Jump to content

Recommended Posts

Posted (edited)

So, this is just the basic RDP, not a server, not Azure or any other kind of gateway.

 

Just for the internal network only, what settings do you need to secure this, I am happy to have one user from one IP only allowed.

 

I have done various settings (finding out there are 2 places and other GPOs that affect it) along the way and just when I though I'd cracked it, find out I can still RDP in from outside...

 

To me the Firewall setting is confusing and I don't seem to be able to limit it. Using a standard rule just seems to open up everything by default and using a customised rule doesn't open up enough or I don't really know what I'm allowing.

 

RDP.JPG

 

I need to dig into what each option means and what not configuring them means (as sometimes that turns out in the rule to allow any):

 

General - Allow the connection - is it secure - customise?

Programs and Service

Remote Computers - Only allow connections from these computers

Protocols and ports

Scope - Local IP address - Remote IP address (surely this is in Remote computers above!)

Advanced - Profiles - Interface Types - Edge transversal

Local Principals - Authorised users

Remote Users - Authorized users

Edited by Koldov
Posted

Well, as RDP seems to be a mojor issue, I thought I would try to make it more secure.

 

I'm doing this via GPO not in the control panel on an individual computer or wherever that menu is from.

 

Is this the basic GPO?:

 

Computer Configuration > Policies > Administrative Templates > Network > Network Connections > Windows Defender Firewall > Domain Profile > Allow inbound Remote Desktop exceptions

 

Here I'd enable it and put in the IP of the only Computer I want to access it.

 

But... that means if someone else logged on to that PC they would also have access (if they were an admin or elevated themselves as that's the only group that's allowed).

 

Also with just that basic rule it seems to set:

 

Profile = Domain (no Private or Public connections - which there shouldn't be but I've heard sometimes it might be possible to change this)

Action = Allow the connection (no secure options)

Program = Any

Local Address = Any

Remote Address = The one specified (why is it remote and not local?)

Protocol = TCP

Local Port = 3389

Remote Port = Any

Authorised Users = Any

Authorised Computers = Any

Authorised Local Principals = Any

 

Etc..

 

I thought the advanced option seemed like a way to make it more secure?

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...