Re: RDP, RWW and VPN difference



What Susan said. ;)

Seriously - I've yet to see virtually anyone implement VPN any other way
than the default. And for that implementation, I definitely prefer RWW. And,
when I add in Dana's two factor authentication, with one-time passwords, I
like that a whole lot better still.


--
Charlie.
http://msmvps.com/xperts64


Leythos wrote:
In article <uNFTVHAwGHA.4880@xxxxxxxxxxxxxxxxxxxx>,
charlie@xxxxxxxxxxxxxxxxxxxxxxx says...
Of the three, RWW is the safest and the most flexible. VPN opens up your
network to whatever malware happens to have found its way onto the remote
client. RDP alone limits your options to a single PC.

Wrong, VPN does not have to open your network, it only does so if you
improperly implement VPN.

Our users VPN into the firewall with one user/password that they don't
control, it's NOT the same user/password they log onto Windows with.

The firewall has a rule, per FW authentication group that limits each
group of users to TCP3389 and either the IP of the terminal server or
the specific workstation they have been assigned in the company.

We have all the RD/TS sessions locked down.

So, with this in mind, there is nothing that can get through the VPN
that could not get into the RWW session. This method, VPN is more secure
as it requires TWO levels of authentication instead of just one.


.



Relevant Pages

  • Re: [fw-wiz] Secure access to LAN resources (WAS: terminal services)
    ... > encrypted tunnel. ... VPN devices are designed to do strong authentication. ... It's always a trade-off between risk and protection. ...
    (Firewall-Wizards)
  • RE: VPN
    ... possible to verify the identity of the server". ... Authentication, the Internet Authentication Service need to be ... On the VPN server, click Start, click Run, type rrasmgmt.msc, and then ... Windows Authentication, under Accounting Provider, click to select Windows ...
    (microsoft.public.windows.server.sbs)
  • Re: VPN over wireless
    ... The RSA key is for authentication, ... Only the payload data packets are encrypted. ... The key exchange mechanism varies with the type of encryption. ... With a VPN, only the packets going between the VPN client and VPN ...
    (alt.internet.wireless)
  • Re: IAS VPN authentication only grants access to domain if user has certificate
    ... authenticate a certificate against AD? ... So my question is at what point does the VPN connection use ...
    (microsoft.public.internet.radius)
  • Re: Win2K3 domain account connecting to Win2K VPN server in an NT4
    ... - since the server is not in the AD domain, you can't add it to the AD ... NT4 accounts can still authenticate, ... I verified that my test accounts could connect to the VPN before migrating ... > The authentication server did not respond to authentication requests in a ... ...
    (microsoft.public.win2000.ras_routing)