RE: Internal access to remote external TS?

  • From: "Andrew English" <andrew@xxxxxxxxxxxxxxxxxxxxxx>
  • To: "[ISAserver.org Discussion List]" <isalist@xxxxxxxxxxxxx>
  • Date: Mon, 29 Nov 2004 23:36:57 -0500

I would suggest that you do not use port 3389 as your external port.
3389 is the first thing hackers look for when port hunting because TS is
easy to hack. When you select RDP (Term Services) Server click on ports
and then enable the firewall port publish and give it a value of 33000
or higher. This way when you RDP in from the internet into your box(es)
you just need to put a :33000 or whatever the port number is and your
in. :-)

 

Andrew

 

 

________________________________

From: Krisna Keo [mailto:krisnak@xxxxxxxxxxxxxxx] 
Sent: Monday, November 29, 2004 8:54 PM
To: [ISAserver.org Discussion List]
Subject: [isalist] RE: Internal access to remote external TS?

 

http://www.ISAserver.org



Hi Rajia,

Protocol rule:

Allow Terminal Services - OUT

        Description : 

        Enabled : True

        Action taken with requests : Allow

        Rule applies to : Selected Protocols

        Protocols : RDP (Terminal Services)

        Rule Applies to : Any Request

 

Protocol Definition:

RDP (Terminal Services)

        Description : Remote Desktop Protocol (Terminal Services)

        Initial Connection Port Number : 3389

        Initial Protocol Type : TCP

        Initial Direction : Outbound

Hope this will helps

Krisna

-----Original Message-----
From: Raji Arulambalam [mailto:RajiA@xxxxxxxxxxxxxx]
Sent: Tuesday, November 30, 2004 8:47 AM
To: [ISAserver.org Discussion List]
Subject: [isalist] Internal access to remote external TS?

http://www.ISAserver.org

Hi

Using ISA Server 2000, whats required to allow an internal client to
access a remote Terminal Services server.

The client has a FW client.

Thanks

RajiA

Email disclaimer: This email and any attachments are confidential. If
you are not the intended recipient, do not copy, disclose or use the
contents in any way. If you receive this message in error, please let us
know by return email and then destroy the message. Environment Bay of
Plenty is not responsible for any changes made to this message and/or
any attachments after sending.

******************************************************

This e-mail has been checked for viruses and no viruses were detected.

------------------------------------------------------

List Archives: http://www.webelists.com/cgi/lyris.pl?enter=isalist

ISA Server Newsletter: http://www.isaserver.org/pages/newsletter.asp

ISA Server FAQ: http://www.isaserver.org/pages/larticle.asp?type=FAQ

------------------------------------------------------

Other Internet Software Marketing Sites:

World of Windows Networking: http://www.windowsnetworking.com

Leading Network Software Directory: http://www.serverfiles.com

No.1 Exchange Server Resource Site: http://www.msexchange.org

Windows Security Resource Site: http://www.windowsecurity.com/

Network Security Library: http://www.secinf.net/

Windows 2000/NT Fax Solutions: http://www.ntfaxfaq.com

------------------------------------------------------

You are currently subscribed to this ISAserver.org Discussion List as:
krisnak@xxxxxxxxxxxxxxx

To unsubscribe visit http://www.webelists.com/cgi/lyris.pl?enter=isalist

Report abuse to listadmin@xxxxxxxxxxxxx

------------------------------------------------------
List Archives: http://www.webelists.com/cgi/lyris.pl?enter=isalist
ISA Server Newsletter: http://www.isaserver.org/pages/newsletter.asp
ISA Server FAQ: http://www.isaserver.org/pages/larticle.asp?type=FAQ
------------------------------------------------------
Other Internet Software Marketing Sites:
World of Windows Networking: http://www.windowsnetworking.com
Leading Network Software Directory: http://www.serverfiles.com
No.1 Exchange Server Resource Site: http://www.msexchange.org
Windows Security Resource Site: http://www.windowsecurity.com/
Network Security Library: http://www.secinf.net/
Windows 2000/NT Fax Solutions: http://www.ntfaxfaq.com
------------------------------------------------------
You are currently subscribed to this ISAserver.org Discussion List as:
andrew@xxxxxxxxxxxxxxxxxxxxxx
To unsubscribe visit http://www.webelists.com/cgi/lyris.pl?enter=isalist
Report abuse to listadmin@xxxxxxxxxxxxx 

Other related posts: