100 likes | 113 Views
Discover the benefits of virtual desktop infrastructure (VDI) and secure desktop architecture. Explore the advantages of secure access to sensitive data, fast deployment and scalability, policy enforcement, and anywhere, anytime access. Learn about the current applications and future possibilities of secure desktops. Get buy-in from your team with a live demo.
E N D
Applying the Power of Virtual Desktops Conrado Wang Ke Cheng deNiemeyer <chengw (at) sacredheart (dot) edu> Information Security Officer, Sacred Heart University
Virtual World at Sacred Heart Univ • VMware VI3 & vSphere 4 • 65 Virtual Servers • 255 Virtual Desktops • Running on 15 Physical blade servers • Virtual Desktop Infrastructure (VDI) • Secure Desktop • Virtual HDD Streaming • Thin Clients in our Labs • Virtual Test Environments
Secure Desktop Backend at SHU Hardware Software • HP c7000 Blade Enclosure • HP BL460c • 2 x Quad Core 2.3Ghz (Intel E5450) • 32 GB RAM • 4 x 1Gb Ethernet (on 2 separate boards) • Netapp 3040 Filers • 1TB for VM and vDisk Images • 12TB for User/Department Data • NFS & iSCSI • Cisco Catalyst 3750 Switches • 1Gb Ethernet (Copper) • 4 x 10Gb Uplink • VMware VI3 • Quest vWorkspace 7.0 • SSL Gateway • Connection Broker • Citrix Provisioning Server 5.1 • PXE Boot • HDD Streaming • Microsoft Windows XP sp3 • Yes it’s Windows 7 Ready • NetAppFlexClone
Secure Desktop Advantages • Low learning curve for users • Secured access to sensitive data • Business data vs. User data • Fast Deployment & Scalability • Stand new VMs in under 2mins • Policy Enforcement • Local administrator privileges • Anywhere, anytime access • Image management • Patch 1 image, update everyone • Currently • ERP (Datatel Colleague R17, R18) • Registrar’s • Human Resources • Business Office • Admissions (Recruitment Plus) • Financial Aid (PowerFAIDS, EDConnect) • Institutional Advancement (Raiser’s Edge) • Health Systems (Titanium) • Public Safety (ARMS) • ImageNow Document Imaging • w/USB scanners
Secure Desktop Disadvantages • Ok Multimedia Support • Now w/Flash Video • ACL/Firewall Rule Maintenance • Increased Complexity • SSL Gateway • Connection Broker • Provisioning Server • ESX Servers • SAN & Blade Infrastructure • “Quality of Life” Issues • Cannot browse the web • Cannot persist software changes • Cannot connect certain USB devices • Coming Soon • Cannot access unsafe shares • Cannot copy & paste to/from client • Cannot connect any USB devices except sanctioned
Getting Buy-in • Explain that security is important and they should just listen to IT… (HA! Just kidding… ) • Initial deployment for test environments • No other alternatives with new version of software • Anywhere Anytime Access • Ability to access legacy environments with new simultaneously • Make no effort to fix the fact that VPN sucks (at least PPTP does…)
Demo • https://securedesk.sacredheart.edu/