Jump to content

Recommended Posts

Posted

I'm looking at allowing VPN access for a select few users but admittedly I know nothing about them (not something i've never needed to use), i've read a few tutorials but just need a few pointers.

we have a 2008r2 domain, and schoolguardian is our firewall.

 

Do I use the vpn service on the firewall or do I set up the network policy and access service role on the server?

Posted
Nope not sure, it's for SLT and they were asking about accessing their files from home - I suggested cloud storage but not sure which is the best option for them.
Posted

with a VPN you are simply adding their machine to the network and exposing the network to any nasties they may have. This is the big thing to be aware of.

 

 

Have a look at HAP ( home access plus ) , which is free and may do just what you need. I have not tried it yet but many here have.

 

Rob

  • Thanks 1
Posted

forgot to mention, we've supplied them with school laptops - so they are domain machines.

Thanks for the suggestion - i'll have a look at it.

Posted
You should be able to setup Routing and Remote Access on your server 2008 DC. You can then setup PPTP or SSL VPN's straight to your server. and then the machines act like they are on the network.
Posted
with a VPN you are simply adding their machine to the network and exposing the network to any nasties they may have. This is the big thing to be aware of.

 

 

Have a look at HAP ( home access plus ) , which is free and may do just what you need. I have not tried it yet but many here have.

 

Rob

 

2 years and no issues with any 'nasties' on our network through the VPN from no domain joined PCs- no doubt thanks to the built in endpoint checker of UAG 2010....

 

Having said this the largest number of our users are using domain joined (and managed PCs) when connecting to our VPN.

 

For basic use just routing and remote access in Server 2008 R2 will fill your needs if you are after more features (and so called security) then look into something like Forefront UAG.

 

We've just finished work on setting up Microsoft Direct Access 2012 and will be doing the final testing in a few days time - if it works as well as expected then its seamless access to the schools network without even needing to choose to connect to something.

 

If done right a VPN is a very powerful tool that you should consider rolling out to all staff members.

Posted

Thanks everyone,

We've not had much call for it as we have so few laptops, it's hardly worth setting up for what we have but we got asked the question on how to access their files etc.

I've not touched remote access since the NT4 days and RAS.

VPN seems easy enough to set up, set up the role and open up some ports it seems, not got a lot on over half term so might give it a go.

I like the sound of direct access, but overkill to set up for our needs (for now)

Posted

Direct Access in Server 2012 is almost as easy as setting up a VPN (well at least I realise it is now after spending half a day getting it sorted) it can be used side by side with a VPN.

 

Look for a SSTP VPN as well - just needs port 443 and if you are a school you can get a free security cert from JANET through your LEA.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...