MAIT.Connect

MAIT.Connect is a standardized technical and organizational procedure that enables MAIT employees to access our customers’ infrastructure, applications, and data.

MAIT Clients

These are the MAIT experts from the Service Desk or Consulting who will provide services for our customers. To achieve this uniformly with stable structures, we use MAIT.Connect internally.

DMZ MAIT.Connect

This is the technical hub of the setup. It uses the product Remote Desktop Manager (RDM). Through this management and the terminal servers provided there, MAIT experts access the resources provided at the customer site.

Customer systems

This symbolically shows the systems provided by the customer that MAIT experts access to deliver their services.

Which system requirements must the server at the customer meet?

The provided server must be a member of the customer domain.

Technical specifications for the working environment:

  • 4 vCPUs
  • min. 16 GB RAM
  • 100 GB HDD
  • at least Windows Server 2019

Which users must be provided by the customer?

For server setup we need an AD user who will be added as a local admin on the server.

The two AD users for the service should be members of the Abas group so that tests with the GUI can be reproduced in the system.

Additional AD users for upgrades will be requested by the MAIT project lead before project start so they can be created.

Can MFA/2FA be required and used?

By using the RDM, we internally enforce MFA for usage. This meets the IT security requirements even without user-side MFA from the customer.

Is a Windows Standard Server sufficient to meet the needs?

For support cases and regular maintenance, a Standard Server with two concurrent logins is sufficient.

For upgrades this is not sufficient. MAIT recommends equipping the server with RDS licenses or temporarily providing a second or third server for the additional users during the upgrade.

Which setup is required if the customer runs a server farm with Session Broker?

In this case it is technically necessary to use a site-to-site tunnel because the Session Broker performs automatic load distribution and does not guarantee access to a specific host. If a dedicated login to a specific server is configured and ensured, that server can also be addressed via OpenVPN.

What connection options exist besides IPsec and OpenVPN?

The RDM also supports HTML5-provided servers or clients. For usability we require clipboard access. File transfer capability is advantageous.

How does MAIT log logins and accesses to the system?

The RDM records who accessed which system, when and with which user. What was done on the system is not recorded. This evidence is usually sufficient for current certifications and auditor requests and can be provided on demand.

Site-to-Site/IPSec

This connection type is set up between customer and MAIT firewalls. MAIT provides standard parameters including PSK & NAT which must be configured on the customer side to ensure communication. The customer lists all machines made available to MAIT (hostname, internal IP address, server function) and the corresponding NAT addresses in the range assigned by MAIT. After successful firewall configuration on both sides (MAIT & customer) and successful NATting (on the customer side), the new connection is released for MAIT employees.

Note: MAIT follows the guidelines of the German Federal Office for Information Security (BSI) and the IETF. Therefore we cannot support connections below the minimum standard. In particular, IKEv1 and DH groups below 15 are no longer offered.

If these settings/parameters are not available, we use the OpenVPN variant.

OpenVPN

With OpenVPN the connection is established directly from the working environment (Windows Server) to MAIT’s firewall. Access to the server is provided via TeamViewer or another remote tool to install the OpenVPN client. Port 443 must be open to the outside for this.

If more than one machine in the customer network is to be connected, each must be provided with the client as well. MAIT opens the ports required for server usage, e.g. RDP.

Afterwards all machines are available to MAIT employees via that OpenVPN connection.

Can VDI clients be connected via a client application (e.g. Citrix Workspace)?

In principle yes, but because of the many servers MAIT operates internally for MAIT.Connect, this cannot be rolled out on all servers. If this is the only option, we require a dedicated server on our side that receives the required application and is operated exclusively for that customer. This is offered separately and must be ordered via sales.

How are systems for Abas, Comarch, IT, PTC, Siemens and other systems integrated?

We recommend a site-to-site tunnel because the servers and resources at the customer are best addressed and administered directly.

For IT-related connections, these are created and administered within the project scope.

If no server can or should be provided at the customer — are there alternatives?

It is possible to provide Windows computers for the individual users in the required number so that the provided users can be used.