RE: VPN & Security Question
- From: "Patrick Rouse" <PatrickRouse@xxxxxxxxxxxxxxxxxxxxxxxxx>
- Date: Fri, 10 Jun 2005 21:06:03 -0700
Even in an industry like banking I would neve use VPN to increase security of
an RDP or ICA Connection. For increased security (if you're not satisifed
with the 128 bit encryption that RDP provides) look into secondary
authentication like Biometrics or SecureID/SafeWord.
VPNs are great for connecting remote offices, but way too much
administrative burden to use for individual remote user connections.
Brian Madden and I (along with the rest of the TS MVPs) had this same
conversation with the MSFT TS Product team who was not willing to say that TS
should be deployed over the Internet w/o VPN, but we told them that we do it
and recommend it all the time w/o any issues.
Show me an exploited RDP Connection before deciding you need more security.
Make sure you have a good password policy and that your TS is behind a
firewall and you should be fine.
--
Patrick Rouse
Microsoft MVP - Terminal Server
http://www.workthin.com
"mrussogfc" wrote:
> Richard what industry do you work in? If you work in banking or some other
> high risk area you may have to use VPN otherwise why bother.
> --
> callwalker
>
>
> "Richard Brooks" wrote:
>
> > I hope this is not a stupid question but is a VPN really necessary for
> > secure terminal services? If you change the servers administrator name to
> > something encrypted and use 8 alpha numeric character strong passwords and
> > set the encryption to high, how would someone gain access to the server?
> > With brute force, you would not only have to try all passwords but all
> > usernames as well. And if the encryption is set to high, Man in the middle
> > attacks would not be very effective either. Also, you would set policy so
> > only an administrator can log in to the server, so social engineering would
> > not be an issue either. So, why add the extra VPN layer that only degrades
> > performance?
> >
> > Thanks
> >
> >
> >
> >
.
- Follow-Ups:
- RE: VPN & Security Question
- From: Cybersteve
- RE: VPN & Security Question
- References:
- VPN & Security Question
- From: Richard Brooks
- RE: VPN & Security Question
- From: mrussogfc
- VPN & Security Question
- Prev by Date: RE: Hardware upgrade - Terminal Server 2003
- Next by Date: anyone SP1 windows2003
- Previous by thread: RE: VPN & Security Question
- Next by thread: RE: VPN & Security Question
- Index(es):
Relevant Pages
|