students details to my C Drive, you've just breached the Data Protection Act if your local hdd isn't encrypted.

  • Thanks 1
Posted
just because you have access via a vpn doesn't mean the laptops have to be encrypted.

 

According to the BECTA guidelines laptops containing sensitive information should be encrypted

 

You just contradicted yourself... The majority of files that will be accessed remotely would be data regarding children. Sure, some will be lesson plans and the like but as the other type is likely to be accessed, your laptops should be encrypted if you intend to copy files from a VPN to it.

 

But as I said, if you're just opening the files remotely, and not actually copying them across, then that necessity is removed.

Posted

Hi

 

I am in the same boat as you are sippo :) I believe Sims Capita learning gateway sounds like what we need to protect Sims data... Have a chat with your Sims Manager about this software!!! Plus before 2010 you will need a portal so students and there parents can access schools data from home...

 

Hope this helps... :D

Posted

I didn't contradict myself I just kept typing while thinking :)

 

As I said just because you have vpn access doesn't mena you need to encrypt.

 

If you copy files to the laptop over the vpn then yes.

 

Allthough I'll contradict myself again now because as we all know the moment you turn a computer/laptop off the memory doesn't immediately clear but takes time, this means an attack can be leveraged against the memoery if you have physical access.

 

Therefore you could say that becuase it's been opened it's available from the memory.

 

This is also an attack vector against truecrypt.

 

Ben

Posted

Just use Windows Server VPN (Routing and Remote Access).

 

I set this up for the teachers and works great, give them some insturctions on how to use it from home.

 

(Adobe Captivate CS4 Videos)

 

Ian. ;)

Posted (edited)

If you have money to spend on this I can highly recommend Juniper Networks Secure Access SSL line..

 

:) We use Terminal Services (with Sims on and loads of other things) and also give access to web based stuff like OWA, intranet etc. Home directories and other mapped drives are accessible through the browser so you can download and upload files from home. Some other features are host/ endpoint checks for AV / Firewall etc and you can do custom checks on registry / files - if a machine falls out of policy the system can put it right by forcing upgrade of definition files etc - you can also tie in two factor authentication if you use it.

Edited by ssiruuk2

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...