Ethical Hacking Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package. | Computer Forensics Training at InfoSec Institute Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors. |

| Subject: | RE: Terminal Servers @ Datacenter |
|---|---|
| Date: | Mon, 18 Sep 2006 15:49:59 +0100 |
We have a similar situation and we use RSA Secure ID for this. Simple overview 1. Each user gets a fob 2. The fobs will be assigned to as many servers as to like. 3. When the users tries to sign in to a server, the RSA service checks the credentials and also makes sure that the fob and user is allowed to access that machine. 4. Then you will have a full audit trial of what user logged on to what server and when We use a managed RSA Ace server, so we use a hosted RSA authentication server, so we don't have manage the Ace server. We are able to access reports on access and setup the fobs via a web based control page. We access all the hosted solutions via VPN. The users can authenticate to the VPN via Radius. I hope this gives you a starter for 10. Regards Jason Gregson -----Original Message----- From: listbounce@securityfocus.com [mailto:listbounce@securityfocus.com] On Behalf Of dubaisans dubai Sent: 18 September 2006 14:25 To: focus-ms@securityfocus.com Subject: Terminal Servers @ Datacenter Hi, Looking for best practices in managing windows servers in a datacenter. We have 100 windows servers with Terminal services. There is no Active Directory domain.Everything is workgroup. There is a set of 10 admins who share responsibility of administering these servers. Each admin has access to a group of 10 or 15 Servers. For the purpose of tracking access, we would like to setup one central gateway server in the DMZ where all admins will login first. Based on their user-id, they can initiate connection to their authorised internal server. It should not be possible for one server to initiate connection to another server. All servers should accept connection only from this central gateway server. We are open to buying a third party product if required. It would be great if we can also track what the admins are doing . --------------------------------------------------------------------------- ---------------------------------------------------------------------------
smime.p7s
Description: S/MIME cryptographic signature
| <Prev in Thread] | Current Thread | [Next in Thread> |
|---|---|---|
| ||
| Previous by Date: | Terminal Servers @ Datacenter, dubaisans dubai |
|---|---|
| Next by Date: | SecurityFocus Microsoft Newsletter #308, mfossi |
| Previous by Thread: | Terminal Servers @ Datacenter, dubaisans dubai |
| Next by Thread: | SecurityFocus Microsoft Newsletter #308, mfossi |
| Indexes: | [Date] [Thread] [Top] [All Lists] |