Re: Security when students log in from home



Then you need to make sure your servers are properly secured using best
practices in that only the right users are local/domain administrators, that
those users are using strong passwords, that only the right groups have
access to shares on the servers if there are any shares, review of security
logs, non needed services are disabled, keeping current with critical
updates, etc. Also with a VPN you can strictly manage where a user can go
when logged onto via VPN, For instance with Windows 2003 Server you can have
a remote access policy that restricts users from accessing the IPs of
servers or other sensitive computers if you want.

Steve


"Paul" <g6yak@xxxxxxxxxxxxxxxx> wrote in message
news:ljrvq29vs8br71h7raalfvdvqcktpbnrll@xxxxxxxxxx
Thanks for the reply, most of the security we have relies on them using
our machines that are locked down
they can't download and use hacking tools etc. What we are more worried
about is that on their own machines they are the
administrator and can download all manner of tools. They might then be
tempted to try them against the net work after hours
when they have time on their hands and a valid log on, as I would at that
age.
Thanks
Paul

On Wed, 17 Jan 2007 19:34:02 -0600, "Steven L Umbach"
<n9rou@xxxxxxxxxxxxxxxxxxxxxxxxxx> wrote:

A remote control solution is probably the best and will perform the best.
You might try something different from what you are now using and there
are
free versions of some such as VNC and other variations of VNC. XP Pro
Remote
Desktop is also very good. Whatever you choose your security should be
configured so that it is not possible for students to access servers they
have no business being on. You can use a variety of ways including ipsec
[an
advanced topic], share permissions that use the principle of least
privilege, strictly managing privileged local and domain groups, and
managing user rights so that users do not have the logon locally or access
this computer from the network user rights for servers they should not
access however users need access this computer from the network for domain
controllers.

Steve

http://en.wikipedia.org/wiki/VNC

"Paul" <g6yak@xxxxxxxxxxxxxxxx> wrote in message
news:q97tq29uld2vp9c22ms726m6r39huj7r0u@xxxxxxxxxx
We are an 11 to 18 school and want the students to be able to log in and
work from home.
We have a thin client system that will do the job, but won't give them
all
of the programs they need as some will not work
over a thin client system. As far as we can see, the best way if finance
would allow is for each student to have a school
owned laptop that we manage so that it can be locked down and then let
them log on to our VPN.
As we haven't the funding for this, is there any way to let them log on
to
the VPN with their own machines, but still
restrict what they can actually do, for example stop them from running
hacking or password changing utils against our
servers?

Thanks
Paul




.



Relevant Pages

  • Re: Site to Site VPN 2 SBS servers
    ... site to site VPN. ... Microsoft CSS Online Newsgroup Support ... This newsgroup only focuses on SBS technical issues. ... | Subject: Re: Site to Site VPN 2 SBS servers ...
    (microsoft.public.windows.server.sbs)
  • Re: Change of IP for Servers
    ... Static device like printers will need to have their gateway's ... All servers ... We have an ISP who is providing internet and VPN access. ...
    (microsoft.public.win2000.networking)
  • Re: They are coming back from holdays
    ... If they violate company policy then it's unethical, ... there are commercial public VPN services that encourage ... IT admin here try and crack and sniff a 256 bit encryption scheme. ... I did see a lot of connections coming through this company's servers ...
    (comp.security.firewalls)
  • Re: Site to Site VPN w/DHCP
    ... do this natively with some PIXs: ... I'm working on getting the VPN going but just having one problem. ... and download "Servers Alive." ... one site in USA one in China. ...
    (comp.dcom.vpn)
  • RE: Connecting to Windows servers through adsl
    ... join your computer into domain after the VPN connection is established. ... | which connect to internet through adsl line from home. ... | servers with their internal ip's and machine names. ... | to see any server's shares, he gets a logon window ...
    (microsoft.public.win2000.security)

Quantcast