Saturday, 18 May 2013

Publishing Microsoft Lync 2010 using Microsoft UAG 2010

I've been working with Microsoft UAG since it's been available.  I had a head start as I was using and deploying IAG and Whale previously, which were the two predecessors to UAG.

I've published a few different applications, but a majority of the solutions will include Microsoft Exchange (whether it's OWA, full Outlook and/or ActiveSync), RDP connections (usually for administrators to access servers or to Terminal Servers), and some sort of Intranet or SharePoint site.  Some of the rarer occasions I've been asked to give terminal access to AS/400 solutions, publish VMware View, deliver the Neocoretech VDI solution using HTML 5 clients on iPads, etc, etc.

So when I was asked to deploy Lync 2010, I was pretty confident it would be straightforward.  I did some research to ensure I was following best practise, but ended up using a few documents to achieve a fully working solution.  Please note I wasn't doing this blind as I had deployed Lync in our office, but could make it work with UAG without real certificates (as is highlighted in the following instructions)

I was deploying an SSL-VPN portal as well as creating a Lync connection for the computers, which meant I modified some of the configurations given.

The first document I used was this one:
http://social.technet.microsoft.com/wiki/contents/articles/14000.publish-lync-2010-with-forefront-unified-access-gateway-2010-uag.aspx

Ensure you have all the domain names for the various Lync components, but I used a different document for this.

As ever, I was deploying a Celestix WSA solution, which was straightforward.  I followed Georg Thomas' instructions, but did not follow the section on the "Additional Trunk Configuration" as this would impact my SSL-VPN portal.  I did create the registry key as described, but also follow Erez Ben Ari's blog here with the additional registry key: http://blogs.technet.com/b/edgeaccessblog/archive/2012/06/15/lync-publishing-on-uag.aspx

I would typically use wildcard certificates, but as these do not work with Lync on UAG, we has to use a SAN (Subject Alternate Name) certificate.  As I have never done this before, I followed these comprehensive instructions: http://technet.microsoft.com/en-us/library/gg429704.aspx  The request of the certificate from the provider is the same as a "normal" or wildcard certificate, as is the installation.

Thanks the well written documents abover, the publishing of Lync 2010 was straightforward.

Friday, 3 May 2013

Backups, a necessary evil?

It may be unfair of me to compare backups to car insurance, but here goes!
  • We all know we need it, but not everyone has it. 
  • We buy it, hoping to never have to use it.
  • We never know how effective it is until we have to use it.
  • We ignore the extra offerings, believing we can get it cheaper elsewhere.
  • Most people will buy on price, rather than looking at what it covers.
With most back up solutions there is a limitation with the platform on which the backup solutions runs.  Some are software only, some are appliance only, some only have agents and push to the internet, some only run in a virtual environment, and many vendors will only give one or two of these choices.

Looking at the agents and application support, some specialise with virtualised environments, some only with Windows servers, some have limited integration agents and therefore struggle to back up vital servers within your network.

Some have the ability to create bare metal backups in case of a disaster, but they can only restored on similar hardware.  Most people will struggle to find similar hardware, once it's over a year old, as the manufacturers are continuing to release new hardware.

Then there's the media it will back up to, some will only go to tape, disk, SAN, NAS, removable media, to the internet (cloud), or to a private network/cloud, but again some will only give limited choices.

We at e92plus, currently work with Unitrends, who can offer the following:
  • Choice of platform, supporting either a backup appliance or a virtual appliance for either Microsoft Hyper-V or VMware vSphere.
  • Backup a variety of operating systems, including Microsoft Windows, Linus, Apple Mac OS X, AIX and Solaris.
  • Integrates with Microsoft Hyper-V and VMware virtualisation environments, including instant recovery for VMware.
  • The ability to archive to Disk, tape, NAS and SAN.
  • The ability to replicate to another appliance, to another virtual appliance, to the Unitrends Cloud, or to a private cloud (hosted by either you or a trusted partner/supplier).
  • Utilising compression and de-duplication technologies to the reduce the size of the backups.
  • The ability to create bare metal backups, and restore to dissimilar hardware.
Unitrends sounds too good to be true, but a number of environments (have a look on Spiceworks) and I are currently using and very happy with the solution.

The pricing is very competitive as well, but you probably won't believe it until you try it, so have a look here to download your Free Edition, which will allow you to protect four virtual machines, forever, for free!

Wednesday, 1 May 2013

Shoulder Surfing...

Working in IT security, I understand and advocate the importance of PINs and passwords, as well as explaining why they shouldn't be shared.  My 8 year old and 6 year old have computer lessons at school from which they understand the importance of keeping passwords secret. 

On our home PC, I've created profiles for them where they insisted on having passwords and even I as the administrator/father don't know their passwords.  It makes me proud when I try and trick the password out of the them, that they won't tell me.

Imagine my surprise when my wife recounts her day, where my 2 year old son was happily playing on the iPad and listening to iTunes.  I tell my wife that my iPad is PIN protected!  I've been "shoulder surfed" by my two year old son!

Not a major problem as I don't keep important information on it, but he can play Angry Birds whenever he wants (and pretty much does)...

 
What if this was a work environment, it would not be acceptable if this had happened.  In fact, I would suspect someone would get either a verbal or written warning for such a security lapse.  Maybe I have a certain amount of paranoia, but I don't check my email on my mobile when there are people close enough to shoulder surf me.  Not that I have anything that private or personal, but I don't know what's in that email until I open it.
 
The facts around visual security are pretty much as you expect:
  • 80% chance that you've already become a victim of others reading over your shoulder
  • £1.9 million is the average cost to businesses per incident of physical data theft
  • 96% of data breaches in 2010 were avoidable
  • 52% of laptop users in the UK are ignoring visual security issues
  • 67% of working professionals surveys in the US had worked on some type of sensitive data outside of the office.
Visual security of on-screen data can be a key part of the implementation of ISO 27001.  So if you excuse the reflection, you can see both my laptop and desktop screen when looking at them head on.
 
 
Here is my screen from an angle and slightly above to give the view of a shoulder surfer, you can see my 3M privacy filters working their magic.
 

 
When the view angle exceeds 30 degrees, the screen is protected.  You can also see a notch in the top right allowing these to be removed to give the normal visibility back.
 
e92plus have started distributing the 3M privacy filters and free samples can be requested from here: http://www.securityplusonline.co.uk/3m  


Monday, 16 July 2012

Privilege Management… What is it and do I really need it?

If any of you reading this use Windows 7 on your laptop and computer, or you administer a number of Windows 7 machines, you will be all too familiar with the User Access Control (UAC) prompt.  You will know the frustration as user being unable to update your computer, even though you know it’s the right thing to do, but as an administrator you need to lock down the UAC, as you can’t have users installing untrusted pieces of software.

We see that the users need the flexibility to be able to do their job, while the administrator has the security of the IT systems in mind.

What’s the fix? 
In most organisations, there is an IT team who have to enter in administrative credentials when required.  This may be workable or acceptable in a small organisation, but in larger organisations more members are required in the IT team.  Even in our organisation with 35 people, it can consume a lot of time form the internal support team, especially when there are Adobe or Java updates for instance.

A better solution? 
The Viewfinity Management solution, will offer the following functions:
  • Elevate privileges – allowing certain processes or applications to automatically have their administrative rights elevated.
  • Block/White listing – allowing specific software to blocked or allowed to run.
  • Policy Automation and On Demand Elevation – allowing ad-hoc self-elevation for power users and allowing end users to have specific policy workflow applied.
  • End User Experience – allowing customised messages, keeping the user experience more in line with company policy.
  • Remote Workforce – allowing policies to propagate to home works, remote office or frequent travellers.
  • Compliance Reports – gives reports on all users, including full audit trials for compliance validation, with dedicated reports for SOX, PCI DSS, HIPAA, and other industry mandates.  
The Viewfinity Management solution can be deployed as a GPO snap-in, a server based software solution or as a cloud solution, giving flexibility in choice, but also the ability for resellers to move into Managed Service Provider (MSP) realm  providing this solution to multiple end users.

Do I really need it?
If you don’t want to employ a team to manually enter in credentials or maximise your support team in other activities, then any Windows domain with Windows 7 computers needs a solution like Viewfinity.

e92plus are the sole distributor for Viewfinity in the UK.

Wednesday, 18 April 2012

Using my iPad for work!


After much pressure from the MD and Marketing Manager, and now also having my own iPad, I decided to investigate iPad access to our network.

My first port of call was configuring a server to run Neocoretech, which is a VDI solution that does not require a SAN or massively complicated infrastructure prior installing (unlike some of the alternative solutions).  With the Neocoretech server running and configured on our network, I had to build a Windows 7 image.  The image I created was a “read only “image, so that the user cannot change the image.  Some minor configuration was carried out to make the virtual machine a member of the domain, as well restricting some functions of the operating system in order to improve performance.   

Testing was carried out from a laptop to ensure the VDI infrastructure was working, before connecting my iPad to the wireless network and browsing the VDI landing page.  I had to install a free RDP client onto my iPad, and I chose Remote Desktop – Universal App by Evolve Networks, as these gave me the option to create more than one RDP session unlike the Wyse free application.

On network, it gave me a very good user experience, where the Windows 7 desktop was useable on the iPad.  The only gripe I had was that scroll bars were a pain, and where you would expect to press and drag them, you had to click to jump to the scroll bar on.

My next challenge was getting this to work remotely.  As you can see from other posts, we use Microsoft UAG hosted on a Celestix appliance as our remote access, but this solution does not offer an iOS client to allow the iPad to fully integrate with the features of the UAG, so I am unable to use the UAG to give me VDI access on the iPad.

As an alternative, I configured a Cyberoam UTM appliance to give me an L2TP VPN.  Following these instructions provided from Cyberoam will give the right result: http://kb.cyberoam.com/default.asp?id=1891

As did not have alternative route out to the internet, I create a hotspot on my iPhone, and used Bluetooth to connect my iPad to the hotspot.  Using 3G, I connected my iPad to the L2TP VPN, and from there started up my RDP client, and connected to my VDI server.  I was surprised as the latency was not as bad as I had expected, but it gave me my Windows 7 desktop on my iPad via the 3G network!

Very impressed how quickly this was configured and running, but now I need to customise my Windows 7 VDI image to optimise it for our network.

iOS and Android in the workplace (aka Replacing your computer with an iPad/Android Tablet?)

With iOS and Android becoming more popular in the home environment, I am often asked how these devices can be used as the endpoint to connect to a work network.  I would like to separate the use of these devices as a work device, rather using them as an access point for the occasional remote access session.

Irrespective of whether the tablet or mobile is a company or personal device, the issue with connecting it to your network is software support, so we have to look at what applications are required in the workplace.  With email, most mobile and tablet devices will support Exchange, and most of these devices will have the ability to create, read and edit Microsoft Office documents.  There may be some issues with legacy applications, or Windows only applications, which would render the device useless for those applications.

I’ve read in some places, where the solution is the replace the applications with something that will work on these mobile devices, or on other computer operating systems.   This seems a little bit extreme, especially in the current economic climate, where IT budgets are being cut and hardware refresh rates being increased from three years to up to five years.  Embracing BYOD (Bring Your Own Device) will also bring the same challenges, as the organisation may save hardware costs in not having to purchase and maintain devices, but will have to alter the backend infrastructure to support these new devices.

I’ve always liked the concept of VDI (Virtual Desktop Infrastructure) but in the past, it has been both complicated and expensive.  There are now solutions which can give you a virtual desktop for less than the cost of a new PC.  By manipulating budgets, it would be possible to deploy a VDI solution, instead of carrying out a hardware refresh of the desktop/laptop infrastructure.  The VDI solution would be able to create a Windows desktop environment that can run on any endpoint that supports RDP (Remote Desktop Protocol).  This would enable the old hardware, the mobile devices, the tablets, the BYOD equipment and home devices to connect to the VDI solution using RDP.  This solution can run on the network, and allow these devices to connect assuming they are on the network. 

The next challenge would be allowing these devices to connect to the VDI solution when they are away from the office.  If there is an SSL-VPN solution in place, you may be out of luck!  Most SSL-VPN solutions allow you to connect to your office, via an internet browser.  By installing some software components, via ActiveX or Java, it will give your Windows and Apple (and sometimes Linux) computers the ability to connect to the network and allow your applications to run remotely.  The issue comes as most of these solution providers have not written software components for the mobile and tablet devices to connect natively to the network.  Although web applications will work on these devices, any application requiring more than a web browser will not run.

The way to allow these devices onto the network will be to use a “traditional” VPN, utilising PPTP, L2TP or IPSEC.  This type of connectivity is normally configured on a firewall or VPN concentrator and once configured with the appropriated settings and authentication (we will have to think about security); these devices will connect and can interact with your network as if they were a computer on the network.

Once connected, the VDI solution will be available to the device, and then allow your Windows desktop to run, even though the device is not in the office and may not be running a traditional operating system!


Tuesday, 7 February 2012

An Introduction to Neocoretech NDV

Neocoretech does not have an operating system requirement, as part of the installer will install a bespoke Linux build, optimised to run the Neocoretech solution. The installation package can be deployed in minutes via a CD ROM, with subsequent servers dynamically integrated into the architecture.
NDV supports multiple operating systems, including Windows and Linux, with both 32-bit and 64-bit distributions supported.  The GUI based management console is intuitive, utilising a “drag and drop” interface.

High Availability can be quickly configured and deployed, without a requirement for a SAN.  Direct Attached Storage is utilised for media storage, but with an innovative architecture, RAM is utilised to create quick virtual PCs, without the IOPS storm even if multiple virtual PCs are started.

“Read-only” virtual PCs can be created giving the user a clean PC every day.  This leads to convenient management, standard build control, better disk usage and better administrative control. Persistent (personal) virtual machines can be created as well, giving a more conventional PC experience.

There are three deployment options, including:

1)      Single server deployments, hosting all the functions
2)      Two server deployments, giving a highly available architecture
3)      Multiple server deployments, giving distributed functionality and large scale deployments

If you are interested in becoming a reseller or want to see a web demo, please contact e92plus for more information.