Re: Remote desktop over vpn




"Jeff B" <jbeardNo-Spam1185@xxxxxxxxxxxx> wrote in message
news:Q7adnTBdjf_i3gLenZ2dnUVZ_tydnZ2d@xxxxxxxxxxxxxxx
> >Yes, but in most cases people posting to this group don't have their
> >firewall setup to restrict at the port/service level. I suspect that VNC
> >would work just fine.
> >
> >90% of people, when configuring a VPN, configure it wide open, all ports
> >and protocols.
>
> Can you define ASSUME? Murphy will bite the user and the enterprise that
> is silly enoungh to do either!
>
> Even Joe XP/Home edition users are implementing deny all/all, so lot's of
> luck.
>
> --
> ---
> Jeff B (remove the No-Spam to reply)

Jeff, how many corporate VPN's have you had experience with?

The suggestion that 90% of people configure a VPN wide open is, in my
*experience* approximately correct. Perhaps 10 to 20 percent high, but no
more.

One of the first things we typically address when consulted.

The reason is that they use the tunnel to run a workstation from remote as
if it were on the LAN. Have you ever tried to enumerate all the ports and
protocols required for a typical corporate workstation to do a domain log
in, run exchange, read file shares, print, hit a few client/server
applications, and allow the centrally managed coprorate update/virus/support
tools? Once you open that much stuff up, you may as well open up the rest
because your behind is hanging out so far anyway on so many interesting
services...

-Russ.


.



Relevant Pages

  • RE: P2P applications scanning? Trojan? Malicious users?
    ... Hi Jeff, Hi all... ... > and programmatically switched off infected ports. ... > However, as a side effect of the tarpit, now that things are settling ... > pinpoint or google a clue. ...
    (Incidents)
  • Re: Public DNS names for SBS 2K3 - Question
    ... Jeff. ... "Dave Hibbeln" wrote in message ... > In what document did you find these recommendations for DNS names. ... >> you're using, if you are using standard ports, the port is ...
    (microsoft.public.windows.server.sbs)
  • Re: Ports 1985 and 1986
    ... I havent seen any other connects to those ports since I first posted ... Jeff Lane wrote: ... > Unfortunately, I am a linux admin, not a windows admin, so I am not ... Thinking About Security Training? ...
    (Security-Basics)
  • Re: VPN Setup
    ... "Jeff G" wrote: ... > So do I have to open any ports on the RRAS server? ... > I cannot ping the RRAS server from the Internet either by IP or name. ...
    (microsoft.public.windows.server.networking)
  • Re: FreeBSD 5.0 Ports collection?
    ... > Hi Jeff, ... >>code for the ports on a CD and install from a CD? ... >>Jeff D. Hamann ...
    (comp.unix.bsd.freebsd.misc)