Managing remote users

News Analysis
Oct 3, 20055 mins

IT administrators agree that centralized servers and thin clients ease the task of supporting off-site employees.

Data center consolidation appears to be an ever-increasing strategy for managing remote users, IT managers say, as concerns for data security, reliability and availability of assets continue to pervade enterprise networks.

Data center consolidation appears to be an ever-increasing strategy for managing remote users, IT managers say, as concerns for data security , reliability and availability of assets continue to pervade enterprise networks.

Among those managing remote users from a central location is Wade Phillips, director of technology for the Shakopee School District in Minnesota.

“We do this for a single point of administration and economies of scale,” Phillips says. “We have a Fibre-Channel -based infrastructure so it made sense to pull back all of our services to a central location.”

Phillips manages remote students, teachers and staff using Citrix MetaFrame. Those users log on to a Citrix thin client to access their applications.

“We allow teachers, students and staff to connect remotely and access published applications from virtually any Internet-connected device,” he says. “We are supporting up to 200 concurrent connections as of today and only expect to grow.”

In this fashion, because users are connecting to centralized servers, it is easy for Phillips to back up the network with conventional tools. He uses Microsoft’s Volume Shadow Copy Services for recent document recoveries and data backups on the servers to restore anything that a user cannot get back.

Hospital keeps data server-based

Mark Moroses, senior director technical services/security officer at Maimonides Medical Center in New York, takes a slightly more complicated approach to centralized management.

He has two types of users: clinical and administrative. While administrative workers generally check e-mail and retrieve an occasional file from Maimonides’ network, clinical workers access applications and medical records for 98% of their needs.

“By design and policy, no data is stored remotely,” Moroses says. “Clinical application data is only server-based. Mail storage is server-based. Generic file storage is only backed up if it is located on a network file server.”

Unlike Phillips, Moroses supports user workstations and laptops. Users connect remotely to Maimonides’ network via thin clients.

“The only thick client we support is the teleradiology workstation, for which we will actually still have to send a technician to their homes if necessary,” Moroses says. “Laptops are brought to us, for remediation and redeployment.”

And Moroses solves configuration and application issues with remote tools, such as WebEx Support Center, IBM Director or Symantec’s OnCommand remote control.

Centrally installed anti-virus software protects remote laptops and workstations from worms and spyware. Cisco IPSec and SSL software handles authentication of users to the network. “We use IPSec for site-to-site connectivity, and SSL is preferred for remote users,” Moroses says.

Credit Union centralizes management

Tom Gonzales, senior network administrator for the Colorado State Employees Credit Union in Denver, uses a VPN to protect his network from unauthorized remote users. He uses Altiris ‘ Client Management Suite to protect the remote users’ workstations and laptops.

“Altiris allows for scheduled imaging of the hard drive both to a hidden partition on the laptop and to a network share,” Gonzales says. “We generally, reimage to a last known good state. We don’t spend too much time troubleshooting problems.”

Like Moroses and Phillips, Gonzales centralizes management of remote users for cost, reliability and survivability. He also uses anti-virus software that automatically updates those workstations and servers.

Except for Moroses, none of these users has incorporated continuous data protection (CDP) products or wide-area file services (WAFS) into their environments.

Moroses is looking to beta test Revivio’s Continuous Protection Server, an appliance that backs up data continuously and allows the recovery of data from any point in time.

College rejects WAFs

Ken Weaverling, director of systems administration for Delaware Technical and Community College in Wilmington, Del., looked at WAFS technology, but rejected it because of its expense. Weaverling, like Phillips, uses a terminal server environment to connect his remote users with the network at the college.

Bernie Lubitz, director of telecom technology and services for Martin Memorial Health Systems in Stuart, Fla., tells much the same story. He has looked at WAFS, but says that until the bandwidth on his WAN is unsuitable, he doesn’t need it. Lubitz has an IPSec VPN from Juniper and an SSL VPN for more telecommuters. Like Gonzales, he uses Altiris to for workstation control.

“Centralization has proven to be more easily secured and supported,” Lubitz says.

Lubitz supports non-employed physician offices, vendors, and more than 30 member physician offices. He has 100 VPN appliance-based sites, 200 casual users and 35 legacy sites.

All Lubitz’s sites are backed up to host-based systems. Users are supported with Altiris software.

It appears that all these users have settled on a handful of vendors for managing their remote users. Cisco and Juniper for VPNs; Altiris for workstation management; Cisco for WAFS (the company acquired WAFS start-up Actona Networks) and Revivio for CDP.

Whether these new technologies, WAFS and CDP, will take off in managing remote offices and users is still too early to see. But it appears that the rest have adopted the same “gold standard” for tying their users to their networked data center.

Strategy-building suggestionsTips for setting up and managing remote users.
  • Identify remote users. Are they individual, remote networks or both?
  • Determine how you will connect mobile users, telecommuters and users in branch offices.
  • Decide how users will connect to the network as a thin-client, a Web-based application or in a client/server approach?
  • Determine how you will support that user and what remote access software you will use.
  • Establish back-up policies for remote users.
  • Set up security and authentication for remote users with firewalls and VPNs. Enable IPSec and/or SSL encryption.