?
Solved

Windows 2008 RDS Gateway Server - IIIS - Security

Posted on 2010-09-08
4
Medium Priority
?
521 Views
Last Modified: 2012-05-10
Hello

I have enabled TS Gatewaye on my server. Clients can RDP to from outside and authenicate against the server.

I have noticed that is if i type in the name of the server in a URL http://ts.domain.com then i get the default IIS page. Is there away to stop that I see this as secuirty hole.

I tried the server http redirect option redirecting to https://ts.domain.com/ts but this breaks the authenication.

Any ideas on how to make the Gateway more secure while still allowing it authenicate.

thank you

john
0
Comment
Question by:escadmin
  • 3
4 Comments
 
LVL 3

Accepted Solution

by:
SangramGohil earned 750 total points
ID: 33644552
Hi,

Use URL rewrite in IIS7

i think it will not break authentication also

http://www.iis.net/download/urlrewrite

give it a try.

formula could be like
Requested URL : Matches the pattern
Using: Regular Expression
Pattern :(.*)

Logical Group

Condition : {HTTPS}
Matches the pattern
OFF$

Action Type :Redirect

Redirect URL: https://{http_host)/ts

give it a try in test lab first
0
 

Author Comment

by:escadmin
ID: 33650955
Will look at the application this weekend. I need to find what exactly RDS Gateway is conencting to on the inside.

John
 
0
 

Author Comment

by:escadmin
ID: 33827171
The problem is i cannot redirect it. Last week I had someone scan my server. Nothing uploaded etc. I wish MS would have something about locking down the Terminal server gateway. I award you the points as no one else responded.
0
 

Author Closing Comment

by:escadmin
ID: 33827176
No answers to locking down the server.
0

Featured Post

Free Tool: IP Lookup

Get more info about an IP address or domain name, such as organization, abuse contacts and geolocation.

One of a set of tools we are providing to everyone as a way of saying thank you for being a part of the community.

Question has a verified solution.

Are you are experiencing a similar issue? Get a personalized answer when you ask a related question.

Have a better answer? Share it in a comment.

Join & Write a Comment

Media Temple is proud to announce our partnership with the Society of Digital Agencies (SoDA) as their exclusive hosting partner.
This installment of Make It Better gives Media Temple customers the latest news, plugins, and tutorials to make their VPS hosting experience that much smoother.
This tutorial will show how to configure a new Backup Exec 2012 server and move an existing database to that server with the use of the BEUtility. Install Backup Exec 2012 on the new server and apply all of the latest hotfixes and service packs. The…
This tutorial will show how to configure a single USB drive with a separate folder for each day of the week. This will allow each of the backups to be kept separate preventing the previous day’s backup from being overwritten. The USB drive must be s…

569 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question