Solved

Brute force and Terminal server (Ts Web Access 2008) on server 2008 ent editon x32 Cisco or server 2008

Posted on 2011-09-24
3
374 Views
Last Modified: 2012-05-12
Hi there,
I get now thousands of auto emails genetrated regarding unsuccessful security logs from one of my server on which I am running tsweb access.  My clients access this server via https://server.mydomainname.com' and work on a database program.  As a precautionary measure I have already put in the account lock out policy after certain number of unsuccessful attempts but it seems like the people who attempt to have un authorized access to this server use Dos console with port mapped to 3389 and then they use brute force with different combinations to gain access.
I need help how to block the external unauthorized users IP addresses and or break their connection after certain # of logins? in server 2008.
Or
Any good software firewall which checks the unsuccessful attempts and puts them in the block IP and then release them after an amount of time.
Or
Cisco solution.  At the moment I have cisco 2911 router with IOS firewall, I am getting tired of putting in manually the IPs of these buggers.
Help plz
0
Comment
Question by:amanzoor
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
3 Comments
 
LVL 42

Assisted Solution

by:kevinhsieh
kevinhsieh earned 100 total points
ID: 36594353
There is a worm going around that has a limited dictionary of passwords that it tries. The problem is that a firewall has no way to tell a good connection from a bad connection because it only understands TCP, and it has no visibility into what is happening over the encrypted RDP session. Your best defense is to have good passwords in place. There was another question on EE asking for the same thing. I don't remember the resolution.

You can require VPN connection or RDP Gateway. The worm isn't coded to go through an RDP gateway (and it would be hard to do because you would need to name or IP of the RDP server behind the gateway).

Whitelisting your clients is another way, but not foolproof. I suggest implementing RDP gateway. You can also add cool two-factor authentication such as PhoneFactor, which is free for up to 25 unique users per month.
0
 
LVL 11

Accepted Solution

by:
yelbaglf earned 400 total points
ID: 36595249
0
 
LVL 4

Author Closing Comment

by:amanzoor
ID: 36595524
I am really thankful to experts like you, your uptodate knowledge.
Thanks
0

Featured Post

Backup Solution for AWS

Read about how CloudBerry Backup fully integrates your backups with Amazon S3 and Amazon Glacier to provide military-grade encryption and dramatically cut storage costs on any platform.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
DNS Replication 12 70
How to rollback Windows updates with SCCM? 6 82
RDS on 2012 R2 and Term Server on 2008 and a licensing question 4 67
robocopy question 3 30
In the hope of saving someone else's sanity... About a year ago we bought a Cisco 1921 router with two ADSL/VDSL EHWIC cards to load balance local network traffic over the two broadband lines we have, but we couldn't get the routing to work consi…
This article explains how to install and use the NTBackup utility that comes with Windows Server.
This tutorial will walk an individual through the steps necessary to configure their installation of BackupExec 2012 to use network shared disk space. Verify that the path to the shared storage is valid and that data can be written to that location:…
This tutorial will show how to configure a single USB drive with a separate folder for each day of the week. This will allow each of the backups to be kept separate preventing the previous day’s backup from being overwritten. The USB drive must be s…

749 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question