Re: Spreading Virus/worms/spyware via terminal server connections?



No problem - my bad - I should have provided more details upfront. With the
SonicWall's VPN I can configure the firewall's VPN polcy to either 'split
tunnel' the session or force the client to access via only a secured gateway.
I agree if the PC is already infected then it does not matter - somehow
the firewall that the VPN is going through needs to somehow filter/scan the
VPN tunneling session for virus/worms/spyware etc..I'll check with my
Sonicwall firewall vendor if they have this security feature....

Thanks again for your feedback. Appreciated it.

--
LPJ


"Jeff Pitsch [MVP]" wrote:

> Ok, got it. Sorry about that. If your vpn is setup to not allow split
> networking, then I wouldn't think you have anything to worry about. If you
> allow it then yes I'd be worried. But those settings wouldn't prevent
> anything from coming through if it was already on the PC though. does that
> make sense?
>
> Jeff Pitsch
> Microsoft MVP - Terminal Services
> http://www.sbcgatekeeper.com
> Your Terminal Services Security Website
>
> "Luigi" <Luigi@xxxxxxxxxxxxxxxxxxxxxxxxx> wrote in message
> news:E958F828-45BB-414C-A9D1-288D2C6482F4@xxxxxxxxxxxxxxxx
> > Jeff,
> >
> > Thanks for your comments. See my latest post to Lanwench on my
> > environment.
> > Just for clarification - our Terminal Server sits behind a SonicWall 2040
> > firewall. So it is not using a public IP address. We use the SonicWall
> > VPN
> > client to connect to our LAN via the firewall then login into our TS.
> >
> > My main concern is having remote users using an unsecured/infected
> > public-personal PC to connect to the Terminal Server via the Remote
> > Desktop
> > WEB connection browser.
> >
> > --
> > LPJ
> >
> >
> > "Jeff Pitsch" wrote:
> >
> >> I'm assuming by your comments that your terminal server has a public IP
> >> address, which means it's directly accessible by te public (TSWeb does
> >> nothing for this) and this means your internal network is exposed to the
> >> internet. I would be much more concerned about this very bad design than
> >> anything else. You've virtually eliminated your firewall as a protective
> >> measure.
> >>
> >> Jeff Pitsch
> >> Microsoft MVP - Terminal Services
> >> http://www.sbcgatekeeper.com
> >> Your Terminal Services Security Website
> >>
> >> "Luigi" <Luigi@xxxxxxxxxxxxxxxxxxxxxxxxx> wrote in message
> >> news:DF3F9D99-1A35-43D2-9383-1D31E2802066@xxxxxxxxxxxxxxxx
> >> > How safe is a Terminal Server Service running Remote Desktop Web
> >> > Connection
> >> > if the remote client's home PC is infected with a worm/virus or
> >> > spyware.
> >> > Can
> >> > the worm/virus/ spyware utilize the Terminal services client's web
> >> > connection
> >> > to spread the virus/worm/spyware to the office LAN/WAN?
> >> >
> >> > Can someone intercept/hack a terminal server session's Remote Desktop
> >> > WEB
> >> > connection?
> >> >
> >> > Similar to first question but connecting to the Terminal Server via
> >> > VPN -
> >> > utilizing the XP's Remote Desktop Connection client -with VPN you are
> >> > actually making a connection the office LAN server shared resources -
> >> > can
> >> > a
> >> > home network that is infected with worms/virus/spyware - infect the
> >> > office
> >> > LAN via the VPN or Terminal Server?
> >> >
> >> > --
> >> > LPJ
> >>
> >>
> >>
>
>
>
.



Relevant Pages

  • Re: SBS 2008 - Firewall Appliance?
    ... Cisco ASA 5510 Appliance Content Security Edition Bundle ... 250 IPsec VPN peers, ... But "firewall services" are simply listed as included. ... If you don't need AV or VPN then this is overkill....and I recommend running client AV on a server that can handle monitoring anyways....not using an edge device as the client AV manager...but that's another conversation. ...
    (microsoft.public.windows.server.sbs)
  • Re: remoting not working through vpn
    ... These can act differently depending on where the VPN terminates. ... I have ISA firewall and all my VPN connections terminate on the firewall system. ... The other case might be that you have tunneled the VPN completely through the firewall and let it terminate on the server itself. ... The problem may be in how the client system is presenting its ...
    (microsoft.public.dotnet.framework.remoting)
  • Re: Teleworking
    ... Cisco VPN Client running on local PC ... ADSL router runing VPN passthrough and full firewall ... > simplify the management and deployment of PGP and reduce overall PGP ...
    (Security-Basics)
  • Re: RE:Sizing a Firewall for a Client
    ... about the Sonic Wall Pro, when in turn will cost you at least 3 times as ... Sizing a Firewall for a Client ... We've tested the Sonicwall with up to 5 VPN clients at once ...
    (Security-Basics)
  • Re: remoting not working through vpn
    ... network through vpn, it worked. ... When we changed the client remoting ... and opened that port on the client's firewall, ... As an alternative approach I guess we could have the server queue up ...
    (microsoft.public.dotnet.framework.remoting)