DC and RDP

Gad SAADIA
Gad SAADIA used Ask the Experts™
on
I have to install RDS services on a WIndows 2008R2 DC

(I know it is not a recommended thing to do for security reasons but I have to do it anyway...)

What specific things do I have to do in order to make this solution work?

Thank you
Comment
Watch Question

Do more with

Expert Office
EXPERT OFFICE® is a registered trademark of EXPERTS EXCHANGE®
Photographer
Awarded 2007
Top Expert 2008
Commented:
OK - It would be remiss of me not to point out that this is not recommended as you are blowing a big whole in your security by effectively allowing users to log-on locally to the DC.

If you really must do this (under protest and having pointed out the folly of the practice) ,then see http://technet.microsoft.com/en-us/library/cc742817(v=ws.10).aspx

Commented:
Just don't forget to verify RDP is enabled in the firewall....
WORKS2011Managed IT Services, Cyber Security, Backup

Commented:
- make sure port 3389 points to the server ip in your firewall
- on the server / Start / right click Computer / Remote Settings / Remote / Remote Desktop check "Allow connections from computers running any versions of Remote Desktop (less secure) / Select Users, add user.
- Start / Administrator Tools / ADUC / expand Sever.local / Builtin / Remote Desktop Users make sure user is added here.

If you wish to make this more secure you can change the IP address from 3389 to 3390 or another port however if you wish to do this open another thread and I'll run you through it.
As stated above if you are accessing this externally then its good practice to change the port from the default.

You can do this either by redirecting from a different source port to the destination port of 3389 (eg external port 3391 to 3389 on your firewall.

Or you can change the listening port on your server outlined here

http://support.microsoft.com/kb/306759

If you choose option 2 make sure you open the custom port on your windows firewall as well

You would also need to append the port number to the IP before connecting
Gad SAADIAManager

Author

Commented:
thank you

Do more with

Expert Office
Submit tech questions to Ask the Experts™ at any time to receive solutions, advice, and new ideas from leading industry professionals.

Start 7-Day Free Trial