Jump to content

Recommended Posts

Posted

Hi,

 

Just looking into RDP / RemoteApp for SLT initially. Are there any Link2ICT schools using this? and was it straightforward to setup?

 

Thanks

  • 4 weeks later...
Posted

They won't do it. Unless you push it through something like Forefront TMG over port 443.

 

They refuse to open anything on port 3389 even with a change request signed by the Head.

Posted
Hi,

 

Just looking into RDP / RemoteApp for SLT initially. Are there any Link2ICT schools using this? and was it straightforward to setup?

 

Thanks

 

Put in a Remote Desktop Gateway for the external bit it only needs 443 and has an SSL Cert on it and then you can push Remote App or direct Remote Desktop through it, we use it in our firm and its great nice and simple and our security team are happy as larry with it :) Works on PC, Mac, Apple, Android and Windows Phone :)

Guest obsidianpillar
Posted
Put in a Remote Desktop Gateway for the external bit it only needs 443 and has an SSL Cert on it and then you can push Remote App or direct Remote Desktop through it, we use it in our firm and its great nice and simple and our security team are happy as larry with it :) Works on PC, Mac, Apple, Android and Windows Phone :)

 

Do you put yours in a DMZ, or just open up the port? I normally put mine in a DMZ, however have a new client that only has 5 members of staff, and not very many hits to their main site. I'm looking at if it's worth it by just opening up the port to the gateway. Doing so removes the need for a RODC etc which is one less server to patch.

 

Interested to hear your thoughts.

Tom

Posted

Opening RDP to the public is a very bad idea, as it means anyone could then 'attempt' to sign into your server.

 

One option is to look at setting up a VM and configuring it for VPN. It's something I've looked at before, but haven't had the time to do it properly. Link2ICT will then route all VPN requests to your VM for example, instead of requiring the Cisco VPN client, which clearly doesn't work on Windows 10.

 

VPN of some form is always going to be better/more secure than RDP (in the context of accessing services remotely).

  • Thanks 1
Posted

When I had to suffer using BGFL VPN I used a program called Shrewsoft VPN that used the PCF file used by Cisco and connected just fine.

 

Might be worth a look.

  • Thanks 1
Posted (edited)
Do you put yours in a DMZ, or just open up the port? I normally put mine in a DMZ, however have a new client that only has 5 members of staff, and not very many hits to their main site. I'm looking at if it's worth it by just opening up the port to the gateway. Doing so removes the need for a RODC etc which is one less server to patch.

 

Interested to hear your thoughts.

Tom

 

Its in the normal network published by a reverse proxy solution. You could probably DMZ it if you like

Edited by ZeroHour

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...