How to 'Harden' Remote Desktop

How to 'Harden' Remote Desktop

Secure Home | Search | About
 Microsoft Applications Security    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content add this group's latest topics to your Google content
Subject Author Date
How to 'Harden' Remote Desktop Courtney R 11-11-2005
Posted by =?Utf-8?B?Q291cnRuZXkgUg==?= on November 11, 2005, 4:05 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
We have several XP Pro Clients using Remote Desktop Client connecting to a
remote Windows 2000 Terminal Server.

What I'd like to do is specify who can connect, @ what time of day,
allowable IP addresses, better encryption, by MAC address, etc.

Anyone know of 3rd party software that will help me do this at low
cost/free. Already looked @ SecureRDP, not interested.

If anyone can help, greatly appreciate.

Thanks

Posted by Miha Pihler [MVP] on November 11, 2005, 4:19 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
Hi,

On Windows 2003 Server you can use TSL (SSL) for additional security and to
prevent MITM (Man In The Middle) attack.

How to configure a Windows Server 2003 terminal server to use TLS for server
authentication
http://support.microsoft.com/?id=895433

Encryption is already provided in Windows 2000 and Windows 2003 RDPs and you
can set different levels at server level...

Configuring authentication and encryption
http://www.microsoft.com/technet/prodtechnol/windowsserver2003/library/ServerHelp/a92d8eb9-f53d-4e86-ac9b-29fd6146977b.mspx

From where do these users access these Terminal Services? Only from LAN or
over the Internet? Note -- MAC filtering doesn't provide real security. MAC
address can be changed in about 5 seconds (not much better with IP address).
Even if you could enable MAC filters (or if they would provide any security)
you would limit Terminal Services to only those clients that would be on
same LAN as TS (but you can also use firewalls and/or IP policies to do
that).

- What you could do (and probably should do) is use policy settings on RDP
server to define which users have right to logon to the server over Terminal
Services

Allow log on through Terminal Services
http://www.microsoft.com/technet/prodtechnol/windowsserver2003/library/ServerHelp/83c29372-c6c5-4550-86ab-ebdbf120f9fa.mspx

- Use IP Policies (yes even on Windows 2000) to limit which IP addresses can
access Terminal Service. For additional security you can even enable IPSec
for additional encryption.

--
Mike
Microsoft MVP - Windows Security

> We have several XP Pro Clients using Remote Desktop Client connecting to a
> remote Windows 2000 Terminal Server.
>
> What I'd like to do is specify who can connect, @ what time of day,
> allowable IP addresses, better encryption, by MAC address, etc.
>
> Anyone know of 3rd party software that will help me do this at low
> cost/free. Already looked @ SecureRDP, not interested.
>
> If anyone can help, greatly appreciate.
>
> Thanks



Posted by karl levinson, mvp on November 12, 2005, 7:08 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
In addition to the other answers...

Check out the Windows 2000 Terminal Services hardening guide at
www.nsa.gov/snac

I'm not sure you really need to add any third party solution for what you
are asking... Windows TS is fairly secure, especially if you are using
Windows 2003 Server or have hardened the TS settings via the above document.
Considering that the data is both well encrypted AND is graphical data, it
is non-trivial to intercept that data and fairly unlikely that anyone would
do so.

If it is possible to use two-factor authentication and/or client and server
certificates from a Windows 2003 certificate server to authenticate the
identity of both, that may help gain additional security as well. I'm not
sure you really need that additional security, not sure what your
requirements and tolerance for risk are.


> We have several XP Pro Clients using Remote Desktop Client connecting to a
> remote Windows 2000 Terminal Server.
>
> What I'd like to do is specify who can connect, @ what time of day,
> allowable IP addresses, better encryption, by MAC address, etc.
>
> Anyone know of 3rd party software that will help me do this at low
> cost/free. Already looked @ SecureRDP, not interested.
>
> If anyone can help, greatly appreciate.
>
> Thanks



Similar ThreadsPosted
remote desktop web June 2, 2006, 1:37 pm
SSL and Remote Desktop March 11, 2008, 12:11 pm
Remote Desktop Connection June 13, 2005, 3:56 pm
Remote Desktop over VPN connection April 6, 2006, 4:42 pm
Remote Desktop Connection June 21, 2007, 11:32 pm
Remote Desktop on 2003 Domain August 18, 2005, 1:43 pm
Remote Desktop works but Assistance does not June 13, 2006, 12:37 pm
Remote Desktop and Terminal Services July 12, 2006, 7:12 pm
Remote Desktop Port Question April 9, 2007, 3:35 pm
Citrix, VPN, Remote Desktop and Wireless security November 18, 2005, 4:05 pm

The site map in XML format XML site map

Contact Us | Privacy Policy