130 pts.
 How to allow outside access to internal pc securely
Hi all, I need to allow an outside service engineer connect to a machine tool (PC attached) to run diagnostics on my network. What's the best way to allow him temperorily access to this internal pc? This will probably only happen a few times a month, so access doesn't have to be enabled permanently. I have a checkpoint firewall and use HP procurve managed switches. Should I be setting up a rule on the firewall or setting up a VLAN on the switch? Or some combination? Not sure how best to approach this? Thanks in advance, Paul

Software/Hardware used:
ASKED: March 9, 2008  12:58 AM
UPDATED: December 30, 2009  12:53 PM

Answer Wiki:
Setting up a VPN (Virtual Private Connection) is a trivial matter to set up and provides an encrypted tunnel (link) for remote workers. If you are running Windows Server it is set up under Routing and Remote Mangement. It can even be set up on a standalone XP (probably 2000 and lower as well) workstation by creating an advanced connection in the Create New Connection wizard (Accept incoming connections.) You'd just have to route port 1723 (default PPTP port) to whichever computer is accepting the connections. You'll also need to have a user set up to be able to connect remotely - this is done under the Dial-in tab on their user account. #######Added by Kb3cgj##### I usually recommend Logmein.com. You can setup a free account and give the engineer access to it. When he is done trouble-shooting..simply delete the account and uninstall the software....They have a number of good products. Nick +++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++ Guys I would NEVER NEVER suggest that you use sites such as logmein/gotomypc to access an Internal server.... You're allowing access from yet ANOTHER 3rd party into your network by doing this.... it only takes one disgruntled employee at a 3rd party service to do something stupid and bang goes your network security!! You need to set up a fully encrypted VPN, send them over the client or however you choose to do it, and pull them through your firewalls with severe restrictions!! You can always set up times for this access to reduce risk. Amanda
Last Wiki Answer Submitted:  December 30, 2009  12:53 pm  by  Kb3cgj   580 pts.
All Answer Wiki Contributors:  Kb3cgj   580 pts. , Nevyn357   30 pts.
To see all answers submitted to the Answer Wiki: View Answer History.


Discuss This Question:
_ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _


 

another good tool is gotomypc. It works great and we have had engineers use it to dial into our systems before. It can be found at http://www.gotomypc.com

 6,850 pts.

 

Hamahi is another free & easy to setup vpn…
https://secure.logmein.com/products/hamachi/vpn.asp?lang=en
Clients for Windows, Mac & Linux

 20 pts.