Windows Vista Tips

Windows Vista Tips > Newsgroups > Windows Vista Security > Terminal Server secure implementation

Reply
Thread Tools Display Modes

Terminal Server secure implementation

 
 
juanp
Guest
Posts: n/a

 
      08-10-2007
Hi all,

I want to install Terminal server in the lan so Users
can log in from home and connect to there pc's.

I need to implement a secure way so I read that TS
will encrypt all the traffic between the client and
server with RCA Rc4 and a key of 128 bit so Its a vpn.
why many companies first installed a vpn client on the
custumers pc to connect to a cisco pix and then after
ther connection is established they open up terminal
client and connect to the terminal server.

I dont see the benefits of encrypting twice the data..
I thing that using just the Ts encryption is enough to
establish a vpn over the internet also changing the
default 3389 port and puting the TS server in the dmz.

Am I wrong?

Thanks,

Juan

 
Reply With Quote
 
 
 
 
Steve Riley [MSFT]
Guest
Posts: n/a

 
      08-15-2007
No, TS over the Internet isn't a VPN. It is, however, one of several forms
of remote access to information on your network.

TS over the Internet is perfectly acceptable, provided that you secure it
correctly. By default, RDP authenticates the client to the server, but
doesn't authenticate the server to the client. To avoid the potential for a
man-in-the-middle attack, you need to enable mutual authentication.

This requires Windows Server 2003 SP 1 configured to use TLS for server
authentication and data encryption, RDP 5.2 on the clients, and some other
prerequisites. See http://support.microsoft.com/?id=895433 for more details.

Steve Riley

http://blogs.technet.com/steriley


"juanp" <> wrote in message
news: ps.com...
> Hi all,
>
> I want to install Terminal server in the lan so Users
> can log in from home and connect to there pc's.
>
> I need to implement a secure way so I read that TS
> will encrypt all the traffic between the client and
> server with RCA Rc4 and a key of 128 bit so Its a vpn.
> why many companies first installed a vpn client on the
> custumers pc to connect to a cisco pix and then after
> ther connection is established they open up terminal
> client and connect to the terminal server.
>
> I dont see the benefits of encrypting twice the data..
> I thing that using just the Ts encryption is enough to
> establish a vpn over the internet also changing the
> default 3389 port and puting the TS server in the dmz.
>
> Am I wrong?
>
> Thanks,
>
> Juan
>

 
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
Terminal Server Licensing error Gretchen Hembree Windows Vista General Discussion 6 07-16-2008 03:34 AM
remote desktop connection to my terminal server Kees Brussen Windows Vista General Discussion 1 02-20-2008 09:54 PM
Vista and Terminal Server 2003 SP2 Kevin Marshall Windows Vista Networking 2 01-15-2008 02:39 PM
Terminal Server in Vista Home? Chufty Windows Vista Networking 2 03-01-2007 12:00 PM
Is Vista a Terminal Server ? Rafa J. Windows Vista General Discussion 4 03-17-2006 09:56 PM



1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59