Re: How can I prevent a TS user from TS or RDP to another server?

From: Miha Pihler (mihap-news_at_atlantis.si)
Date: 07/29/04


Date: Thu, 29 Jul 2004 23:12:50 +0200

Hi,

I am not sure how many (TS) servers you have and how practical this is for
you, but you can do this by managing permissions "Allow logon through
Terminal Services". This is a group policy setting. You can also open
"Terminal Services Configuration" right click on RDP-TCP and select
Properties. Click on Security tab and assign your "guest" user Deny
permission.

Last option that comes to mind -- again I don't know how convenient this is
for you. Setup your TS server in DMZ and deny access from DMZ to LAN on TS
TCP port (TCP port 3389).

I hope this helps,

Mike

"GX" <GX@DOMAIN.com> wrote in message
news:9CdOc.333$Hu2.108@tornado.tampabay.rr.com...
> Big Picture
>
> How can I prevent a TS user from TS or RDP to another server?
>
>
>
> Scenario:
>
> Users (Vendors) log into my organization via VPN. They are setup on the
VPN
> under a group which has only access to one machine and back via RDP. (i.e.
> Microsoft Group has access to the Microsoft Server Box, now we setup John
on
> the Microsoft group and he has only RDP access to the Win2KSVR). In order
> for them to get into the Win2KSVR they are also setup on the network as
jdoe
> (Domain Admins) and that's the way he log into the Win2KSVR.
>
>
>
> Concern:
>
> John VPN into organization and RDP to Win2KSVR did what he needed to do
and
> opened the network neighborhood and saw all the servers we have. Now he
> wants to browse and log into the boxes he has no need in loging in.
>
>
>
> Question:
>
> How can I prevent a user from login into another machine via TS or RDP
when
> they are login into a machine via TS or RDP?
>
>



Relevant Pages

  • RDP to internal client machine?
    ... Have the router successfully setup to allow VPN to the server, ... to then RDP to other computers within the network, ... machines within the network I ...
    (microsoft.public.windows.server.sbs)
  • RE: Windows Remote Desktop
    ... between the server and client in addition to RDP encryption. ... On the topic of securing RDP i was wondering if anyone can help.... ... connection is difficult. ... >We provide Ethical Hacking, Advanced Ethical Hacking, Intrusion ...
    (Security-Basics)
  • RE: Windows Remote Desktop
    ... clients and match your server configuration to match the target server ... Https would not be subject to a MiM attack using the method I described. ... Citrix can be more secure then RDP. ... >We provide Ethical Hacking, Advanced Ethical Hacking, Intrusion ...
    (Security-Basics)
  • RE: Windows Remote Desktop
    ... This step confirms that the server is ... Subject: Windows Remote Desktop ... Citrix can be more secure then RDP. ... >We provide Ethical Hacking, Advanced Ethical Hacking, Intrusion ...
    (Security-Basics)
  • RE: Windows Remote Desktop
    ... On the topic of securing RDP i was wondering if anyone can help.... ... If you get a hold of the certificate the server presents to the ... SSL/HTTPS then use the Citrix ICA encryption on top of that, ... >We provide Ethical Hacking, Advanced Ethical Hacking, Intrusion ...
    (Security-Basics)