Koldov Posted June 29, 2021 Posted June 29, 2021 (edited) So, this is just the basic RDP, not a server, not Azure or any other kind of gateway. Just for the internal network only, what settings do you need to secure this, I am happy to have one user from one IP only allowed. I have done various settings (finding out there are 2 places and other GPOs that affect it) along the way and just when I though I'd cracked it, find out I can still RDP in from outside... To me the Firewall setting is confusing and I don't seem to be able to limit it. Using a standard rule just seems to open up everything by default and using a customised rule doesn't open up enough or I don't really know what I'm allowing. I need to dig into what each option means and what not configuring them means (as sometimes that turns out in the rule to allow any): General - Allow the connection - is it secure - customise? Programs and Service Remote Computers - Only allow connections from these computers Protocols and ports Scope - Local IP address - Remote IP address (surely this is in Remote computers above!) Advanced - Profiles - Interface Types - Edge transversal Local Principals - Authorised users Remote Users - Authorized users Edited June 29, 2021 by Koldov
bald_pig Posted June 29, 2021 Posted June 29, 2021 Is there a reason you're using the advanced firewall settings, and not just allowing remote desktop in the basic settings?
Koldov Posted June 29, 2021 Author Posted June 29, 2021 Well, as RDP seems to be a mojor issue, I thought I would try to make it more secure. I'm doing this via GPO not in the control panel on an individual computer or wherever that menu is from. Is this the basic GPO?: Computer Configuration > Policies > Administrative Templates > Network > Network Connections > Windows Defender Firewall > Domain Profile > Allow inbound Remote Desktop exceptions Here I'd enable it and put in the IP of the only Computer I want to access it. But... that means if someone else logged on to that PC they would also have access (if they were an admin or elevated themselves as that's the only group that's allowed). Also with just that basic rule it seems to set: Profile = Domain (no Private or Public connections - which there shouldn't be but I've heard sometimes it might be possible to change this) Action = Allow the connection (no secure options) Program = Any Local Address = Any Remote Address = The one specified (why is it remote and not local?) Protocol = TCP Local Port = 3389 Remote Port = Any Authorised Users = Any Authorised Computers = Any Authorised Local Principals = Any Etc.. I thought the advanced option seemed like a way to make it more secure?
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now