Skip to content
JamesKingWork edited this page Jul 22, 2020 · 7 revisions

Proposed structure for VNC Cloud Groups:

Proposed procedure for setting up VNC Cloud access:

Owner / Admin (Single Experiment Controls group member)

  1. Enables "global" Two-Factor Authentication for all users of the VNC Cloud system, in accordance with site security advice.
  2. Creates "Machine Groups" in VNC portal all within the ISIS "Team", one per physical ISIS instrument e.g. "LMX" (See diagram above)
  3. Creates "People Groups", one per instrument (e.g. "LMX Instrument Scientists" or perhaps "LMX Users" containing ISs and external users for simplicity)
  4. Grants access to Machine Group to appropriate People Group
  5. Invites Instrument Scientists (IS) to create a VNC account via VNC portal (invitation email)
  6. Grants "Manager" privilege to IS
  7. Adds IS to appropriate People Group(s)

Manager (IS or other ExptCtrl member)

  1. Creates VNC Cloud account using link in invitation email from Owner/Admin
  2. Sends emails to external users via VNC Cloud portal inviting them to create a VNC account
  3. Grants "User" privilege to new users
  4. Adds users to appropriate People (instrument) Group(s) (and removes when experiment over)
  5. (Optional if willing & able) Installs VNC Server on the relevant machine(s) (e.g. NDCxxx & NDLxxx) via conventional VPN and RDP. (Details in "Deployment" section of VNC Cloud portal). More help in VNC Article
  6. Enables "Cloud Connectivity" in Server options
  7. Adds "local" computers (viewing, analysis, etc.) to Machine Group(s) (See diagram above)
  8. Performs below steps to use VNC client

User (External facility user):

  1. Creates VNC cloud account using link in invitation email from IS
  2. Downloads, installs and runs VNC client.
  3. Logs in and is presented with list of machines authorised to connect to
  4. Connects to a machine, typically a general access cabin PC (NDCxxx) or analysis machine (NDLxxx) [at this point has same access as if physically present in instrument cabin]
  5. Connects to instrument control computer (NDXxxx) via RDP (if session not already established)
Clone this wiki locally