Link to home
Start Free TrialLog in
Avatar of nourben
nourbenFlag for United States of America

asked on

Enable Remote Desktop on Win XP Pro With Firewall enabled.

I am on a Windows 2003 Servers, I have about 120 desktops (Windows XP Pro SP2) with the Firewall enabled, I want to enable remote desktop to all these desktops for Domain administrators only, I don't want users to be able to remote desktop to their machines, how should I proceed?
Avatar of mikeleebrla
mikeleebrla
Flag of United States of America image

1. enable port 3389 to pass through the windows firewall (that is the port that RDC uses)
2. enable remote desktop on each of these PCs for domain admins only.

thats it.

Avatar of nourben

ASKER

Can I do this with a Group Policy?
Avatar of Netman66
Yes.

Computer Configuration>Administrative Templates>Network>Network Connections>Windows Firewall>Domain Profile ::

Windows Firewall: Allow remote administration exception = Enabled.

Avatar of nourben

ASKER

It did not do it in my envirement, but the following worked:

Computer Configuration>Windows Settings>Local Policies/Users Rights Assignment:
     Allow log on through Terminal Services - Domain/Administrator

Computer Configuration>Administrative Templates>Network>Network Connections>Windows Firewall>Domain Profile :
      Windows Firewall: Allow Remote Desktop exeption - enabled

Computer Configuration>Administrative Templates>Windows Components>Terminal Services
      Allow users to connect remotely using Terminal Services

I needed all theses settings for the GPO to work.


Well, the first and last elements would have been automatic had the checkbox for Allow Remote Desktop in System Properties was checked.  I had assumed this was already done.

ASKER CERTIFIED SOLUTION
Avatar of Computer101
Computer101
Flag of United States of America image

Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial