Solved

Brute force and Terminal server (Ts Web Access 2008) on server 2008 ent editon x32 Cisco or server 2008

Posted on 2011-09-24
3
366 Views
Last Modified: 2012-05-12
Hi there,
I get now thousands of auto emails genetrated regarding unsuccessful security logs from one of my server on which I am running tsweb access.  My clients access this server via https://server.mydomainname.com' and work on a database program.  As a precautionary measure I have already put in the account lock out policy after certain number of unsuccessful attempts but it seems like the people who attempt to have un authorized access to this server use Dos console with port mapped to 3389 and then they use brute force with different combinations to gain access.
I need help how to block the external unauthorized users IP addresses and or break their connection after certain # of logins? in server 2008.
Or
Any good software firewall which checks the unsuccessful attempts and puts them in the block IP and then release them after an amount of time.
Or
Cisco solution.  At the moment I have cisco 2911 router with IOS firewall, I am getting tired of putting in manually the IPs of these buggers.
Help plz
0
Comment
Question by:amanzoor
3 Comments
 
LVL 42

Assisted Solution

by:kevinhsieh
kevinhsieh earned 100 total points
ID: 36594353
There is a worm going around that has a limited dictionary of passwords that it tries. The problem is that a firewall has no way to tell a good connection from a bad connection because it only understands TCP, and it has no visibility into what is happening over the encrypted RDP session. Your best defense is to have good passwords in place. There was another question on EE asking for the same thing. I don't remember the resolution.

You can require VPN connection or RDP Gateway. The worm isn't coded to go through an RDP gateway (and it would be hard to do because you would need to name or IP of the RDP server behind the gateway).

Whitelisting your clients is another way, but not foolproof. I suggest implementing RDP gateway. You can also add cool two-factor authentication such as PhoneFactor, which is free for up to 25 unique users per month.
0
 
LVL 11

Accepted Solution

by:
yelbaglf earned 400 total points
ID: 36595249
0
 
LVL 4

Author Closing Comment

by:amanzoor
ID: 36595524
I am really thankful to experts like you, your uptodate knowledge.
Thanks
0

Featured Post

Don't lose your head updating email signatures!

Do your end users still have the wrong email signature? Do email signature updates bore you or fill you with a sense of dread? You can make this a whole lot easier on yourself by trusting an Exclaimer email signature management solution. Over 50 million users do...so should you!

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Creating an OSPF network that automatically (dynamically) reroutes network traffic over other connections to prevent network downtime.
You might have come across a situation when you have Exchange 2013 server in two different sites (Production and DR). After adding the Database copy in ECP console it displays Database copy status unknown for the DR exchange server. Issue is strange…
This tutorial will show how to push an installation of Backup Exec to an additional server in both 2012 and 2014 versions of the software. Click on the Backup Exec button in the upper left corner. From here, select Installation and Licensing, then I…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…

911 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

16 Experts available now in Live!

Get 1:1 Help Now