Re: Locking down Remote Desktop.

From: Daniel Kelly \(AKA Jack\) (d.kellyNOSPAM_at_NOSPAM.ucl.ac.uk)
Date: 06/14/04


Date: Mon, 14 Jun 2004 16:23:13 +0100

If you don't want to risk installing SP2-beta then Kerio Personal Firewall
will allow you to specify IP ranges. I use Kerio right now. Be warned - it
is VERY anal! You have to teach it everything. I originally thought this
would be a good thing but the fact of the matter is that no one has enough
time to research every IP address that your computer connects to. So I now
just say "allow connection" without much consideration as to whether or not
it's a good idea.

Thanks,
Jack

"Sooner Al" <SoonerAl@somewhere.net.invalid> wrote in message
news:eNNzIXvTEHA.1472@TK2MSFTNGP12.phx.gbl...
> Actually, I misspoke on the restrict by IP issue. With the new XP SP2
Windows Firewall a user can
> specify access to remote users trying to connect via Remote Desktop to
specific IP addresses, ie.
> allow only certain IP addresses to access TCP Port 3389... Its possible
other firewall/NAT/routers
> may have that same functionality, ie. the ability to filter incoming IP
addresses and block access
> to certain ports...
>
> Note that SP2 has not been officially released yet...and is still
undergoing beta testing...
>
> --
> Al Jarvi (MS-MVP Windows Networking)
>
> Please post *ALL* questions and replies to the news group for the mutual
benefit of all of us...
> The MS-MVP Program - http://mvp.support.microsoft.com
> This posting is provided "AS IS" with no warranties, and confers no
rights...
>
> "Sooner Al" <SoonerAl@somewhere.net.invalid> wrote in message
> news:ON48mLvTEHA.2716@tk2msftngp13.phx.gbl...
> > You can change the listening port on the RD host. Make sure you reboot
the PC after making the
> > change..
> >
> > http://support.microsoft.com/default.aspx?scid=kb;en-us;Q306759
> > http://support.microsoft.com/default.aspx?scid=kb;en-us;Q304304
> >
> > I know of no way to restrict access to a RD host by IP...Perhaps someone
else does...
> >
> > --
> > Al Jarvi (MS-MVP Windows Networking)
> >
> > Please post *ALL* questions and replies to the news group for the mutual
benefit of all of us...
> > The MS-MVP Program - http://mvp.support.microsoft.com
> > This posting is provided "AS IS" with no warranties, and confers no
rights...
> >
> > "Anon" <Carmexman@hotmail.com> wrote in message
news:1aae301c44eef$cbebe040$a501280a@phx.gbl...
> >>I know there is a way to change the listening port for
> >> the remote desktop but what I am wondering is there a
> >> function or a registry setting to allow me to specify
> >> what IP's are allowed to connect to the machines remote
> >> desktop instead of which users are allowed?
> >>
> >
> >
> > ---
> > Outgoing mail is certified Virus Free.
> > Checked by AVG anti-virus system (http://www.grisoft.com).
> > Version: 6.0.701 / Virus Database: 458 - Release Date: 6/7/2004
>
>
> ---
> Outgoing mail is certified Virus Free.
> Checked by AVG anti-virus system (http://www.grisoft.com).
> Version: 6.0.701 / Virus Database: 458 - Release Date: 6/7/2004
>



Relevant Pages

  • Re: IP Tables -A What am I doing wrong
    ... >unpriveleged port. ... >from /proc/sys before any of the firewall rules start. ... Why even specify an address? ... Don't forget about FRAGMENTED TCP packets. ...
    (comp.os.linux.security)
  • Re: Connecting to SQL2005 named instance through firewall
    ... When you specify a port number, you don't specify the instance name (the port number serves as "identification" of where to go. ... have SQL Server Browser started on the server machine and let port 1434 UDP through the firewall. ...
    (microsoft.public.sqlserver.setup)
  • Re: Anyone got F11 NIS working?
    ... Is my only option to disable the firewall completely? ... which lets you specify which port it binds to. ... the configuration file that the script sources beforehand. ...
    (Fedora)
  • RE: Kerio Personal Firewall
    ... Any other windows try Active port utility. ... Subject: Kerio Personal Firewall ... allows me to specify explicitly which service is allowed inbound/outbound ... "netstat -a" only lists the active listening ports but doesnt tell me which ...
    (Security-Basics)
  • Connecting to SQL2005 named instance through firewall
    ... I can telnet to the port the SQL Server instance is listening on and it connects (so SQL Server and firewall settings are OK) but I cannot work out how to actually specify the port to connect to in the New Server Registration dialog on the machine I'm connecting *from*. ...
    (microsoft.public.sqlserver.setup)