This shows you the differences between two versions of the page.
Both sides previous revision Previous revision Next revision | Previous revision Next revision Both sides next revision | ||
doc:success-stories:electronic-glovebox [2013/11/20 09:57] stefanbaur |
doc:success-stories:electronic-glovebox [2013/11/20 10:06] stefanbaur |
||
---|---|---|---|
Line 1: | Line 1: | ||
+ | |||
====== X2Go at the Doctor' | ====== X2Go at the Doctor' | ||
Line 7: | Line 8: | ||
ReCoBS is a security concept designed by the German Federal Office for Information Security ([[https:// | ReCoBS is a security concept designed by the German Federal Office for Information Security ([[https:// | ||
- | It places a Terminal Server (in our case, a Linux box running X2Go) in a demilitarized zone (DMZ) between two Firewalls. This Terminal Server may freely surf the net, but it cannot initiate " | + | It places a Terminal Server (in our case, a Linux box running X2Go) in a demilitarized zone (DMZ) between two Firewalls. This Terminal Server may freely surf the net, but it cannot initiate " |
- | Where we're diverting from the standard ReCoBS approach is that we're using a single firewall with a third ethernet port for the DMZ, and we're running both the firewall and the X2Go Terminal Server as virtual machines on a stripped down Debian Linux with KVM. | + | Where we're diverting from the standard ReCoBS approach is that we're using a single firewall with a third ethernet port for the DMZ, and we're running both the firewall and the X2Go Terminal Server as virtual machines on a stripped down Debian Linux with KVM. Also, we're providing a web proxy server with a default deny policy, so that you can whitelist " |
While the system isn't limited to a particular hardware configuration (we've shipped regular midi-tower cases as well as 19", 1HU rack-mount servers), our standard model is a fanless (i.e. entirely passively cooled), very compact case with enough CPU and RAM for up to 5 concurrent users. A picture, showing the box on top of a stack of copy paper for easy size comparison, is available here: [[http:// | While the system isn't limited to a particular hardware configuration (we've shipped regular midi-tower cases as well as 19", 1HU rack-mount servers), our standard model is a fanless (i.e. entirely passively cooled), very compact case with enough CPU and RAM for up to 5 concurrent users. A picture, showing the box on top of a stack of copy paper for easy size comparison, is available here: [[http:// | ||
Line 23: | Line 24: | ||
Thanks to the Published Application Mode, these applications interact with the Desktop as if they were installed locally on the machine, there is no annoying full-desktop window that you need to drag out of the way to access your local applications, | Thanks to the Published Application Mode, these applications interact with the Desktop as if they were installed locally on the machine, there is no annoying full-desktop window that you need to drag out of the way to access your local applications, | ||
- | Please visit our website for further information and to view a screencast. The website is in German only at the moment, but if you are interested in selling GloveBoxes in your country, feel free to contact us by e-Mail and we'll provide you with English translations of whatever you may need. Also, while the screencast has German on-screen text and no translation yet, it should be rather easy to figure out what it's about, even without | + | Please visit our website for further information and to view a screencast. The website is in German only at the moment, but if you are interested in selling GloveBoxes in your country, feel free to contact us by e-Mail and we'll provide you with English translations of whatever you may need. Also, while the screencast has German on-screen text and no translation yet, it should be rather easy to figure out what it's about, even without |
* Overview: [[http:// | * Overview: [[http:// | ||
* Screencast: [[http:// | * Screencast: [[http:// | ||
* e-Mail: [[mailto: | * e-Mail: [[mailto: | ||
+ | |||
+ | ---- | ||
+ | |||
+ | Kudos to [[http:// |