Nutter helps a reader who’s setting up remote access for his users
We are starting to get more requests from staff and management for remote access to our network. Some are using DSL, others cable modems and the rest dial up. Until recently, we only had a few requests for remote access, but the number has been growing. We’re trying to juggle these requests while protecting our network at the same time. Any suggestions?
– Via the Internet
Let’s start at the remote end and work our way back to your network. For those users who have broadband access, you will probably want to mandate some type of hardware firewall be used (one you can remotely manage and potentially upgrade). This will mean that management will have to buy off on this because of the potential cost involved. If your company is supplying the computer used at home, some of what we next need to think about will be easier since your company will own the equipment. For non-broadband users, think about a software firewall such as ZoneAlarm or other equivalent product. They need to have some type of protection on their end.
Anti-virus software should be installed on the remote computer. I would strongly suggest that the ability to change configuration or uninstall the software be password-protected if the software you’re using allows it. Look at the frequency of updates and see how often you need to schedule the remote computers to check for virus signature updates. I would suggest having the computers check daily.
Examine exactly what your users need from your network when they’re remote. You’ll need to think about how to support users remotely if the VPN client stops working and what it may take to get things running again. This is one area in which SSL-based VPNs may be easier because there is no software to install or maintain on the remote desktop. If you elect to go with a “conventional” VPN connection you’ll have to install client software. If you go with the later, you may want to talk to management about a policy that forbids users from installing any software on a computer that is accessing the company network unless IT is involved. I have run across some situations in which installing an application has caused the VPN client to stop working. This policy also helps in some other areas, such as license compliance. You can take extra steps to make sure that only properly purchased and license software is installed on computers that access your network. Depending on the type of firewall you purchase for remote users, you might want to consider the option of having VPN tunnels and enable split tunneling. In this scenario, only requests for your servers come over the VPN and all other requests go out locally at the remote user’s end.
You may also want to require that only company-owned computers access the network. That way you don’t have to worry about what applications or other installed items could cause a problem that you’d have to support. One other thing that should be added to the remote users’ policy: Users need to take some responsibility in having the latest Windows patches installed, unless you’re considering something like SUS or another product that can push out the patches. What I have outlined here are the basics of what you will need to think about. The more variables you can eliminate, the easier things should be to support.




