Windows IT Pro is the authoritative and independent resource for windows nt, windows 2000, windows 2003, windows xp. Features a collection of resources and magazines for windows IT professionals.
  
  
  Advanced Search 


October 2006

Virtual PC Security Solution

IT Server Architect Mike Nichol shares his resourceful solution to a dual-system sign-on problem
RSS
Subscribe to Windows IT Pro | See More Security Articles Here | Reprints
Or get the Monthly Online Pass—only $5.95 a month!
Main Article    Introducing Microsoft Certificate Lifecycle Manager

Although Microsoft Virtual PC 2004 is a versatile product, you probably don't think of it as a security tool. But when Mike Nichol, an IT server architect for Telstra Business Systems (TBS), a provider of managed IT services for converged networks (and subsidiary of the Australian telecom giant Telstra), needed to find a simple method to let TBS staff log on to a remote customer's system, he turned to Virtual PC 2004 for the solution. I spoke with Mike about his innovative use of Microsoft's free desktop virtualization product and his current biggest security challenge.

Explain the security problem that you needed to solve.
We were providing managed services to a customer whose legacy network didn't adhere to TBS's security requirements—in fact, their corporate network actually linked into their phone network. We were at pains to avoid connecting that system to TBS's corporate network, particularly so we didn't compromise our own security. Also, we do managed services for a lot of government and corporate bodies and have to adhere to stringent security requirements. Plugging into an unsecure network would void all those requirements.

But the TBS staff members who were involved in the day-to-day business of providing managed services to that customer had to have some connectivity to the client's network and also connect to our corporate WAN. In the past, we accomplished this by giving the staff members two separate PCs on their desktops: a PC connected to the TBS network and another that they used to connect to the client's network. As you can imagine, this solution was awkward to use and took up a lot of space on the desk.

What made you think of using Virtual PC 2004 to solve the sign-on problem?
Sometimes the obvious solution is to try and make the client's network more secure, so we do that. But this client—for their own security requirements—didn't want us plugging into their network. I'm a great believer in working smarter, not harder, and using existing technology to do so. We needed a low-cost, easy-to-use solution that our existing staff could support without needing additional training. Virtual PC 2004 fit those requirements.

How does the solution work?
We provided our standard operating environment PCs with additional RAM—we increased RAM from 512MB to 1GB—dual NICs, and dual screens. We then ran Virtual PC 2004 with a dedicated NIC patched into the existing customer LAN and unbound this from the host PC to prevent any cross-connectivity. In the morning when our users come in, they turn on their PCs and log on as they normally would to the corporate network (the host), usually just by simply clicking an icon to get to the customer's network. Some of our users spend most of their time in the customer's legacy network, whereas others jump between the two networks. When we introduced the solution, some of the users were a little skeptical, just because it was new technology. But then, a month or two into it, it was business as usual, and some of the users even forget that they're on a virtual system.

The solution's simplicity is what makes it such a good fit for our organization and our customers. We used Virtual PC 2004 in a different way than most IT pros would typically consider using it and as a result saved additional cost and desk space and provided ease of use for our clients. The end result is supportable and complies with existing and future security requirements. We're now using our Virtual PC solution and variations of it across the company in both lab and production environments.

You solved the dual sign-on problem fairly easily by applying a widely used technology in an original way. What's the biggest security issue you now face?
I guess the biggest security challenge for us is our own workforce, not so much technically as in social engineering. We've got almost 200 technicians who work out in the field with clients providing managed services as well as corporate PABX [private automatic branch exchange, aka PBX] services. They use laptops to plug in to a client's network via a serial port or Internet cable and have access to clients' networks that they normally wouldn't have on our corporate network. Additionally, they need to keep their machines up to date and make sure that they're clean because we don't want the technicians to infect the clients— or the clients to infect our network.

What have you done to make your technical staff more security conscious?
As we in IT make personal contact with staff, we try to approach security from the point of view that we're not trying to stop you from doing your job or tell you what to do, we're only trying to make sure everyone's safe. Once most people understand that, they realize that you're not just trying to be the security police; you really are trying to help them. You're not imposing a particular security policy because you don't want them to have MP3s, for example, you're doing it for a purpose: to keep our corporate network and customers secure.

I think IT tends to impose security policy-in a blanket fashion. I think I realized a number of years ago, when someone came back to me and said, "Well, why is there a security problem? Can you explain it to me?" that you can't just impose a policy with no explanation. People will resent that. But if you go the extra little bit and explain—for example, we're locking this down for these reasons—users still might not being happy with the restriction, but they'll be more understanding about it.

End of Article



Reader Comments
"We then ran Virtual PC 2004 with a dedicated NIC patched into the existing customer LAN and unbound this from the host PC to prevent any cross-connectivity."

By unbound do you mean you unchecked the "Internet Protocol (TCP/IP)" for the dedicated NIC's properties on the host machine. What items did you leave checked for the dedicated NIC on the host system?

Great solution, Thanks

hurtley March 20, 2007 (Article Rating: )


I'll contact Mike Nichol and ask him to respond to your question. I'm glad you found his solution useful!
--Anne Grubb, senior editor, Windows IT Pro

AnneG_editor March 21, 2007 (Article Rating: )


I'm very interested in the answer to Hurtley.

"By unbound do you mean you unchecked the "Internet Protocol (TCP/IP)" for the dedicated NIC's properties on the host machine. What items did you leave checked for the dedicated NIC on the host system? "

Cheers.

arvdsar April 09, 2007 (Article Rating: )


You must log on before posting a comment.

If you don't have a username & password, please register now.




Top Viewed ArticlesView all articles
The Memory-Optimization Hoax

Don't believe the hype. At best, RAM optimizers have no effect. At worst, they seriously degrade performance. ...

VMware and the Future of Virtualization

What's next for virtualization and business IT? Windows IT Pro senior editor Jeff James speaks with VMware President and CEO Diane Greene on the future of virtualization technology. ...

What service packs and fixes are available?

...


Security Whitepapers Anti-Virus Is Dead: The Advent of the Graylist Approach to Computer Protection

Getting the Job Done: Comparing Approaches for Desktop Software Lockdown

Instant Messaging, VoIP, P2P, and games in the workplace: How to take back control

Related Events Check out our list of Free Email Newsletters!

Security eBooks Spam Fighting and Email Security for the 21st Century

Understanding and Leveraging Code Signing Technologies

A Guide to Windows Certification and Public Keys

Related Security Resources Become a VIP member of the Windows IT Pro community!
Get it all with the VIP CD and VIP access. A $500+ value for only $279!

Subscribe to Windows IT Pro!
Solve your toughest technical problems with our experts and access 10,000 + articles online. 30% off

Monthly Online Pass - Only $5.95!
Get instant access to 10,000+ articles from Windows IT Pro Magazine!

TechNet Virtual Labs
Evaluate and test Microsoft's newest products.


ADS BY GOOGLE SPONSORED LINKS FEATURED LINKS

Critical Challenges of ESI & Email Retention
Are you storing too much electronic information? Get expert legal advice and better understanding of what you are required to do as an IT professional.

Become a fan of Windows IT Pro on Facebook!
Join us on Facebook and be a fan of Windows IT Pro!

Sustainable Compliance: Are You Having a Resource Crisis?
Read this white paper to examine trends in compliance and security management and review approaches to reducing the cost and operational burden of compliance.

Rev Up Your IT Know-How with Our Recharged Magazine!
The improved Windows IT Pro provides trusted IT content with an enhanced new look and functionality! Get comprehensive coverage of industry topics, expert advice, and real-world solutions—PLUS access to over 10,000 articles online. Order today!

Get It All with Windows IT Pro VIP
Stock your IT toolbox with every solution ever printed in Windows IT Pro and SQL Server Magazine plus bonus Web-exclusive content on hot topics. Subscribe to receive the VIP CD and a subscription to your choice of Windows IT Pro or SQL Server Magazine!



Order Your Fundamentals CD Today!
Gain an introduction to Exchange, learn server security requirements, and understand how unified communications can play a role in your messaging strategies with this free Exchange CD.
Windows IT Pro Home Register About Us Affiliates / Licensing Media Kit Contact Us/Customer Service  
SQL Connected Home IT Library SuperSite FAQ Wininfo News
Europe Edition Office & SharePoint Pro Windows Dev Pro Windows Excavator 
 
 Windows IT Pro is a Division of Penton Media Inc.
 Copyright © 2008 Penton Media, Inc., All rights reserved. Terms and Use | Privacy Statement | Reprints and Licensing