Often we recieve support requests where users want to access their workstations from outside the LAN, either via VPN or simply via a web browser. We often have to create tunnels within our ASA/PIX to allow user to come in to their workstations for genuine purposes, sometimes to let some experts install software and at other's they just want to pick up a file they desperately need.
I was wondering if there is an easy solution that would help us accomplish this procedure, without the involvement of of Network administrator but with adequate security and change management control in place? Something, where a helpdesk administrator can have a dashboard where he/she just clicks on the user's workstation IP, and an automatic NAT gets accomplished and RDP gets enabled with port 3389 passed through the firewall.
The solution can be either ASA/PIX based or ISA based.
I read an article here, but I wonder if it's relevant in our scenario: