Re: setting up RD without a VPN connection ?

From: Patrick Rouse [MVP] (PatrickRouseMVP_at_discussions.microsoft.com)
Date: 10/06/04


Date: Tue, 5 Oct 2004 20:49:04 -0700

Can the remote client connect to any Terminal Server on the Public Internet?
This would be the first thing I would verify. If you do a search on Google
for Remote Desktop Web Connection, many public connections are listed (while
admins should probably block robots/spiders from picking these up) which
could be used to test your connectivity. I'm not recommending trying to
logon to any of them, but if you can get to their GINA Logon then you're
connected over port 3389 and know that the remote computer is working
properly.

Another thing you will have a problem with is a highly latent connection,
regardless of the measured thruput. 20Kbps is barely enough bandwidth to
work over a 800x600 desktop at 256 colors with mediocre performance when
latency is not a problem, but when you add a high latency to the connection
the performance may reach abismal.

The lowest speed connection I've found to be sufficient for a working RDP
session @ 800x600 & 256 color depth is 26.4Kbps.

As far as VPNs go, I not only do NOT recommend them for securing RDP
connection, but believe that unless they are managed IPSec/L2TP VPNs that
they are a security risk as you're allowing any garbage or services on the
remote computer to directly interact with a corporate network. PPTP VPNs add
zero extra security to an RDP Session, as the tunnel is setup with the
credentials provided by the end-user, not by PKI based certificates.

Secondary authentication (i.e. Safeword or SecureID) is a better way to
increase the already solid security of Windows Terminal Server, whether using
RDP or ICA protocol.

Patrick Rouse
Microsoft MVP - Terminal Server
http://www.workthin.com

"Bill Sanderson" wrote:

> Keep talking to Al, but I just want to reiterate that the VPN is not
> necessary for RD to work, nor is the VPN needed so that the information
> being transmitted is encrypted.
>
> A VPN connection does make the connection more secure--less susceptable to
> certain types of attacks--"man in the middle" attacks.
>
> You can definitely work without it and many of us do, regularly.
>
> "Daniel Rascoe" <danielrascoe@hotmail.com> wrote in message
> news:uWcXgOzpEHA.3464@TK2MSFTNGP14.phx.gbl...
> >I want to remotely control a computer that has Windows XP Pro SP2 on it.
> >I'd like to use remote desktop in the simpliest configuration. Can I use RD
> >without a VPN connection? Should I be using something other than RD? FYI,
> >the client computer is running windows 2000 pro SP4. I've followed the
> >directions at
> > http://www.microsoft.com/windowsxp/using/mobility/getstarted/remoteintro.mspx
> > But I can't seem to get RD to work.
> >
> > Daniel
> >
>
>
>



Relevant Pages

  • Remote Desktop Disconnect
    ... precisely the time you attempt a connection, ... receive the following error message: ... The terminal server cannot issue a client license. ... >Remote Desktop Disconnected ...
    (microsoft.public.win2000.termserv.clients)
  • Re: Authentication event id 5722
    ... Have you considered using RWW for this remote user? ... need either a local workstation or a Terminal Server for him to connect to. ... After changing the password, however, an authentication is ... of times that I try connecting the laptop through VPN connection), ...
    (microsoft.public.windows.server.sbs)
  • RE: VPN
    ... The problem with sharing data like Quickbooks across VPN is that it has to ... Terminal Server only transfers keyboard, mouse, & video which makes for very ... If you are only a single remote user you could investigate using a XP Pro ... > connection is enabled. ...
    (microsoft.public.windows.server.sbs)
  • Re: Start a program on connection and Windows XP
    ... you mean that the XP machine is the rdp *host*! ... MCSE, CCEA, Microsoft MVP - Terminal Server ... Windows XP remote desktop connection is considered 'remote ...
    (microsoft.public.windows.terminal_services)
  • Re: setting up RD without a VPN connection ?
    ... connecting remotely won't work unless port 3389 is forwarded. ... The connection in Rio de Janeiro is highly variable. ... > Can the remote client connect to any Terminal Server on the Public ... > As far as VPNs go, I not only do NOT recommend them for securing RDP ...
    (microsoft.public.windowsxp.work_remotely)

Loading