Link to home
Start Free TrialLog in
Avatar of Mr.X
Mr.X

asked on

how to find out suspicious atta is on default rdp port 3389 on server ?

got a server 2012
got a port forwarding to the server to  access from external . it’s just using default internal port 3389 on server
if I want to find out is there any suspicious attacks going on my rdp port . how do I find out? any particular event Id I need to look for ?
ASKER CERTIFIED SOLUTION
Avatar of David Johnson, CD
David Johnson, CD
Flag of Canada image

Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
Port forwarding and allowing unfiltered access to Remote Desktop IMO is asking for trouble

Personally I would never do this unless a UTM device such as Sonicwall, Fortinet Etc was being used and access was allowed for approved IP's only

This would also provide more robust logging and protection options
Avatar of Mr.X
Mr.X

ASKER

hi david ,
if I enable the group policy for that setting on the domain controller ou (which has 2 dc).

do I need to login to each dc to check login attempts, ??
or if I login to first dc can I check the login attempts of seconds dc ?

or if I enable same policy on computer OU. same question: from dc can I see all login attempts of all computers or do I need to login to each pc to check login attempts ?
SOLUTION
Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
No comment has been added to this question in more than 21 days, so it is now classified as abandoned.

I have recommended this question be closed as follows:

Split:
-- 'David Johnson, CD' (https:#a43072688)
-- 'David Johnson, CD' (https:#a43074232)


If you feel this question should be closed differently, post an objection and the moderators will review all objections and close it as they feel fit. If no one objects, this question will be closed automatically the way described above.

seth2740
Experts-Exchange Cleanup Volunteer