Solved

Router question

Posted on 2003-10-22
7
677 Views
Last Modified: 2010-04-09
We have a Linksys router.

In order to connect to our desktop machines remotely, we're supposed to "enable remote management" on our router.

Is this a security risk if we leave it enabled?
0
Comment
Question by:skbohler
  • 3
  • 2
  • 2
7 Comments
 
LVL 2

Accepted Solution

by:
sh00t3r earned 125 total points
ID: 9601927
Ok let's find out exactly what needs to be done....

When you "enable remote management" all your doing is allowing users on the internet to directly connect and manage your linksys router given the right credentials. This doesn't give them direct access to your desktop machines on the Local Area Network.

Depending on what type of communication to the desktops are required will determine how you configure your linksys router. If you need to directly connect to these desktop machines I would suggest setting up some type of VPN (virtual private network). Your linksys may or may not support VPN. Shoot me over the model number and I can let you know. Otherwise you will have to setup port forwarding to the designated machines. Your best bet with security in mind is to setup a VPN.

Is it a security risk to enable remote managment? Yes. You must set a very very strong password. Don't use the default of "admin". Your router will get hacked quicker then you can say blackhat.
0
 
LVL 2

Expert Comment

by:sh00t3r
ID: 9601952
Questions:

1. Who needs access to these desktop machines?
2. What type of access do they need? Will they just need access to files? Or will they need to see the entire computer to run applications and such (Terminal Services)?
3. What type of Internet Connection do you have? DSL/Cable, T1, etc.?
4. Model of your Linksys Router


0
 

Author Comment

by:skbohler
ID: 9604062
The people who need access are the users of the office computers who want to access the whole computer from home. They want to see the entire computer via MS Remote Desktop Connection. They each have a DSL/Cable connection.

My router model is BEFSR41

Thanks!

Steve
0
Threat Intelligence Starter Resources

Integrating threat intelligence can be challenging, and not all companies are ready. These resources can help you build awareness and prepare for defense.

 
LVL 4

Expert Comment

by:ferg-o
ID: 9604835

Um - yep sh00t3r is right - remote management on the Linksys is just what it says and if you don't need it I would disable it immediately. At the very least change the port it uses to something slightly more obscure than 8080.

First I will make the assumption that the router is runing dynamic NAT meaning that you have hidden addresses behind it and one valid address on the outside. In this case you will have to enable port forwarding for TCP 3389 from outside to the IP address of the machine on the inside that you want access to.

You can only do this for one machine. The user will then connect via remote desktop to the IP address of the firewall and that will forward them to their machine. The limitation is one IP per TCP port.

If you want other machines to have access then you will either have to make their machines listen on a different TCP port to the default and change the TCP port that they use remote desktop from home with.

Instructions for changing these for terminal services are here:

http://support.microsoft.com/default.aspx?scid=187623

I could not find a way to do this with XP but may help to get you started. This way each remote desktop client can connect to each machine inside the firewall using an individual TCP port.

HOWEVER! This opens up all the inside machines to terminal services from everywhere on the Internet. I suggest you use VPN if you can...


0
 
LVL 2

Expert Comment

by:sh00t3r
ID: 9611226
Depending on your ISP you may have a useable public ip range. For instance most cable/dsl ISP's for small business will usually include 5 static ips. Then you can redirect the traffic from each one of these static "public" ip's towards the internal clients. So in essence you could get 5 for 5, kinda like arby's. 5 internal computers can get access by 5 outside users. More outside users would be able to access these computers if you had legitimate terminal services server but your probably using XP.

So a couple more questions...

1. Does your ISP give you more then 1 static IP?
2. Operating Systems of PCs
3. How many people need access to their computers?

If it's over 5 users you will want to think about other remote applications. Such as citrix. Citrix would provide all the functionality you need. Or a legitimate version of terminal services server.
0
 

Author Comment

by:skbohler
ID: 10044507
Is setting up a VPN pretty complicated?
0
 
LVL 4

Expert Comment

by:ferg-o
ID: 10048843

Not if you have Linksys routers/firewalls at home. Then it is really simple. If this is not an option then you will need some VPN client software. Unfortunately I do not know of a good client for connecting to Linksys machines - someone else reading might...
0

Featured Post

What Is Threat Intelligence?

Threat intelligence is often discussed, but rarely understood. Starting with a precise definition, along with clear business goals, is essential.

Join & Write a Comment

Suggested Solutions

Wikipedia defines 'Script Kiddies' in this informal way: "In hacker culture, a script kiddie, occasionally script bunny, skiddie, script kitty, script-running juvenile (SRJ), or similar, is a derogatory term used to describe those who use scripts or…
If you are like regular user of computer nowadays, a good bet that your home computer is on right now, all exposed to world of Internet to be exploited by somebody you do not know and you never will. Internet security issues has been getting worse d…
Access reports are powerful and flexible. Learn how to create a query and then a grouped report using the wizard. Modify the report design after the wizard is done to make it look better. There will be another video to explain how to put the final p…
Polish reports in Access so they look terrific. Take yourself to another level. Equations, Back Color, Alternate Back Color. Write easy VBA Code. Tighten space to use less pages. Launch report from a menu, considering criteria only when it is filled…

705 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

17 Experts available now in Live!

Get 1:1 Help Now