Windows IT Pro is the leading independent community for IT professionals deploying Microsoft Windows server and client applications and technologies.
  
  
  Advanced Search 


May 2000

Tried and True Remote Access Solutions


RSS
Subscribe to Windows IT Pro | See More Internet Articles Here | Reprints | Or get the Monthly Online Pass—only $5.95 a month!

Access your network over a dial-up, VPN, or Internet connection

No matter what solution a company employs, remote access is almost always a huge pain for users and administrators. Users have trouble accessing their corporate resources when they're away from the office, and administrators end up with a large phone bill, extra equipment to maintain, and holes in their firewall.

Because I work from a remote home office and travel every month to my corporate office, I have to deal with these situations. I also have the added bonus of needing remote access to two different offices when my travels take me to some other location.

Let's take a look at the common solutions I've tried. The first solution uses dedicated dial-up hardware. On the plus side, this method is inherently secure because users dial in to a location within their corporate network. This method doesn't add holes to the firewall, and you can add security measures, such as dial-back connections to authorized numbers. On the minus side, this method requires sufficient dedicated phone lines to support peak demand. I worked in an organization in which remote access—with more than 100 dedicated lines—became effectively unavailable during major trade shows because too many employees were trying to check their email messages at the same time. Although the market for this solution is mature and many solutions are easy to implement, you need to consider the cost. The hardware necessary to handle dial-up connections and the large monthly phone bills (even high-volume toll-free service is expensive) limit this solution's value to businesses.

VPN technology has made significant strides in recent years as the preferred remote access solution. The ability to use an inexpensive local Internet connection to access a corporate network makes remote access simpler. Whether a user connects when traveling, working in a remote office, or telecommuting, the connection type is always the same when using a VPN.

With Windows NT 4.0's PPTP, Microsoft jump-started the common use of VPNs. I briefly reviewed this technology when it became available in the mid-1990s. For my tests, I set up one server and one client and used DUN and PPTP to make a VPN connection. I learned of people's vast interest in this technology when I received more than 100 reader responses asking how I made my test VPN work—the directions that Microsoft provided were incomplete and inaccurate. Despite problems with PPTP and its security, I continued to receive requests for additional information on a regular basis for more than a year after the story ran. Users and administrators wanted a secure software-based connection that could run over the public Internet.

A quick look at Windows 2000 (Win2K) will show you just how much attention Microsoft paid to VPNs. Microsoft provides a VPN option as a basic connection type in the Dial-up Networking Connection Wizard. Microsoft also added IP Security (IPSec) and the Layer 2 Tunneling Protocol (L2TP), which the company developed with Cisco Systems.

With ISPs offering Internet access nationwide for $20 per month, a VPN connection offers mobile users an exceedingly inexpensive method for accessing their main office. VPN connections can cause problems because you need to configure the user client and the host network to support public Internet connections without compromising the security of the host network. Network administrators balk at anything that creates holes in their firewalls, and rightly so. Although vendors offer products, such as Network Associates' PGP VPN and SynData Technologies' SynCrypt VPN, to simplify the client side of the connection equation, keeping VPNs properly configured, connected, and secured is not a trivial activity. Some products, such as Cisco's router software, allow connections using IPSec, which might solve the VPN security problem. Eventually, any properly configured router with a security authentication mechanism, such as a Remote Authentication Dial-In User Service (RADIUS) server, will provide secure point-to-point communications between two Internet-connected systems.

If you look at why users most often need remote access, you'll discover that the number one reason is email access. And to obtain email messages, direct access to a host network isn't a necessity (unless the email solution requires direct access). But the most popular email solutions for NT—Microsoft Exchange Server and Lotus Domino—offer POP3 connectivity as well as proprietary options. POP3 support is the key to easy email connectivity that provides minimal exposure and risk to your corporate network.

With the two offices I connect to regularly, my primary need is email access. I almost never remotely access files from servers at either location, so access to those network resources isn't crucial when I travel. Therefore, my remote access solution is pretty simple. Although my business email account is on an Exchange server, my corporate office connects the Exchange server to a POP3 connector that is accessible from outside the firewall. The connector's resolvable IP address is an alias and makes security simple and straightforward. I use Exchange only for email (not for other uses), so POP3 access is all I need. For my home office, in which I run a standard SMTP and POP3 sendmail implementation, I already have the appropriate holes punched into my firewall.

So my routine when traveling is easy. I use MSN as my dial-up Internet provider, so before I travel, I obtain a list of numbers for my destination city from MSN's Access Phone Numbers Web page and save those numbers to a file on my notebook computer. When I arrive at my hotel, I dial up the most convenient number, and I'm on the Internet. Because I don't need any special VPN software, I can launch my email client and download the few hundred messages that show up in my inboxes each day. The access phone number is almost always local, so the price for the call stays the same whether I connect for 10 minutes or 10 hours.

Does my method solve every problem I have with remote access? Of course not. For my home office frame relay network, I'm investigating whether to switch to a Cisco router to directly access my network resources, then use IPSec to secure the connection. But for now, I have an easy way to obtain the items that are necessary to perform my daily job: my email messages. And when I need a large file from the corporate network, I can make a quick phone call or email request to have the file sent to me. (I find it a little less painful to have someone send a large file to me in an email message than to download a 2MB file over a 28.8Kbps connection.) Because I'm remotely accessing only my email messages, when I walk away from a system during a download, I'm not leaving an unsecured pipe in my corporate network, as I would be if I were downloading from a direct dial-up or VPN connection. This method keeps the security level a little higher, and I'm sure my corporate IT staff sleep a bit easier, too.

End of Article



Reader Comments
When yor write:
"Although my business email account is on an Exchange server, my corporate office connects the Exchange server to a POP3 connector that is accessible from outside the firewall. The connector's resolvable IP address is an alias and makes security simple and straightforward."

Wich POP3 connector do yor use?
Is the internet mail service of Exchange Server, or is another machine (outside the firewall) with another software?
If this is the case, wich is that POP3 connector software?

Thanks in advance

Gastón Christen May 26, 2000


your routine to stay connected requires planning and discipline. try using uRoam www.uroam.com great product with a complete platform designed for simple and secure access your information without changing your work behavior

al gray February 01, 2001


You must be a registered user or online subscriber to comment on this article. Please log on before posting a comment. Are you a new visitor? Register now




Top Viewed ArticlesView all articles
Battery Life Issues Almost Certainly Not Windows 7's Fault

While Microsoft is still investigating a notebook battery life issue that was supposedly caused by Windows 7, some interesting trends have emerged. ...

Confirmed: Battery Life Issues Not Windows 7's Fault

Microsoft on Monday issued a lengthy statement about the recent Windows 7 battery controversy, echoing my assessment from earlier in the day, but backing it up with hard, cold evidence. ...

Microsoft Warns of Windows Version Expirations

Microsoft warned that this year will see three out-of-date Windows versions slip into retirement. ...


Windows OSs Whitepapers Protecting Microsoft SharePoint

Related Events Deep Dive into Windows Server 2008 R2 presented by John Savill

Check out our list of Free Email Newsletters!

Windows OSs eBooks Understanding and Leveraging Code Signing Technologies

A Guide to Windows Certification and Public Keys

SQL Server Administration for Oracle DBAs

Related Windows OSs Resources Introducing Left-Brain.com, the online IT bookstore
Looking for books, CDs, toolkits, eBooks? Prime your mind at Left-Brain.com

Discover Windows IT Pro eLearning Series!
Clear & detailed technical information and helpful how-to's, all in our trademark no-nonsense format


Windows IT Pro Home Register FAQ for Windows WinInfo News
Europe Edition About Us Contact Us/Customer Service Media Kit Affiliates / Licensing  
SQL Server Magazine Office & SharePoint Pro DevProConnections IT Job Hound
Left-Brain.com Technology Resource Directory asp.netPRO ITTV Windows SuperSite 
 
 Windows IT Pro is a Division of Penton Media Inc.
 © 2010 Penton Media, Inc. Terms of Use | Privacy Statement