Re: Security TS




"HDI" <hdinf@xxxxxxxxxxx> wrote in message
news:1147003571.950615.142080@xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx
Yes we have a router.

The question came beause someone said he can get into the server in
about 10-15 minutes.

Currently no firewall or vpn


To keep this in perspective...

There are a lot of layers of security. One very important layer is physical
access control. Often servers are behind locked doors for this very reason -
limit physical access to the keyboard.

Another layer that encompasses almost all of the rest of security is what I
call logical access control. This would be userID/password combinations,
encryption, operating system hardening, network traffic control (firewall -
vpn), etc.

By offering a TS for access over the Internet you are eliminating one aspect
of control... physical access control. But you still have all the other
options available.

So... if this person who says he can "get in" in 15 minutes can "get in" by
sitting at the keyboard, he will be able to "get in" remotely too. If he
can't "get in" by sitting at the keyboard, he can't "get in" remotely
either. Test him! :)

-Frank


.



Relevant Pages

  • Re: More on Remote Desktop
    ... Chances are good, though, that he's already got VPN capabilities on his ... firewall to do it for $100. ... > server at home...or purchase additional/new hardware... ... >> my firewall makes the PPPoE connection to my ADSL ISP. ...
    (microsoft.public.windowsxp.network_web)
  • Re: More on Remote Desktop
    ... You realize the Remote Desktop data stream is encrypted the same as a PPTP VPN link... ... Unless of course the original poster wants to implement an L2TP/IPSec VPN server at home...or ... > firewall to get between your clients and server on your own LAN. ... > setup so that my firewall makes the PPPoE connection to my ADSL ISP. ...
    (microsoft.public.windowsxp.network_web)
  • Re: VPN Firewall for new webserver
    ... > I'm setting up a webserver at a colocation and I need to put a VPN ... You're not going to get a quality firewall for that amount, ... and D-Link makes a DI-804HV unit ... users access to the SQL server, let them do it through a VPN session. ...
    (comp.security.firewalls)
  • Re: Cant logon to computer in SBS Domain..
    ... Does the user can access and log on to the Remote Web Workplace? ... Whether you can connect and log on to the server desktop through RWW? ... On the Firewall page, ensure that Enable firewall is selected. ... About External Firewall VPN ...
    (microsoft.public.windows.server.sbs)
  • Re: xp sp2 an 2003er domäne
    ... >Der Angreifer ist nicht nur eingedrungen, ... >> Also du schlägst vor dass ich da ne Firewall vor klemm. ... bzw. dann heisst die Lösung VPN. ... >stehen können frei mit dem Server kommunizieren. ...
    (microsoft.public.de.german.windows.server.networking)