FAQFAQ   SearchSearch      ProfileProfile    Private MessagesPrivate Messages   Log in/Register/PasswordLog in/Register/Password

Terminal Server secure implementation

 
   Windows (Home) -> Security RSS
Related Topics:
Vista logon with smart card - How do I configure Vista to allow me logon to my home computer using a DoD issued smart card. It is currently used to access my DoD e-mail and for and has the ability to logon to DoD owned systems & networks. The card..

Voice recognition and security - I am presently to the degree that I can't use a keyboard or mouse so Windows Vista voice of the godsend. It works really well in most however whenever it security alert occurs it appears to override voice..

Registering REG Files - Can someone please on how to Register REG Files using things like for all users on a Standard User Computer ? The problem, i guess, lies with the of the registry -- Or Tsemah YSIDE

Restarting a Windows Service with C# under Vista when User.. - Hello! I need to restart the Audio via C#. I'm using the Class to do this. It is no problem under XP and no problem under vista if UAC is disabled. But with enabled UAC i'm getting a

Host Error on Bootup - Father inlaw is running Vista Home Premium 64. He gets this error upon booting. Where do I start? Where do I find this error and how do I fix it? [image: Thanks to everyone. Great forums..
Next:  Security: Encrypting offline files  
Author Message
juanp

External


Since: Aug 10, 2007
Posts: 3



(Msg. 1) Posted: Fri Aug 10, 2007 1:13 am
Post subject: Terminal Server secure implementation
Archived from groups: microsoft>public>windows>vista>security (more info?)

Hi all,

I want to install Terminal server in the lan so Users
can log in from home and connect to there pc's.

I need to implement a secure way so I read that TS
will encrypt all the traffic between the client and
server with RCA Rc4 and a key of 128 bit so Its a vpn.
why many companies first installed a vpn client on the
custumers pc to connect to a cisco pix and then after
ther connection is established they open up terminal
client and connect to the terminal server.

I dont see the benefits of encrypting twice the data..
I thing that using just the Ts encryption is enough to
establish a vpn over the internet also changing the
default 3389 port and puting the TS server in the dmz.

Am I wrong?

Thanks,

Juan
Back to top
Login to vote
Steve Riley [MSFT]

External


Since: Aug 28, 2007
Posts: 6



(Msg. 2) Posted: Wed Aug 15, 2007 5:55 am
Post subject: Re: Terminal Server secure implementation [Login to view extended thread Info.]
Archived from groups: per prev. post (more info?)

No, TS over the Internet isn't a VPN. It is, however, one of several forms
of remote access to information on your network.

TS over the Internet is perfectly acceptable, provided that you secure it
correctly. By default, RDP authenticates the client to the server, but
doesn't authenticate the server to the client. To avoid the potential for a
man-in-the-middle attack, you need to enable mutual authentication.

This requires Windows Server 2003 SP 1 configured to use TLS for server
authentication and data encryption, RDP 5.2 on the clients, and some other
prerequisites. See http://support.microsoft.com/?id=895433 for more details.

Steve Riley
steve.riley RemoveThis @microsoft.com
http://blogs.technet.com/steriley


"juanp" <juanbabi RemoveThis @gmail.com> wrote in message
news:1186708413.635579.88000@j4g2000prf.googlegroups.com...
> Hi all,
>
> I want to install Terminal server in the lan so Users
> can log in from home and connect to there pc's.
>
> I need to implement a secure way so I read that TS
> will encrypt all the traffic between the client and
> server with RCA Rc4 and a key of 128 bit so Its a vpn.
> why many companies first installed a vpn client on the
> custumers pc to connect to a cisco pix and then after
> ther connection is established they open up terminal
> client and connect to the terminal server.
>
> I dont see the benefits of encrypting twice the data..
> I thing that using just the Ts encryption is enough to
> establish a vpn over the internet also changing the
> default 3389 port and puting the TS server in the dmz.
>
> Am I wrong?
>
> Thanks,
>
> Juan
>
Back to top
Login to vote
Display posts from previous:   
       Windows (Home) -> Security All times are: Eastern Time (US & Canada) (change)
Page 1 of 1

 
You can post new topics in this forum
You can reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
Categories:
  Windows Forums
 Game Forums
 Linux Forums
 Mac Forums
 PDA Forums
 Mobile Forums
  Top  |  Store  |  RSS Feeds RSS  |  Data Feeds  |  Advertise  |  Submit  |  Bookmark  |  Newsletter  |  Contact