Re: Limit the Remote desktop connection

Tech Tip: Click here to run a free scan for Windows Errors and optimize PC performance



Dear TP

Your IP Sec Policy is better i think as we can customize on our own. Thanks
for your response. I will get back once i try that..

:-)
Chandra

TP wrote:
Hi Chandra,

There are multiple ways to accomplish this. Here are
a few:

1.) Use Window Firewall (free)

Create/Edit Exception for Remote Desktop, change
the scope to Custom List, and enter your local subnet.
Open Control Panel and launch Windows Firewall to
configure. You will also need to create exceptions
for other traffic, for example File and Printer Sharing
for the local subnet as well.

2.) Use IP Security (free)

Create an IP Security policy that only permits your
local ip subnet to connect via RDP (tcp port 3389 by
default). IP Security policies are created/edited using
the IP Security Policy Management mmc snapin.

Take a look here for a video clip that walks you
through the setup:

http://tshelp.bravehost.com/demos/ipsec_rdp.html

The clip demonstrates how to permit only a specific
ip address to connect to the server. In your case you
will need to choose "A specific IP Subnet" for the
RDP_Permit filter and enter your local ip subnet.

3.) Use an external firewall device ($)

In most cases people protect their servers from
the Internet by placing them behind a firewall device.
If they do not want someone to access TS from the
Internet, then they block RDP traffic at the firewall.

Please let me know if you have any questions.

Thanks.

-TP

HI all,

[quoted text clipped - 11 lines]
Thanks in advance
Chandra

--
chandra

Message posted via WinServerKB.com
http://www.winserverkb.com/Uwe/Forums.aspx/windows-ts/200612/1

.



Relevant Pages

  • Re: [fw-wiz] Security and Audit Policy
    ... Enabling firewall rules without a solid security policy and management ... nameserver (I don't like clients resolving directly in any circumstance.) ...
    (Firewall-Wizards)
  • Re: I need help creating forest trusts
    ... These DC's are behind the same firewall and they're on the same ... > subnet so all the traffic is unfiltered. ... Is there a security policy defined on DomainA preventing communication? ... Prev by Date: ...
    (microsoft.public.win2000.active_directory)
  • Re: [fw-wiz] httport 3snf
    ... > Having worked in the Firewall support role at several companies, ... I had my CIO approve my security policy. ... time educating him about Internet risk. ... There's also a very good "at what point is the firewall now useless" ...
    (Firewall-Wizards)
  • RE: Sandboxing
    ... the 3Com Embedded Firewall would be extremely useful and enabling (in ... your case) when you look at it in a VPN context. ... This security policy will accomplish quite a few things: ... During the Policy Server installation, ...
    (Focus-IDS)
  • Re: Folder Redirection
    ... correct once it is moved to the new subnet. ... Logon Optimization is turned off in policy. ... 305293 Description of the Windows XP Professional Fast Logon Optimization ...
    (microsoft.public.windows.group_policy)