WebEx Remote Access White Paper The CBORD Group, Inc.
Document Revision: 1 Last revised: October 30, 2007 Changes are periodically made to the information contained in this document. While every effort is made to ensure that all information is correct, inconsistencies may occur. Proprietary & Confidential Information Do Not Distribute The CBORD Group, Inc 61 Brown Road Ithaca, NY 14850 607 257-2410 607 257-1902 fax 2007 The CBORD Group, Inc. CBORD and CS Gold are registered trademarks of The CBORD Group, Inc. All other brand names and product names are believed to be registered trademarks or service marks of their respective owners.
Introduction WebEx Remote Access is a web-delivered system support tool that offers a more secure, reliable, and efficient method of providing support to your CBORD systems. Remote Access runs over the WebEx MediaTone network, a worldwide mesh of application-specific data switches housed in secure WebEx data centers interconnected via dedicated lines. CBORD connects to your WebEx-enabled systems through our WebEx secure Internet portal, though which all traffic is encrypted and all access is logged for future auditing. This white paper describes the deployment, security, and use of WebEx Remote Access. WebEx Remote Access installation Installation of WebEx Remote Access takes just minutes. The WebEx Remote Access installer (MSI or EXE) is downloaded from cbord.webex.com and run on each server licensed. The installer package is under 10 MB in size. The WebEx Remote Access installation wizard walks you through several windows in order to install and configure the agent. Most configuration options are grayed out as they are set globally for CBORD s portal, cbord.webex.com. An installation document will be provided if CBORD will not be onsite for installation. The minimum requirements for WebEx Remote Access are: Microsoft Windows 98, ME (Millennium Edition), 2000, XP, NT, or 2003 Server Intel x86 (Pentium 400 MHz + ) or compatible processor 128 MB RAM Microsoft Internet Explorer 6.0, Netscape 7.0, Firefox 1.0, or Mozilla 1.6 JavaScript and cookies enabled on the Web browser; ActiveX enabled on Internet Explorer Internet connection WebEx Remote Access use Once WebEx Remote Access has been installed on your server(s), they must be associated with CBORD s WebEx portal. When you call CBORD for support, your support representative will access your server(s) via our secure WebEx portal instead of Microsoft Remote Desktop or pcanywhere as had been common in the past. Your CBORD support representative can perform all the same support tasks in WebEx Remote Access as in the traditional peer-to-peer remote tools, including: One click CTRL-ALT-DEL for login Windows Login / Log off / Lock console Remote desktop control File transfer The following tools are available with WebEx Remote Access, but not with legacy remote tools. Call Escalation A support representative can invite someone from R&D into a session to troubleshoot an issue faster.
Reboot and reconnect If a reboot is required, the Remote Access agent will reconnect as soon as your server is available so CBORD technicians can continue work. Firewall and Proxy compatibility WebEx Remote Access first attempts connection using TCP port 1270. If TCP port 1270 is blocked by a firewall, the WebEx client tunnels all communications using HTTP (TCP port 80) and HTTPS (TCP port 443). Once connected to CBORD, all communications use HTTPS (TCP port 443). In most cases, WebEx Remote Access will work on your server without intervention. In case your site is restricting outgoing traffic via firewall or proxy, please note the following: HTTP (TCP port 80) and HTTPS (TCP port 443) must be allowed for incoming and outgoing traffic. ActiveX must be allowed through for this connection. WebEx sites should not be cached (content or IP-path). In the rare case an exception is required for WebEx traffic, the IP range that can be used is 64.68.96.0 64.68.127.255. WebEx Remote Access security WebEx Remote Access provides better security for your CBORD systems than is available with pcanywhere or Microsoft Remote Desktop even when these legacy tools are used through a VPN. Encryption of all communications All WebEx Remote Access sessions are encrypted with 128-bit SSL. No session data retention WebEx Remote Access session data is transmitted over WebEx s secure, private MediaTone switched network. Data is never retained on the WebEx network or on CBORD s WebEx portal. Individual technician logins Every CBORD technician has an individual login to CBORD s WebEx portal. Session logs indicate the technician(s) connected to your system. This capability provides better auditing of system access than is possible with legacy remote support methods. Multi-layer authentication Password policy for CBORD technicians WebEx portal login credentials follows CBORD s corporate IT policy for password aging, password complexity, and password re-use. Once connected to the CBORD portal, the technician clicks on a link to your server and is prompted for a CBORDspecific access code. After the technician has successfully entered the access code, s/he is presented with the login prompt on your server. Only after the technician has entered correct server credentials is s/he able to access your system. Though there are three layers of authentication, a technician can be connected to your server in less than one minute following your request for support.
E-mail notifications The WebEx Remote Access agent can be configured to email you every time a technician connects to your server. When a technician disconnects from a session, you will receive another email containing a session log. You may change the email distribution list at any time through the WebEx Remote Access property page (accessed by right-clicking on the WebEx logo in your server s system tray Properties). CBORD cannot change the email distribution list when connected to your server through Remote Access. Comprehensive Session Logs Every Remote Access session is logged in a small HTML file stored on your server. The content of this session log is also emailed to you after the session is completed. The WebEx Remote Access session log includes following information: Site auditing Name of the technician Time and Date of connection / disconnection Server reboots CTRL-ALT-DELETE Log on / Log off File transfers (including the names of the files) CBORD can provide a detailed server access report upon request. These reports detail each connection to your server including: technician name, date, and time, as well as a long list of other support-related functions. This information is also available to you anytime in the HTML session logs stored on your server. Disabling Remote Access when not in use The WebEx Remote Access agent runs as a system service and waits for a connection from CBORD by default. However, it may be necessary as part of your security policy to disable all remote access until support is requested. WebEx Remote Access can be toggled online or offline with two mouse clicks from the right-click menu of the WebEx icon in your system tray.
CS Gold: Additional considerations WebEx Remote Access can be used for the support of your CS Gold system; however, there may be times it is necessary for CBORD technicians, DBAs or R&D to access your system with Oracle database administration tools such as Toad. In most cases, Oracle will require port 1521 be open in your firewall. The options for allowing direct access are: Open port 1521 specific to the CS Gold DBS IP address Open CS Gold DBS IP address to CBORD s IP address Open port 1521 specific to CS Gold DBS IP address from CBORD s IP address If direct access is not available, it may be necessary for CBORD technicians to install Oracle s free DBA tool, SQL Developer, to properly support your CS Gold system. Remote DBA services Users of CBORD s Remote DBA service must have port 1521 open to the CS Gold DBS server at all times.