{"id":29,"date":"2011-05-02T21:10:47","date_gmt":"2011-05-03T04:10:47","guid":{"rendered":"https:\/\/thebeagle.itgroove.net\/?p=29"},"modified":"2023-02-24T21:47:09","modified_gmt":"2023-02-24T21:47:09","slug":"secure-remote-access-options-for-smb","status":"publish","type":"post","link":"https:\/\/regroove.ca\/archive\/2011\/05\/02\/secure-remote-access-options-for-smb\/","title":{"rendered":"Secure Remote Access Options for SMB"},"content":{"rendered":"<p>A big chunk of the customer base I deal with at <a href=\"https:\/\/www.itgroove.net\" target=\"_blank\" rel=\"noopener noreferrer\">itgroove<\/a> are small offices that have single or dual server infrastructures.&#160; In many cases they want to allow their staff to remotely access systems and resources at the office.&#160; There are two very good tools available to this SMB space to control and secure this type of access.<\/p>\n<p>The first option is to use the remote access tools built into Windows Small Business Server.&#160; SBS has shipped with decent remote access tools since SBS2003 but I\u2019ll focus on SBS2008 and SBS2011 in this post.<\/p>\n<p>SBS2008 offers Remote Web Workplace or RWW as the remote tool of choice.&#160; RWW is a webpage hosted by the SBS machine that is published out to the public Internet and which offers secured, controlled access to published internal resources on the SBS host as well as on the internal LAN.&#160; SBS2011 renames this to Remote Web Access or RWA and it expands upon the features offered by RWW.&#160; In either case, resources on the SBS host and\/or LAN are made available to authenticated users and the resources presented are controlled by options assigned to the user\u2019s Windows account.<\/p>\n<p><a href=\"https:\/\/thebeagle.itgroove.net\/wp-content\/uploads\/thebeagle\/2011\/05\/SNAGHTMLa9c65bc.png\"><img loading=\"lazy\" decoding=\"async\" style=\"border-right-width: 0px;padding-left: 0px;padding-right: 0px;border-top-width: 0px;border-bottom-width: 0px;border-left-width: 0px;padding-top: 0px\" title=\"SNAGHTMLa9c65bc\" border=\"0\" alt=\"SNAGHTMLa9c65bc\" src=\"http:\/\/thebeagle.itgroove.net\/wp-content\/uploads\/thebeagle\/2011\/05\/SNAGHTMLa9c65bc_thumb.png\" width=\"564\" height=\"401\" \/><\/a><\/p>\n<p>&#160;<\/p>\n<p>&#160;<\/p>\n<p>&#160;<\/p>\n<p>&#160;<\/p>\n<p>&#160;<\/p>\n<p>RWW presents this webpage and presents a standard Windows authentication challenge.&#160; Once proper credentials are presented the following screen is presented:<\/p>\n<p><a href=\"http:\/\/thebeagle.itgroove.net\/wp-content\/uploads\/thebeagle\/2011\/05\/SNAGHTMLaa01117.png\"><img loading=\"lazy\" decoding=\"async\" style=\"border-right-width: 0px;padding-left: 0px;padding-right: 0px;border-top-width: 0px;border-bottom-width: 0px;border-left-width: 0px;padding-top: 0px\" title=\"SNAGHTMLaa01117\" border=\"0\" alt=\"SNAGHTMLaa01117\" src=\"http:\/\/thebeagle.itgroove.net\/wp-content\/uploads\/thebeagle\/2011\/05\/SNAGHTMLaa01117_thumb.png\" width=\"569\" height=\"387\" \/><\/a><\/p>\n<p>From here an authenticated user can access Outlook Web Access (Check Email), connect via RDP to desktop machines on the LAN (Connect to a Computer), connect to the internal SharePoint site (Internal Website), Connect to the SBS Server (Connect to Server) and access other resources as published to the webpage.&#160; The resources that the user sees on this page are the resources they are allowed to use, if a user is not allowed access to desktop machines, for example, then the \u201cConnect to Computer\u201d link is not displayed.<\/p>\n<p>SBS2011 expands the connection types to also allow for access to shared folders on the SBS server.&#160; This allows authenticated user to access shared files on the server directly from the RWA webpage and is a feature that users have asked for for a number of years.<\/p>\n<p>RWW\/RWA relies on standard Windows authentication mechanisms as well as SSL for security.&#160; For those who desire more there are add-ons available from third parties that add additional security with tools like two-factor authentication.<\/p>\n<p>For those that do not have SBS (or those who do but that don\u2019t want to use RWW\/RWA) there is a great option available in the <a href=\"http:\/\/www.sonicwall.com\" target=\"_blank\" rel=\"noopener noreferrer\">Sonicwall<\/a> Virtual Office.&#160; Sonicwall embeds an SSL VPN server and remote access tools in all of their UTM firewall products starting with the entry-level TZ100.&#160; The SSL-VPN server and Virtual Office remote access tool are configured within the standard Sonicwall management interface.&#160; The Sonicwall can integrate with Active Directory for user authentication or a standalone user database can be created within the Sonicwall and used for authentication.&#160; Either way, users can be identified and access rights granted.&#160; Authenticated users can then login to the Virtual Office webpage and access resources they are allowed to use.<\/p>\n<p>The nice thing about the Virtual Office is that access to internal resources, specifically RDP access, can be controlled user by user as Virtual Office has a \u201cpublishing\u201d feature that allows an administrator to publish RDP access tailored by user.&#160; A sample Virtual Office looks something like this:<\/p>\n<p><a href=\"http:\/\/thebeagle.itgroove.net\/wp-content\/uploads\/thebeagle\/2011\/05\/SNAGHTML1240bab64.png\"><img loading=\"lazy\" decoding=\"async\" style=\"border-bottom: 0px;border-left: 0px;padding-left: 0px;padding-right: 0px;border-top: 0px;border-right: 0px;padding-top: 0px\" title=\"SNAGHTML1240bab6[4]\" border=\"0\" alt=\"SNAGHTML1240bab6[4]\" src=\"http:\/\/thebeagle.itgroove.net\/wp-content\/uploads\/thebeagle\/2011\/05\/SNAGHTML1240bab64_thumb.png\" width=\"571\" height=\"408\" \/><\/a><\/p>\n<p>The \u201cbookmarks\u201d are the published links, in this case the link is published to the same machine using two different protocols \u2013 one specific to IE and the other that will work with almost any browser on machines running Windows, Mac and even Linux.&#160; The links presented here are specific to one particular user, other users might see other links.&#160; For those companies out there that use Windows Server 2008 Foundation, Sonicwall Virtual Office can provide the RDP access to internal systems that is not shipped as part of the O\/S a la SBS.<\/p>\n<p>Both SBS and Sonicwall offer \u201ctraditional\u201d VPN options, as well; SBS sets up a Windows VPN connection that users can use (form Windows machines only) while Sonicwall offers an SSLVPN client (NetExtender) that works with multiple browsers and also runs from Mac OSX.<\/p>\n<p>In summary, there are lots of options available for SMB\u2019s looking for ways to provide controlled, secure remote access to resources on their internal networks with SBS and Sonicwall offering two very good options.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>A big chunk of the customer base I deal with at itgroove are small offices that have single or dual server infrastructures.&#160; In many cases they want to allow their staff to remotely access systems and resources at the office.&#160; There are two very good tools available to this SMB space to control and secure &hellip; <a href=\"https:\/\/regroove.ca\/archive\/2011\/05\/02\/secure-remote-access-options-for-smb\/\"><\/a><\/p>\n","protected":false},"author":10,"featured_media":0,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"inline_featured_image":false,"footnotes":""},"categories":[256,257,266],"tags":[468,540,543,550,574,635],"acf":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v23.0 - https:\/\/yoast.com\/wordpress\/plugins\/seo\/ -->\n<title>Secure Remote Access Options for SMB - Archive<\/title>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/regroove.ca\/archive\/2011\/05\/02\/secure-remote-access-options-for-smb\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Secure Remote Access Options for SMB - Archive\" \/>\n<meta property=\"og:description\" content=\"A big chunk of the customer base I deal with at itgroove are small offices that have single or dual server infrastructures.&#160; In many cases they want to allow their staff to remotely access systems and resources at the office.&#160; There are two very good tools available to this SMB space to control and secure &hellip;\" \/>\n<meta property=\"og:url\" content=\"https:\/\/regroove.ca\/archive\/2011\/05\/02\/secure-remote-access-options-for-smb\/\" \/>\n<meta property=\"og:site_name\" content=\"Archive\" \/>\n<meta property=\"article:published_time\" content=\"2011-05-03T04:10:47+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2023-02-24T21:47:09+00:00\" \/>\n<meta property=\"og:image\" content=\"http:\/\/thebeagle.itgroove.net\/wp-content\/uploads\/thebeagle\/2011\/05\/SNAGHTMLa9c65bc_thumb.png\" \/>\n<meta name=\"author\" content=\"Sean Wallbridge\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Sean Wallbridge\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"4 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"WebPage\",\"@id\":\"https:\/\/regroove.ca\/archive\/2011\/05\/02\/secure-remote-access-options-for-smb\/\",\"url\":\"https:\/\/regroove.ca\/archive\/2011\/05\/02\/secure-remote-access-options-for-smb\/\",\"name\":\"Secure Remote Access Options for SMB - Archive\",\"isPartOf\":{\"@id\":\"https:\/\/regroove.ca\/archive\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\/\/regroove.ca\/archive\/2011\/05\/02\/secure-remote-access-options-for-smb\/#primaryimage\"},\"image\":{\"@id\":\"https:\/\/regroove.ca\/archive\/2011\/05\/02\/secure-remote-access-options-for-smb\/#primaryimage\"},\"thumbnailUrl\":\"http:\/\/thebeagle.itgroove.net\/wp-content\/uploads\/thebeagle\/2011\/05\/SNAGHTMLa9c65bc_thumb.png\",\"datePublished\":\"2011-05-03T04:10:47+00:00\",\"dateModified\":\"2023-02-24T21:47:09+00:00\",\"author\":{\"@id\":\"https:\/\/regroove.ca\/archive\/#\/schema\/person\/74e1c0def190f181c1394c2b6d883e77\"},\"breadcrumb\":{\"@id\":\"https:\/\/regroove.ca\/archive\/2011\/05\/02\/secure-remote-access-options-for-smb\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/regroove.ca\/archive\/2011\/05\/02\/secure-remote-access-options-for-smb\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/regroove.ca\/archive\/2011\/05\/02\/secure-remote-access-options-for-smb\/#primaryimage\",\"url\":\"http:\/\/thebeagle.itgroove.net\/wp-content\/uploads\/thebeagle\/2011\/05\/SNAGHTMLa9c65bc_thumb.png\",\"contentUrl\":\"http:\/\/thebeagle.itgroove.net\/wp-content\/uploads\/thebeagle\/2011\/05\/SNAGHTMLa9c65bc_thumb.png\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/regroove.ca\/archive\/2011\/05\/02\/secure-remote-access-options-for-smb\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Blog Archive\",\"item\":\"https:\/\/regroove.ca\/archive\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Secure Remote Access Options for SMB\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/regroove.ca\/archive\/#website\",\"url\":\"https:\/\/regroove.ca\/archive\/\",\"name\":\"Archive\",\"description\":\"\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/regroove.ca\/archive\/?s={search_term_string}\"},\"query-input\":\"required name=search_term_string\"}],\"inLanguage\":\"en-US\"},{\"@type\":\"Person\",\"@id\":\"https:\/\/regroove.ca\/archive\/#\/schema\/person\/74e1c0def190f181c1394c2b6d883e77\",\"name\":\"Sean Wallbridge\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/regroove.ca\/archive\/#\/schema\/person\/image\/\",\"url\":\"https:\/\/secure.gravatar.com\/avatar\/adf8cea6291c39d166616f2148d919a6?s=96&d=mm&r=g\",\"contentUrl\":\"https:\/\/secure.gravatar.com\/avatar\/adf8cea6291c39d166616f2148d919a6?s=96&d=mm&r=g\",\"caption\":\"Sean Wallbridge\"},\"url\":\"https:\/\/regroove.ca\/archive\/author\/swallbridge\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Secure Remote Access Options for SMB - Archive","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/regroove.ca\/archive\/2011\/05\/02\/secure-remote-access-options-for-smb\/","og_locale":"en_US","og_type":"article","og_title":"Secure Remote Access Options for SMB - Archive","og_description":"A big chunk of the customer base I deal with at itgroove are small offices that have single or dual server infrastructures.&#160; In many cases they want to allow their staff to remotely access systems and resources at the office.&#160; There are two very good tools available to this SMB space to control and secure &hellip;","og_url":"https:\/\/regroove.ca\/archive\/2011\/05\/02\/secure-remote-access-options-for-smb\/","og_site_name":"Archive","article_published_time":"2011-05-03T04:10:47+00:00","article_modified_time":"2023-02-24T21:47:09+00:00","og_image":[{"url":"http:\/\/thebeagle.itgroove.net\/wp-content\/uploads\/thebeagle\/2011\/05\/SNAGHTMLa9c65bc_thumb.png"}],"author":"Sean Wallbridge","twitter_card":"summary_large_image","twitter_misc":{"Written by":"Sean Wallbridge","Est. reading time":"4 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"WebPage","@id":"https:\/\/regroove.ca\/archive\/2011\/05\/02\/secure-remote-access-options-for-smb\/","url":"https:\/\/regroove.ca\/archive\/2011\/05\/02\/secure-remote-access-options-for-smb\/","name":"Secure Remote Access Options for SMB - Archive","isPartOf":{"@id":"https:\/\/regroove.ca\/archive\/#website"},"primaryImageOfPage":{"@id":"https:\/\/regroove.ca\/archive\/2011\/05\/02\/secure-remote-access-options-for-smb\/#primaryimage"},"image":{"@id":"https:\/\/regroove.ca\/archive\/2011\/05\/02\/secure-remote-access-options-for-smb\/#primaryimage"},"thumbnailUrl":"http:\/\/thebeagle.itgroove.net\/wp-content\/uploads\/thebeagle\/2011\/05\/SNAGHTMLa9c65bc_thumb.png","datePublished":"2011-05-03T04:10:47+00:00","dateModified":"2023-02-24T21:47:09+00:00","author":{"@id":"https:\/\/regroove.ca\/archive\/#\/schema\/person\/74e1c0def190f181c1394c2b6d883e77"},"breadcrumb":{"@id":"https:\/\/regroove.ca\/archive\/2011\/05\/02\/secure-remote-access-options-for-smb\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/regroove.ca\/archive\/2011\/05\/02\/secure-remote-access-options-for-smb\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/regroove.ca\/archive\/2011\/05\/02\/secure-remote-access-options-for-smb\/#primaryimage","url":"http:\/\/thebeagle.itgroove.net\/wp-content\/uploads\/thebeagle\/2011\/05\/SNAGHTMLa9c65bc_thumb.png","contentUrl":"http:\/\/thebeagle.itgroove.net\/wp-content\/uploads\/thebeagle\/2011\/05\/SNAGHTMLa9c65bc_thumb.png"},{"@type":"BreadcrumbList","@id":"https:\/\/regroove.ca\/archive\/2011\/05\/02\/secure-remote-access-options-for-smb\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Blog Archive","item":"https:\/\/regroove.ca\/archive\/"},{"@type":"ListItem","position":2,"name":"Secure Remote Access Options for SMB"}]},{"@type":"WebSite","@id":"https:\/\/regroove.ca\/archive\/#website","url":"https:\/\/regroove.ca\/archive\/","name":"Archive","description":"","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/regroove.ca\/archive\/?s={search_term_string}"},"query-input":"required name=search_term_string"}],"inLanguage":"en-US"},{"@type":"Person","@id":"https:\/\/regroove.ca\/archive\/#\/schema\/person\/74e1c0def190f181c1394c2b6d883e77","name":"Sean Wallbridge","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/regroove.ca\/archive\/#\/schema\/person\/image\/","url":"https:\/\/secure.gravatar.com\/avatar\/adf8cea6291c39d166616f2148d919a6?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/adf8cea6291c39d166616f2148d919a6?s=96&d=mm&r=g","caption":"Sean Wallbridge"},"url":"https:\/\/regroove.ca\/archive\/author\/swallbridge\/"}]}},"_links":{"self":[{"href":"https:\/\/regroove.ca\/archive\/wp-json\/wp\/v2\/posts\/29"}],"collection":[{"href":"https:\/\/regroove.ca\/archive\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/regroove.ca\/archive\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/regroove.ca\/archive\/wp-json\/wp\/v2\/users\/10"}],"replies":[{"embeddable":true,"href":"https:\/\/regroove.ca\/archive\/wp-json\/wp\/v2\/comments?post=29"}],"version-history":[{"count":1,"href":"https:\/\/regroove.ca\/archive\/wp-json\/wp\/v2\/posts\/29\/revisions"}],"predecessor-version":[{"id":3099,"href":"https:\/\/regroove.ca\/archive\/wp-json\/wp\/v2\/posts\/29\/revisions\/3099"}],"wp:attachment":[{"href":"https:\/\/regroove.ca\/archive\/wp-json\/wp\/v2\/media?parent=29"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/regroove.ca\/archive\/wp-json\/wp\/v2\/categories?post=29"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/regroove.ca\/archive\/wp-json\/wp\/v2\/tags?post=29"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}