ReverentCreature Posted March 18, 2012 Posted March 18, 2012 Ive got Remote Desktop Services set up! At least it works via https://tsk-sr-001.tillskills.local/rdweb from inside the LAN but not from elsewhere on the Internet. I just get page cannot be displayed and suchlike instead! I think Ive successfully added TCP 3389 and 443 to the BT Router. I can see what I think is the servers public IP 86.149.1.141 and I can ping that from my home pc. So do I need to buy a domain for this to work? I mean how do I know that tsk-sr-001.tillskills.local doesnt exist elsewhere on the Internet?
pritchardavid Posted March 19, 2012 Posted March 19, 2012 Have you setup a gateway server?, if not, its best to.
ReverentCreature Posted March 19, 2012 Author Posted March 19, 2012 Hi there. Possibly not? Its a single server network. All of the RDS components as well as DNS and DHCP are on the one server. Is what youre referring to a setting, role or feature that I can set up on this server? There wil be less than five people using the RDS.
m25man Posted March 19, 2012 Posted March 19, 2012 I hope you have done your security homework, as now you have published your public IP internal server/domain name and the fact that Port 3389 is open to the world TSGrinder here we come... If you must use pure RDP over the web you had better know your stuff especially in the light of last weeks disclosure Microsoft Security Bulletin MS12-020 - Critical : Vulnerabilities in Remote Desktop Could Allow Remote Code Execution (2671387) Once your IP is on a trolls list it's a case of batten down the hatches and all hands to the pumps... 1
pritchardavid Posted March 19, 2012 Posted March 19, 2012 (edited) This is the link you require without a public DNS name. You will need to buy one if you wan a DNS name instead of a IP address which is cheap. tsk-sr-001.tillskills.local - You will not be able to use externall because this is not a vaild external DNS name, yor need oneending with something like .com or co.uk .net etc https://86.149.1.141/RDWeb/ I checked the link, it is working! Edited March 19, 2012 by pritchardavid 1
ReverentCreature Posted March 20, 2012 Author Posted March 20, 2012 If you must use pure RDP over the web you had better know your stuff especially in the light of last weeks disclosure Microsoft Security Bulletin MS12-020 - Critical : Vulnerabilities in Remote Desktop Could Allow Remote Code Execution (2671387) Once your IP is on a trolls list it's a case of batten down the hatches and all hands to the pumps... Thanks for the heads up Geoff! That update should come in automatically as automatic updates is on, correct? I think I need to brush up on my security homework yes. Ive always worked at an RM school so I put on the updates they send out and havent had to deal with updates myself before!
Michael Posted March 20, 2012 Posted March 20, 2012 This is why VPN solutions are better and more secure. Alternatively, you can change the port 3389 to something else. And as above, you should install that update immediately! This is why WSUS is useful as the million and one workstations I manage automatically receive the update and it reports back too.
jamesfed Posted March 20, 2012 Posted March 20, 2012 You should get your LEA/whoever looks after your DNS to point a host recoard (e.g. rds.company.co.uk or rds.schoolname.leaname.sch.uk) at your IP address - make sure your certificates on your server have been setup to accept requests on that DNS name as well. So basicly you shouldn't be using a .local DNS name Following on from what others have said you should look at putting your RDS server behind TMG/UAG for security.
ReverentCreature Posted March 21, 2012 Author Posted March 21, 2012 Thanks guys. RDS comes with a RD Gateway. Is the TS_CAP and TS_RAP that Ive created not enough security?
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now