[Last Call] Learn how to a build a cloud-first strategyRegister Now

x
?
Solved

Brute force and Terminal server (Ts Web Access 2008) on server 2008 ent editon x32 Cisco or server 2008

Posted on 2011-09-24
3
Medium Priority
?
390 Views
Last Modified: 2012-05-12
Hi there,
I get now thousands of auto emails genetrated regarding unsuccessful security logs from one of my server on which I am running tsweb access.  My clients access this server via https://server.mydomainname.com' and work on a database program.  As a precautionary measure I have already put in the account lock out policy after certain number of unsuccessful attempts but it seems like the people who attempt to have un authorized access to this server use Dos console with port mapped to 3389 and then they use brute force with different combinations to gain access.
I need help how to block the external unauthorized users IP addresses and or break their connection after certain # of logins? in server 2008.
Or
Any good software firewall which checks the unsuccessful attempts and puts them in the block IP and then release them after an amount of time.
Or
Cisco solution.  At the moment I have cisco 2911 router with IOS firewall, I am getting tired of putting in manually the IPs of these buggers.
Help plz
0
Comment
Question by:amanzoor
3 Comments
 
LVL 42

Assisted Solution

by:kevinhsieh
kevinhsieh earned 400 total points
ID: 36594353
There is a worm going around that has a limited dictionary of passwords that it tries. The problem is that a firewall has no way to tell a good connection from a bad connection because it only understands TCP, and it has no visibility into what is happening over the encrypted RDP session. Your best defense is to have good passwords in place. There was another question on EE asking for the same thing. I don't remember the resolution.

You can require VPN connection or RDP Gateway. The worm isn't coded to go through an RDP gateway (and it would be hard to do because you would need to name or IP of the RDP server behind the gateway).

Whitelisting your clients is another way, but not foolproof. I suggest implementing RDP gateway. You can also add cool two-factor authentication such as PhoneFactor, which is free for up to 25 unique users per month.
0
 
LVL 11

Accepted Solution

by:
yelbaglf earned 1600 total points
ID: 36595249
0
 
LVL 4

Author Closing Comment

by:amanzoor
ID: 36595524
I am really thankful to experts like you, your uptodate knowledge.
Thanks
0

Featured Post

Prepare for your VMware VCP6-DCV exam.

Josh Coen and Jason Langer have prepared the latest edition of VCP study guide. Both authors have been working in the IT field for more than a decade, and both hold VMware certifications. This 163-page guide covers all 10 of the exam blueprint sections.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

In the hope of saving someone else's sanity... About a year ago we bought a Cisco 1921 router with two ADSL/VDSL EHWIC cards to load balance local network traffic over the two broadband lines we have, but we couldn't get the routing to work consi…
OfficeMate Freezes on login or does not load after login credentials are input.
This tutorial will walk an individual through setting the global and backup job media overwrite and protection periods in Backup Exec 2012. Log onto the Backup Exec Central Administration Server. Examine the services. If all or most of them are stop…
There are cases when e.g. an IT administrator wants to have full access and view into selected mailboxes on Exchange server, directly from his own email account in Outlook or Outlook Web Access. This proves useful when for example administrator want…

825 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question