I've been working with Microsoft UAG since it's been available. I had a head start as I was using and deploying IAG and Whale previously, which were the two predecessors to UAG.
I've published a few different applications, but a majority of the solutions will include Microsoft Exchange (whether it's OWA, full Outlook and/or ActiveSync), RDP connections (usually for administrators to access servers or to Terminal Servers), and some sort of Intranet or SharePoint site. Some of the rarer occasions I've been asked to give terminal access to AS/400 solutions, publish VMware View, deliver the Neocoretech VDI solution using HTML 5 clients on iPads, etc, etc.
So when I was asked to deploy Lync 2010, I was pretty confident it would be straightforward. I did some research to ensure I was following best practise, but ended up using a few documents to achieve a fully working solution. Please note I wasn't doing this blind as I had deployed Lync in our office, but could make it work with UAG without real certificates (as is highlighted in the following instructions)
I was deploying an SSL-VPN portal as well as creating a Lync connection for the computers, which meant I modified some of the configurations given.
The first document I used was this one:
http://social.technet.microsoft.com/wiki/contents/articles/14000.publish-lync-2010-with-forefront-unified-access-gateway-2010-uag.aspx
Ensure you have all the domain names for the various Lync components, but I used a different document for this.
As ever, I was deploying a Celestix WSA solution, which was straightforward. I followed Georg Thomas' instructions, but did not follow the section on the "Additional Trunk Configuration" as this would impact my SSL-VPN portal. I did create the registry key as described, but also follow Erez Ben Ari's blog here with the additional registry key: http://blogs.technet.com/b/edgeaccessblog/archive/2012/06/15/lync-publishing-on-uag.aspx
I would typically use wildcard certificates, but as these do not work with Lync on UAG, we has to use a SAN (Subject Alternate Name) certificate. As I have never done this before, I followed these comprehensive instructions: http://technet.microsoft.com/en-us/library/gg429704.aspx The request of the certificate from the provider is the same as a "normal" or wildcard certificate, as is the installation.
Thanks the well written documents abover, the publishing of Lync 2010 was straightforward.
Saturday, 18 May 2013
Friday, 3 May 2013
Backups, a necessary evil?
It may be unfair of me to compare backups to car insurance, but here goes!
Looking at the agents and application support, some specialise with virtualised environments, some only with Windows servers, some have limited integration agents and therefore struggle to back up vital servers within your network.
Some have the ability to create bare metal backups in case of a disaster, but they can only restored on similar hardware. Most people will struggle to find similar hardware, once it's over a year old, as the manufacturers are continuing to release new hardware.
Then there's the media it will back up to, some will only go to tape, disk, SAN, NAS, removable media, to the internet (cloud), or to a private network/cloud, but again some will only give limited choices.
We at e92plus, currently work with Unitrends, who can offer the following:
The pricing is very competitive as well, but you probably won't believe it until you try it, so have a look here to download your Free Edition, which will allow you to protect four virtual machines, forever, for free!
- We all know we need it, but not everyone has it.
- We buy it, hoping to never have to use it.
- We never know how effective it is until we have to use it.
- We ignore the extra offerings, believing we can get it cheaper elsewhere.
- Most people will buy on price, rather than looking at what it covers.
Looking at the agents and application support, some specialise with virtualised environments, some only with Windows servers, some have limited integration agents and therefore struggle to back up vital servers within your network.
Some have the ability to create bare metal backups in case of a disaster, but they can only restored on similar hardware. Most people will struggle to find similar hardware, once it's over a year old, as the manufacturers are continuing to release new hardware.
Then there's the media it will back up to, some will only go to tape, disk, SAN, NAS, removable media, to the internet (cloud), or to a private network/cloud, but again some will only give limited choices.
We at e92plus, currently work with Unitrends, who can offer the following:
- Choice of platform, supporting either a backup appliance or a virtual appliance for either Microsoft Hyper-V or VMware vSphere.
- Backup a variety of operating systems, including Microsoft Windows, Linus, Apple Mac OS X, AIX and Solaris.
- Integrates with Microsoft Hyper-V and VMware virtualisation environments, including instant recovery for VMware.
- The ability to archive to Disk, tape, NAS and SAN.
- The ability to replicate to another appliance, to another virtual appliance, to the Unitrends Cloud, or to a private cloud (hosted by either you or a trusted partner/supplier).
- Utilising compression and de-duplication technologies to the reduce the size of the backups.
- The ability to create bare metal backups, and restore to dissimilar hardware.
The pricing is very competitive as well, but you probably won't believe it until you try it, so have a look here to download your Free Edition, which will allow you to protect four virtual machines, forever, for free!
Wednesday, 1 May 2013
Shoulder Surfing...
Working in IT security, I understand and advocate the importance of PINs and passwords, as well as explaining why they shouldn't be shared. My 8 year old and 6 year old have computer lessons at school from which they understand the importance of keeping passwords secret.
On our home PC, I've created profiles for them where they insisted on having passwords and even I as the administrator/father don't know their passwords. It makes me proud when I try and trick the password out of the them, that they won't tell me.
Imagine my surprise when my wife recounts her day, where my 2 year old son was happily playing on the iPad and listening to iTunes. I tell my wife that my iPad is PIN protected! I've been "shoulder surfed" by my two year old son!
Not a major problem as I don't keep important information on it, but he can play Angry Birds whenever he wants (and pretty much does)...
On our home PC, I've created profiles for them where they insisted on having passwords and even I as the administrator/father don't know their passwords. It makes me proud when I try and trick the password out of the them, that they won't tell me.
Imagine my surprise when my wife recounts her day, where my 2 year old son was happily playing on the iPad and listening to iTunes. I tell my wife that my iPad is PIN protected! I've been "shoulder surfed" by my two year old son!
Not a major problem as I don't keep important information on it, but he can play Angry Birds whenever he wants (and pretty much does)...
What if this was a work environment, it would not be acceptable if this had happened. In fact, I would suspect someone would get either a verbal or written warning for such a security lapse. Maybe I have a certain amount of paranoia, but I don't check my email on my mobile when there are people close enough to shoulder surf me. Not that I have anything that private or personal, but I don't know what's in that email until I open it.
The facts around visual security are pretty much as you expect:
- 80% chance that you've already become a victim of others reading over your shoulder
- £1.9 million is the average cost to businesses per incident of physical data theft
- 96% of data breaches in 2010 were avoidable
- 52% of laptop users in the UK are ignoring visual security issues
- 67% of working professionals surveys in the US had worked on some type of sensitive data outside of the office.
Visual security of on-screen data can be a key part of the implementation of ISO 27001. So if you excuse the reflection, you can see both my laptop and desktop screen when looking at them head on.
Here is my screen from an angle and slightly above to give the view of a shoulder surfer, you can see my 3M privacy filters working their magic.
When the view angle exceeds 30 degrees, the screen is protected. You can also see a notch in the top right allowing these to be removed to give the normal visibility back.
e92plus have started distributing the 3M privacy filters and free samples can be requested from here: http://www.securityplusonline.co.uk/3m
Monday, 16 July 2012
Privilege Management… What is it and do I really need it?
If any of
you reading this use Windows 7 on your laptop and computer, or you administer a
number of Windows 7 machines, you will be all too familiar with the User Access
Control (UAC) prompt. You will know the
frustration as user being unable to update your computer, even though you know
it’s the right thing to do, but as an administrator you need to lock down the
UAC, as you can’t have users installing untrusted pieces of software.
We see that the users need the flexibility to be able to do their job, while the administrator has the security of the IT systems in mind.
What’s the fix?
In most organisations, there is an IT team who have to enter in administrative credentials when required. This may be workable or acceptable in a small organisation, but in larger organisations more members are required in the IT team. Even in our organisation with 35 people, it can consume a lot of time form the internal support team, especially when there are Adobe or Java updates for instance.
We see that the users need the flexibility to be able to do their job, while the administrator has the security of the IT systems in mind.
What’s the fix?
In most organisations, there is an IT team who have to enter in administrative credentials when required. This may be workable or acceptable in a small organisation, but in larger organisations more members are required in the IT team. Even in our organisation with 35 people, it can consume a lot of time form the internal support team, especially when there are Adobe or Java updates for instance.
A better
solution?
The Viewfinity
Management solution, will offer the following functions:
- Elevate privileges – allowing certain processes or applications to automatically have their administrative rights elevated.
- Block/White listing – allowing specific software to blocked or allowed to run.
- Policy Automation and On Demand Elevation – allowing ad-hoc self-elevation for power users and allowing end users to have specific policy workflow applied.
- End User Experience – allowing customised messages, keeping the user experience more in line with company policy.
- Remote Workforce – allowing policies to propagate to home works, remote office or frequent travellers.
- Compliance Reports – gives reports on all users, including full audit trials for compliance validation, with dedicated reports for SOX, PCI DSS, HIPAA, and other industry mandates.
Do I really need
it?
If you don’t
want to employ a team to manually enter in credentials or maximise your support
team in other activities, then any Windows domain with Windows 7 computers
needs a solution like Viewfinity.
Here is a
recent review from SC Magazine: http://www.scmagazine.com/viewfinity-privilege-management/review/3675/
e92plus are
the sole distributor for Viewfinity in the UK.Wednesday, 18 April 2012
Using my iPad for work!
After much
pressure from the MD and Marketing Manager, and now also having my own iPad, I
decided to investigate iPad access to our network.
My first
port of call was configuring a server to run Neocoretech, which is a VDI
solution that does not require a SAN or massively complicated infrastructure prior
installing (unlike some of the alternative solutions). With the Neocoretech server running and
configured on our network, I had to build a Windows 7 image. The image I created was a “read only “image,
so that the user cannot change the image.
Some minor configuration was carried out to make the virtual machine a
member of the domain, as well restricting some functions of the operating
system in order to improve performance.
Testing was
carried out from a laptop to ensure the VDI infrastructure was working, before
connecting my iPad to the wireless network and browsing the VDI landing
page. I had to install a free RDP client
onto my iPad, and I chose Remote Desktop – Universal App by Evolve Networks, as
these gave me the option to create more than one RDP session unlike the Wyse
free application.
On network,
it gave me a very good user experience, where the Windows 7 desktop was useable
on the iPad. The only gripe I had was
that scroll bars were a pain, and where you would expect to press and drag them,
you had to click to jump to the scroll bar on.
My next challenge
was getting this to work remotely. As
you can see from other posts, we use Microsoft UAG hosted on a Celestix
appliance as our remote access, but this solution does not offer an iOS client
to allow the iPad to fully integrate with the features of the UAG, so I am
unable to use the UAG to give me VDI access on the iPad.
As an
alternative, I configured a Cyberoam UTM appliance to give me an L2TP VPN. Following these instructions provided from
Cyberoam will give the right result: http://kb.cyberoam.com/default.asp?id=1891
As did not
have alternative route out to the internet, I create a hotspot on my iPhone,
and used Bluetooth to connect my iPad to the hotspot. Using 3G, I connected my iPad to the L2TP
VPN, and from there started up my RDP client, and connected to my VDI
server. I was surprised as the latency
was not as bad as I had expected, but it gave me my Windows 7 desktop on my
iPad via the 3G network!
Very
impressed how quickly this was configured and running, but now I need to
customise my Windows 7 VDI image to optimise it for our network.
iOS and Android in the workplace (aka Replacing your computer with an iPad/Android Tablet?)
With iOS and
Android becoming more popular in the home environment, I am often asked how
these devices can be used as the endpoint to connect to a work network. I would like to separate the use of these
devices as a work device, rather using them as an access point for the occasional
remote access session.
Irrespective
of whether the tablet or mobile is a company or personal device, the issue with
connecting it to your network is software support, so we have to look at what
applications are required in the workplace.
With email, most mobile and tablet devices will support Exchange, and
most of these devices will have the ability to create, read and edit Microsoft
Office documents. There may be some
issues with legacy applications, or Windows only applications, which would
render the device useless for those applications.
I’ve read in
some places, where the solution is the replace the applications with something
that will work on these mobile devices, or on other computer operating
systems. This seems a little bit
extreme, especially in the current economic climate, where IT budgets are being
cut and hardware refresh rates being increased from three years to up to five
years. Embracing BYOD (Bring Your Own
Device) will also bring the same challenges, as the organisation may save
hardware costs in not having to purchase and maintain devices, but will have to
alter the backend infrastructure to support these new devices.
I’ve always
liked the concept of VDI (Virtual Desktop Infrastructure) but in the past, it
has been both complicated and expensive.
There are now solutions which can give you a virtual desktop for less
than the cost of a new PC. By
manipulating budgets, it would be possible to deploy a VDI solution, instead of
carrying out a hardware refresh of the desktop/laptop infrastructure. The VDI solution would be able to create a
Windows desktop environment that can run on any endpoint that supports RDP
(Remote Desktop Protocol). This would
enable the old hardware, the mobile devices, the tablets, the BYOD equipment
and home devices to connect to the VDI solution using RDP. This solution can run on the network, and
allow these devices to connect assuming they are on the network.
The next
challenge would be allowing these devices to connect to the VDI solution when
they are away from the office. If there
is an SSL-VPN solution in place, you may be out of luck! Most SSL-VPN solutions allow you to connect
to your office, via an internet browser.
By installing some software components, via ActiveX or Java, it will
give your Windows and Apple (and sometimes Linux) computers the ability to
connect to the network and allow your applications to run remotely. The issue comes as most of these solution
providers have not written software components for the mobile and tablet
devices to connect natively to the network.
Although web applications will work on these devices, any application
requiring more than a web browser will not run.
The way to
allow these devices onto the network will be to use a “traditional” VPN,
utilising PPTP, L2TP or IPSEC. This type
of connectivity is normally configured on a firewall or VPN concentrator and
once configured with the appropriated settings and authentication (we will have
to think about security); these devices will connect and can interact with your
network as if they were a computer on the network.
Once connected,
the VDI solution will be available to the device, and then allow your Windows
desktop to run, even though the device is not in the office and may not be
running a traditional operating system!
Tuesday, 7 February 2012
An Introduction to Neocoretech NDV
Neocoretech does not have an operating system requirement, as part of the
installer will install a bespoke Linux build, optimised to run the Neocoretech solution. The installation
package can be deployed in minutes via a CD ROM, with subsequent servers dynamically
integrated into the architecture.
NDV supports multiple operating systems, including Windows and Linux,
with both 32-bit and 64-bit distributions supported. The GUI based management console is intuitive,
utilising a “drag and drop” interface.
High Availability can be quickly configured and deployed, without a
requirement for a SAN. Direct Attached
Storage is utilised for media storage, but with an innovative architecture, RAM
is utilised to create quick virtual PCs, without the IOPS storm even if
multiple virtual PCs are started.
“Read-only” virtual PCs can be created giving the user a clean PC every
day. This leads to convenient
management, standard build control, better disk usage and better administrative
control. Persistent (personal) virtual machines can be created as well, giving
a more conventional PC experience.
There are three deployment options, including:
1)
Single server deployments, hosting all the
functions
2) Two
server deployments, giving a highly available architecture
3)
Multiple server deployments, giving distributed
functionality and large scale deployments
If you are interested in becoming a reseller or want to see a web demo,
please contact e92plus for more information.
Subscribe to:
Posts (Atom)


