Re: Remote Management

Tech Tip: Click here to run a free scan for Windows Errors and optimize PC performance



Hello,

Thank you for your response.



Is the communciation over 3389 secure?



Please can you recommend couple of firewalls which provide external
authentication.



Thanks

"Leythos" <Void@xxxxxxxxxxx> wrote in message
news:1178843472_5957@xxxxxxxxxxxxxxxxxxxxxxx
On Thu, 10 May 2007 23:16:25 +0000, sajmo wrote:

Hello

I manage a remote windows SBS 2003 server; I have enabled TS in admin
mode. I remote on to the server using the default port TS port 3389 over
the internet. My question is this secure.

I design secure networks for state, military, and private companies - I
never directly expose 3389 to the internet.

If you want to allow RD into the Terminal Server, setup your firewall to
authenticate the user first, then allow authenticated users access to
3389. This means you can use non-AD user/passwords to auth the users, and
we don't allow their firewall user/password to match their AD user/
password.


--
Leythos
Igitur qui desiderat pacem, praeparet bellum.
Calling an illegal alien an "undocumented worker" is like calling
a drug dealer an "unlicensed pharmacist"
spam999free@xxxxxxxxxx (remove 999 for proper email address)


.



Relevant Pages

  • Re: Outlook using RPC over HTTPS does not authenticate using the Kerberos Realm
    ... Used Outlook in Safe Mode, ... For testing, client and server are on the same network, so no proxy server. ... Please first select "Integrated Windows Authentication" on the PRC virtual ... Disable firewall or antivirus on PC, ...
    (microsoft.public.exchange.admin)
  • Re: Firewall - Limit Geographic Area
    ... Firewall - Limit Geographic Area ... > times more secure than a Microsoft Windows machine can be). ... Redhat is conservative about what they release ... > - do not reuse passwords between your server and, say, random ...
    (RedHat)
  • Re: Forms authentication - change password
    ... Contact the server administrator. ... I think your authentication validation method needs to be set to Windows ... the change password feature within ISA ... FBA is only supported using Secure LDAP. ...
    (microsoft.public.isa)
  • Re: Forms authentication - change password
    ... Did you enter a set of domain credentials for the LDAP server set? ... I think your authentication validation method needs to be set to Windows ... the change password feature within ISA ... FBA is only supported using Secure LDAP. ...
    (microsoft.public.isa)
  • RE: Securing a Terminal Services user
    ... Add these users to a group and implicitly deny this group access to any ... applications, i.e. Citrix Secure Gateway, Web Interface & publish the exact ... I am setting up a TS server inside my firewall. ...
    (microsoft.public.windows.terminal_services)