Re: Why use VPN?



Your missing the point. By opening 3389 to your terminal servers you
exposing your internal network to the internet. That is what is bad. A VPN
would prevent this. Or a product as simple as 2x loadbalancer would work
just as well also. It acts as a man in the middle in the DMZ and you never
expose your internal network to the internet.

I'm surprised your security team hasn't thrown up roadblocks on this idea of
opening 3389.

Jeff Pitsch
Microsoft MVP - Terminal Server

Forums not enough?
Get support from the experts at your business
http://jeffpitschconsulting.com

"Vincent Delporte" <vincent.delporte@xxxxxxxxxx> wrote in message
news:le318214elgfooiiibuu84ejlculg5p0n0@xxxxxxxxxx
On Fri, 2 Jun 2006 11:23:51 -0400, "Jeff Pitsch"
<jeff@xxxxxxxxxxxxxxxxxxxxxxxx> wrote:
You are completely exposing your network to the public internet.

I read that RDP encrypts data, so I don't why I need to set up a VPN
instead of just opening TCP 3389?

All corporate information is critical and should be kept secure.

The information in this case is not critical. If someone has a good
article on how VPN work, preferably using stand-alone equipment (ie.
route cum firewall cum VPN instead of relying on PCs to provide the
VPN end-points) I'm interested. Thanks.


.



Relevant Pages

  • Re: Why use VPN?
    ... exposing your internal network to the internet. ... but doesn't a VPN box also require opening up a port to the ...
    (microsoft.public.windows.terminal_services)
  • Re: Clientless VPN (SSL VPN) vs HTTPS
    ... I tend to only read these lists, ... SSL contains ciphers and algorithms to securely authenticate, ... VPN in combination ... Company internal network is: 192.168.1.0/24 ...
    (Security-Basics)
  • Re: slightly off topic - flaws in using win2k for wireless security and openbsd replacing
    ... > Hi UNIX security professionals and hobbyists, ... > Basically, we have our wired internal network, then we have a dual-NIC ... > win2k server that acts as a Microsoft PPTP VPN server, ... > The problem I see is, anybody can connect to the wireless access point ...
    (comp.security.unix)
  • RE: VPNs - Firewalls and Security
    ... You had configured that vpn users access internal network, ... modify your PIX Config, you have configured "crypto map match ... = redesign my network to either firewall the VPN connections or at a = ...
    (Security-Basics)
  • Re: Best practices for internal/external servers
    ... >> the internal server as though they were on the internal network. ... >> (basically replace the dialup with VPN). ... On the other-hand poking holes through the firewall for IMAP access permits ...
    (comp.mail.imap)

Loading