Link to home
Start Free TrialLog in
Avatar of cosmicIPA
cosmicIPAFlag for United States of America

asked on

How to allow Remote XP users to control XP workstations behind a Firewall in an Wndows 2003 environment

Greetings! I need to setup remote access to XP workstations in a Windows 2003 domain using Remote Desktop Connection behind a SonicWall Firewall with a single Static IP. Should I simply configure the Firewall rules, allowing To and From RDP connections, using different port numbers for each workstation ie.,

Static IP = 75.78.10.104

Workstation1 = 75.78.10.104:6689
Workstation2 = 75.78.10.104:6690
Workstation3 = 75.78.10.104:6691

Thanks for your help!
ASKER CERTIFIED SOLUTION
Avatar of Shankadude
Shankadude

Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
Avatar of cosmicIPA

ASKER

What line in each remote workstatitions registry (RDP section?) would need to be modified reflecting a unique port?

Also, are their security issues in using this type of remote control compaired to say pcAnywhere? Would the passwords be sent in clear text and would 3389 be vunerable to a dictionary type attack (probably)?
Avatar of Shankadude
Shankadude

See this Microsoft KB article for the registry keys to change.
http://support.microsoft.com/kb/187623

But if the only goal is to be able to reach the computers from the internet, there is no need to do this with most firewalls.. The portnumbers on the outside and the inside can be different.
You only have to enter in your router/firewall that for example external port 1122 goes to internal port 3389 at computerX, and that external port 1133 goes to internal port 3389 at computerY.

Hope this helps.
Make sure there are no blank Administrator passwords on any of the workstations!  Enforce passwords for all users and make them meet the complexity requirements!
What about semding passwords in clear text; does the client prevent this?
Default there is password encryption.
Read for more details and settings this article:
http://www.mobydisk.com/techres/securing_remote_desktop.html

Thanks for the input. A remote connection initialized over VPN seems like currently the best solution that does not require changing any ports on either the client or server side.

Check this out: https://www.experts-exchange.com/questions/20824244/Any-security-issues-that-i-should-be-aware-of-with-remote-desktop.html

Thank you for your input.