Windows Server 2000/2003 Thread, Securing Windows server 2003 Remote Desktop access for access through the internet in Technical; I will no longer authorise RDP into Northants schools and over the next 12 months will be asking schools to ...
-
19th August 2009, 12:32 PM #16 I will no longer authorise RDP into Northants schools and over the next 12 months will be asking schools to move to a more secure remote setup.
It is open to attack as previously mentioned and it is scary the number of people that have set it up on their MIS to allow for SLT to access the MIS at home in *clear* breach of the DPA!
Seriously folks ... it is not secure, go for a decent VPN solution or other alternatives such as Sun Secure Global Desktop or Citrix ... both over HTTPS with a valid certificate.
-
-
IDG Tech News
-
19th August 2009, 01:15 PM #17
- Rep Power
- 9
aaaahhhhhh... >_< that is soo scary...
anyway using OpenVPN or anything with two factor authentication such as RSA SecurID is the secure way to do it but yes we will have to invest anyway ;-|
-
-
19th August 2009, 06:00 PM #18 Or use TSGateway over HTTPS which comes built in to Server 2008 which also gives added security.
Last edited by SYNACK; 19th August 2009 at 07:41 PM.
-
Thanks to SYNACK from:
albertwt (20th August 2009)
-
19th August 2009, 11:21 PM #19 Do any of the RDP MITMs people have in mind actually work if you turn on server TLS authentication (something you've had an opportunity to do for years now)?
The problem for RBCs/whatever is that you can't rely on people to configure these features, or have genuinely strong passwords etc. , so they're pretty much forced to mandate VPNs.
I expect the 2K8 [2k8R2]+ TS[RD] stuff over TLS will get people more in the security groove though... and I'm definitely prepared to argue the case for that vs. splashing out what can often be a *lot* of money on commercial VPNs.
Last edited by PiqueABoo; 19th August 2009 at 11:24 PM.
-
Thanks to PiqueABoo from:
albertwt (20th August 2009)
-
20th August 2009, 12:29 AM #20
- Rep Power
- 9
Yes, I agree with using the existing Windows features (2003/2008) ratherthan getting additional VPN connection with 3rd party.
So in this case I shall try to deploy Windows Essential Business Server 2008 Standard Security server as they are equipped with FireFront Threat management and also this edition of Windows Server does not need to be member of Active Directory.
-
-
20th August 2009, 09:40 PM #21
I agree with using the existing Windows features (2003/2008) ratherthan getting additional VPN connection with 3rd party.
That's the spirit.
No one's answered the question yet, so after a very quick google I found this Configuring Terminal Servers for Server Authentication to Prevent “Man in the Middle” Attacks. Not necessarily the last word, but it's recent-ish and item 2b (pointing to KB895433) is the 2K3 update I had in mind.
And again with 2K8 you just run RDP over TLS with all that security stuff to play with. The only downside, as ever, is the client boxes: If they're "yours", locked down and configured nicely before they get home it's not too bad, otherwise..
-
SHARE: 
Similar Threads
-
By Grommit in forum Windows
Replies: 8
Last Post: 28th July 2011, 11:32 PM
-
By Asif in forum Network and Classroom Management
Replies: 15
Last Post: 5th September 2009, 08:56 PM
-
By ltunstall in forum Windows
Replies: 7
Last Post: 14th April 2008, 10:45 AM
-
By deepusurana in forum Windows
Replies: 19
Last Post: 12th October 2007, 09:39 AM
-
Replies: 15
Last Post: 2nd May 2007, 05:38 PM
Thread Information
Users Browsing this Thread
There are currently 1 users browsing this thread. (0 members and 1 guests)
Tags for this Thread
Posting Permissions
- You may not post new threads
- You may not post replies
- You may not post attachments
- You may not edit your posts
-
Forum Rules