RE: Remote Desktop, DMZ


Before placing the system in the DMZ, read about the DNS vulnerability
MS recently issued.

Microsoft Security Advisory (935964)
Vulnerability in RPC on Windows DNS Server Could Allow Remote Code


-----Original Message-----
From: listbounce@xxxxxxxxxxxxxxxxx [mailto:listbounce@xxxxxxxxxxxxxxxxx]
On Behalf Of Edmund
Sent: Tuesday, April 24, 2007 7:16 AM
To: security-basics@xxxxxxxxxxxxxxxxx
Subject: Remote Desktop, DMZ

Dear All,

A Remote-Desktop system should be placed within the DMZ,
am I correct?

If that is the case, what if the Remote Desktop
system requires access to an application server; but,
this application server cannot be placed in the DMZ
because LAN users also need access to it?

I've been mulling it over and haven't quite
figured out how or where to put this remote desktop system.
In the DMZ, it will have a hard time being
part of the domain(is this actually necessary?)
or even access an application server (which
is also part of the domain). If I put
the Remote desktop system in the internal LAN,
the risks are not particularly appealing should
the RD system get compromised.

Can someone out there give me some hints/pointers
as to how I might go about in putting a remote
desktop system in an existing network setting?