Re: Terminal services

Tech-Archive recommends: Fix windows errors by optimizing your registry

From: Steve Foster [SBS MVP] (steve.foster_at_picamar.co.uk)
Date: 05/20/04


Date: Wed, 19 May 2004 18:36:28 -0700

Mark Mancini wrote:

> STeve, no, you DON'T need a VPN to add security to TS.....it will only
> REDUCE it. TS should be setup with high encryption for 128 bit
> encryption. He is using it for admin purposes, and shouldn't need
> access to LAN resources. While he is an admin, he maybe accessing it
> from his family computer and putting a PC on a company LAN like that
> is LESS secure than SBC.

The default configuration for a VPN connection is more secure than
direct TS, and offers much more functionality.

The default for TS is to not lock out administrator accounts, no matter
how many attempt to logon, whereas with a VPN it's easy to have a
separate account just for the VPN tunnel.

I know it's possible to make changes to mitigate against these, but
those are not the default settings, and the maximum security with
default settings will come from the use of VPN rather than direct TS.

Who's to say the original poster doesn't need remote access to LAN
resources... When I'm doing remote administrative tasks for my
customers, I often have a need to reach out to the internal network.

-- 
Steve Foster [SBS MVP]
---------------------------------------
MVPs do not work for Microsoft. Please reply only to the newsgroups.


Relevant Pages

  • Re: Terminal services
    ... TS should be setup with high encryption for 128 bit encryption. ... He is using it for admin purposes, and shouldn't need access to LAN ... > Note that it's usually a good to set up VPN and then use TS over VPN ... > Steve Foster ...
    (microsoft.public.backoffice.smallbiz2000)
  • Re: VPN routing from NAT to NAT
    ... if you are willing to lose all LAN connectivity while on ... the VPN, you can perhaps coexist on the same subnet.. ... If you are both using the same private network for your LANs, ... >VPN adapter, because that address is now bound to the VPN adapter and ...
    (microsoft.public.windowsxp.work_remotely)
  • Re: Multi-homed server and VPN
    ... The idea was to separate the LAN traffic from the VPN ... bound for the Internet go to the gateway 192.168.1.251, ... I have 192.168.1.251 as the router ...
    (microsoft.public.windows.server.networking)
  • Re: VPN & firewalls question
    ... What types of things do your remote clients need to do after they ... If the need access to their WinXP Pro LAN computers, create a VPN and fire ...
    (microsoft.public.backoffice.smallbiz2000)
  • Re: IPSEC routing ?
    ... the Tunnel only see the "outside" of the Tunnel,...nothing sees the inside ... Site-to-Site VPN and Remote Access VPN act totally different..... ... This means the VPN Router behaves just like a regular LAN ...
    (microsoft.public.windows.server.networking)