?
Solved

Terminal Services Security

Posted on 2012-03-12
8
Medium Priority
?
296 Views
Last Modified: 2012-03-26
I have a remote web server that I access using Terminal Services.  I noticed (in the event log) that someone is attempting to access the machine.  There are numerous "invalid logon" attempts (every second).

This is a W2008 server.  What is the best way to secure this?   Is there a way to automatically block an IP that has repeated bad logons?

I need to be able to access this server from any location.  Is there a certificate method?
0
Comment
Question by:No1Coder
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 5
  • 3
8 Comments
 
LVL 40

Expert Comment

by:als315
ID: 37710971
You can use certificate for authentification:
http://blogs.msdn.com/b/rds/archive/2010/04/09/configuring-remote-desktop-certificates.aspx
IP blocking is function of firewall, it is not possible in RDP settings.
0
 

Author Comment

by:No1Coder
ID: 37711940
If I setup the certificate, does that require something extra on the client computers I will be using?
0
 
LVL 40

Expert Comment

by:als315
ID: 37713128
You should install certificate on client:
http://www.petri.co.il/securing_rdp_communications.htm
May be this article will be interesting to you:
http://www.petri.co.il/securing-rdp-remote-desktop-and-terminal-server-connections.htm
This parameter was new for me:
Set an account lockout policy - There are tools that will use brute-force to guess passwords and log-on remotely. You cannot totally stop this, but you can minimized it by setting an account lockout policy. If someone tries to guess the password, then after a few guesses they will be locked out for a period of time.
0
What does it mean to be "Always On"?

Is your cloud always on? With an Always On cloud you won't have to worry about downtime for maintenance or software application code updates, ensuring that your bottom line isn't affected.

 

Author Comment

by:No1Coder
ID: 37729165
I setup account lockout policies but they don't seem to work for terminal service connections.  I am still seeing numerous invalid logon attempts every few seconds.  If the lockout was working, I would think it would lock the attemp out for 30 minutes.

These articles are fairly complex.  Event the wizards are pretty complex.  I'm afraid will will lock myself out, or lock out customer access to teh web sites.

I just want to be sure that terminal services connections are from me, although it can be fro multiple machines.

What is the best approach.
0
 
LVL 40

Expert Comment

by:als315
ID: 37729290
As I've stated before - for successfull filtering of attacks you need firewall.
You can try to use internal server 2008 firewall, but usually some external (hardware or software) is used.
Here are some basics:
http://www.windowsnetworking.com/articles_tutorials/configure-Windows-Server-2008-advanced-firewall-MMC-snap-in.html
You can block individual Ips:
http://tech.avivo.si/2011/04/how-to-block-remote-ip-address-hacker-attack-on-windows-2008-server/
0
 
LVL 40

Expert Comment

by:als315
ID: 37734290
0
 

Author Comment

by:No1Coder
ID: 37746584
I don;t think IP filtering will work.  The attacks seem to be coming from more tahn one IP address.

Would a VPN connection be more secure?  I could establish a VPN, and then do terminal services.  I would not have to open the port (3389) publically.
0
 
LVL 40

Accepted Solution

by:
als315 earned 1000 total points
ID: 37746694
Good idea. This is usual setup.
0

Featured Post

Industry Leaders: We Want Your Opinion!

We value your feedback.

Take our survey and automatically be enter to win anyone of the following:
Yeti Cooler, Amazon eGift Card, and Movie eGift Card!

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Determining the an SCCM package name from the Package ID
When asking a question in a forum or creating documentation, screenshots are vital tools that can convey a lot more information and save you and your reader a lot of time
The Task Scheduler is a powerful tool that is built into Windows. It allows you to schedule tasks (actions) on a recurring basis, such as hourly, daily, weekly, monthly, at log on, at startup, on idle, etc. This video Micro Tutorial is a brief intro…
This is used to tweak the memory usage for your computer, it is used for servers more so than workstations but just be careful editing registry settings as it may cause irreversible results. I hold no responsibility for anything you do to the regist…

752 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question