Jump to content

Recommended Posts

Posted
Ive got Remote Desktop Services set up! At least it works via https://tsk-sr-001.tillskills.local/rdweb from inside the LAN but not from elsewhere on the Internet. I just get page cannot be displayed and suchlike instead! I think Ive successfully added TCP 3389 and 443 to the BT Router. I can see what I think is the servers public IP 86.149.1.141 and I can ping that from my home pc. So do I need to buy a domain for this to work? I mean how do I know that tsk-sr-001.tillskills.local doesnt exist elsewhere on the Internet?
Posted
Hi there. Possibly not? Its a single server network. All of the RDS components as well as DNS and DHCP are on the one server. Is what youre referring to a setting, role or feature that I can set up on this server? There wil be less than five people using the RDS.
Posted

I hope you have done your security homework, as now you have published your public IP internal server/domain name and the fact that Port 3389 is open to the world :eek:

TSGrinder here we come...

 

If you must use pure RDP over the web you had better know your stuff especially in the light of last weeks disclosure Microsoft Security Bulletin MS12-020 - Critical : Vulnerabilities in Remote Desktop Could Allow Remote Code Execution (2671387)

Once your IP is on a trolls list it's a case of batten down the hatches and all hands to the pumps...

  • Thanks 1
Posted (edited)

This is the link you require without a public DNS name. You will need to buy one if you wan a DNS name instead of a IP address which is cheap.

 

tsk-sr-001.tillskills.local - You will not be able to use externall because this is not a vaild external DNS name, yor need oneending with something like .com or co.uk .net etc

 

https://86.149.1.141/RDWeb/

 

I checked the link, it is working!

Edited by pritchardavid
  • Thanks 1
Posted
If you must use pure RDP over the web you had better know your stuff especially in the light of last weeks disclosure Microsoft Security Bulletin MS12-020 - Critical : Vulnerabilities in Remote Desktop Could Allow Remote Code Execution (2671387) Once your IP is on a trolls list it's a case of batten down the hatches and all hands to the pumps...

 

Thanks for the heads up Geoff! That update should come in automatically as automatic updates is on, correct? I think I need to brush up on my security homework yes. Ive always worked at an RM school so I put on the updates they send out and havent had to deal with updates myself before!

Posted

This is why VPN solutions are better and more secure. Alternatively, you can change the port 3389 to something else.

 

And as above, you should install that update immediately! This is why WSUS is useful as the million and one workstations I manage automatically receive the update and it reports back too.

Posted

You should get your LEA/whoever looks after your DNS to point a host recoard (e.g. rds.company.co.uk or rds.schoolname.leaname.sch.uk) at your IP address - make sure your certificates on your server have been setup to accept requests on that DNS name as well.

 

So basicly you shouldn't be using a .local DNS name :)

 

Following on from what others have said you should look at putting your RDS server behind TMG/UAG for security.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...