Re: Access to network drives for home and roaming users



Mike,
All the VPN does is to add a security layer to the remote access, so if you
don't want to use VPN, the question is, what security do you want to apply?
Then by the time you add the additional security, you may be thinking that
the VPN wasn't so bad.
Questions:
- Do you want the data in a DMZ, or do you want them to come straight
through the firewall to your LAN?
- If in a DMZ, how will they authenticate to it?
- How to interact with the data: HTTP, CIFS, FTP etc.?
Options you can consider:
1) An SSL VPN gives a simplified user access to internal resource. From a
user perspective, you could say they had direct access, as they only have to
authenticate once. In fact they are going through a VPN tunnel.
2) Allow RDP straight through. Impractical in any but very small
environments.
3) Use Terminal Services with remote access. For file access as distinct
from applications this is similar to the SSL VPN.
4) Anything with the content in a DMZ gets very complicated as to how you
are going to authenticate it with LAN users. You can use IIS with WebDAV and
SSL to give file and folder access, but you need some way to authenticate
the users. You don't want to go through to the DC on the LAN, so you have to
come up with a way of synchronizing usernames to a DMZ AD.
Hope that helps,
Anthony
http://www.airdesk.co.uk




"Mike D" <MikeD@xxxxxxxxxxxxxxxxxxxxxxxxx> wrote in message
news:6471DDBA-BA31-460B-98FF-1D5B40E15F8B@xxxxxxxxxxxxxxxx
Hello, I have a scenario I'd like to put out and see if anyone can help. I
have a windows 2003 R2 network with an internal and perimeter network, the
internal is fully windows 2003 and all users have access to mapped drives
on
the file server, we also have exchange 2007 server. In the perimeter
network
we have a frontend webserver hosting a public site and another box hosting
the edge exchange 2007 server.

I want to achieve simple remote access to user from home or roaming with
laptops without the need for VPN's, Exchange is easy and has been setup
for
OWA or the outlook client over HTTP, the problem I have is access to the
file
system and specifically the network drives they have access to. I'd like
to
give them access to certain network drives or folders somehow without
mapping
them over a VPN. I've thought about ftp etc but I figure there must be
plenty
of need for this out there and other companies must have easily achieved
it
with it being pretty much a microsoft shop....... so I want to see how
others
do it :) can anyone assist or provide advice.

Thanks




.



Relevant Pages

  • Re: Cant logon 2003 SBS domain
    ... Networking, Internet, Routing, VPN Troubleshooting on ... How to Setup Windows, Network, VPN & Remote Access on ... netdiag takes 5 minutes to get the results; network mapping take long to map. ...
    (microsoft.public.windows.server.sbs)
  • Re: VPN cant access internet whilst connected to VPN
    ... >>> The proper method should be to ask the Firewall people at your office ... >>> allow outbound HTTP access for VPN users. ... > But allowing access to the local home network is more of a security risk ...
    (microsoft.public.windowsxp.general)
  • RE: VPNs - Firewalls and Security
    ... we turned off sysopt connection permit ipsec and then added the ... VPN connections. ... VPN's - Firewall's and Security ... You had configured that vpn users access internal network, ...
    (Security-Basics)
  • Re: VPN file access
    ... which is set by the router VPN configuration i think. ... server name or FQDN name. ... E-mail\Configure Remote Access, and select VPN access in the Remote Access ... 0x2F if you are looking in Network Monitor). ...
    (microsoft.public.windows.server.sbs)
  • Re: [Full-disclosure] Remote Desktop Command Fixation Attacks
    ... This set of steps is redundant in many places, and it's also enormously expensive, since you're using no less than three different expensive bits of networking hardware (AP, PIX, VPN Concentrator), in addition to a bunch of x86 server hardware, windows server licenses, and at least one ISA license. ... Your computers necessarily don't have full access to your network infrastructure when they aren't logged on, so GPOs, software updates, etc can't be applied at the times you want them to be applied. ... Turning on, enabling, and implementing every possible security setting and device you think of is not defence in depth, and will probably only have two effects - your users won't use your wireless network, and you'll burn so much cash you won't have any left to spend on *useful* security measures. ...
    (Full-Disclosure)

Loading