Best practice - Networks Remote Access: Difference between revisions

From Security Wiki
Jump to navigationJump to search
No edit summary
No edit summary
 
(3 intermediate revisions by one other user not shown)
Line 1: Line 1:
Created by Emilio Valente - March 26,2007
Created by Emilio Valente - March 26,2007


Windows Users Remote Network Connections:
Best practices document for connecting a Windows Client to a remote Windows System


To allow Windows users to connect remotely from Home or from any other place outside SDSC a secure VPN tunnel should be used (SDSC uses Cisco client). To connect to a “machine room” system (usually a server) the following instructions are recommended https://kb.sdsc.edu/?aid=179 .


On the other hand for users that want to connect systems located other than the machine room such as: workstations or laptops or any other devices, located into their offices or nearby vicinity; the following best practices should be also applied.
To allow Windows users to manage SDSC resources from home or any other remote location, a secure VPN tunnel should be used (SDSC uses a Cisco solution supporting VPN client software and a VPN server appliance). To connect to a “machine room” system (usually a server ) the following instructions are recommended https://kb.sdsc.edu/?aid=179 .


Windows Users:
Remote Desktop. 
For Users that need to be connected to a Wireless-Conference Net .64-65 Windows systems, the below recommendations should be adopted.
Instead of using the above general Cisco VPN client, should use Microsoft End-to-End VPN to get connectivity to their end system (at their office location, for example) and then when connected start their Remote desktop. (see below details of how to install Microsoft VPN).


This would guarantee a layer of protection (for the part of data that travel on the untrusted .64-65 net) since RD has a weak encryption algorithm (RC4) while Microsoft End-to-End VPN uses a stronger one (L2TP/IPSec).  
For users that want to connect windows systems to other windows systems located outside the SDSC machine room, such as a windows office workstations or a windows laptop, the following best practices should be applied.


It is also desirable to change the incoming port where RD is listening for the connection. From the default 3389 an unassigned IANA list taken from the range of 34981-36864 (take one at your preference but please write it down otherwise you will forget it) should be used. (see below details of how to change the default RD port)


How to change default Remote Desktop port in Windows XP:
The Remote Windows system will need to have "Remote Access enabled" under the systems properties menu. This will automatically enable the windows firewall.  If a 3rd party firewall is being used on it will need to pass the correct port number. On the client side just starting the remote terminal session should be sufficient.
http://support.microsoft.com/kb/306759  
 
For users that want additional security, Microsoft End-to-End VPN will provide connectivity to their end system and when connected start their Remote desktop. (see below details of how to install Microsoft VPN).
 
This would guarantee a layer of protection (for the part of data that travel on untrusted nets) since RD has a weak encryption algorithm (RC4) while Microsoft End-to-End VPN uses a stronger one (L2TP/IPSec).
 
Changing the incoming port that RD is listening on can increase protection for the server side. The default port is 3389. Use the last 4 of a known phone number works (pick one but please write it down otherwise you will forget it). (see below details of how to change the default RD port)
 
How to change default Remote Desktop port in Windows XP: http://support.microsoft.com/kb/306759  


How to setup Microsoft VPN in Windows XP: http://compnetworking.about.com/od/vpn/ht/newvpnwindowsxp.htm  
How to setup Microsoft VPN in Windows XP: http://compnetworking.about.com/od/vpn/ht/newvpnwindowsxp.htm  


How to setup Remote Desktop in Windows XP:
How to setup Remote Desktop in Windows XP: http://www.microsoft.com/windowsxp/using/mobility/getstarted/remoteintro.mspx
http://www.microsoft.com/windowsxp/using/mobility/getstarted/remoteintro.mspx

Latest revision as of 21:59, 30 May 2009

Created by Emilio Valente - March 26,2007

Best practices document for connecting a Windows Client to a remote Windows System


To allow Windows users to manage SDSC resources from home or any other remote location, a secure VPN tunnel should be used (SDSC uses a Cisco solution supporting VPN client software and a VPN server appliance). To connect to a “machine room” system (usually a server ) the following instructions are recommended https://kb.sdsc.edu/?aid=179 .


For users that want to connect windows systems to other windows systems located outside the SDSC machine room, such as a windows office workstations or a windows laptop, the following best practices should be applied.


The Remote Windows system will need to have "Remote Access enabled" under the systems properties menu. This will automatically enable the windows firewall. If a 3rd party firewall is being used on it will need to pass the correct port number. On the client side just starting the remote terminal session should be sufficient.

For users that want additional security, Microsoft End-to-End VPN will provide connectivity to their end system and when connected start their Remote desktop. (see below details of how to install Microsoft VPN).

This would guarantee a layer of protection (for the part of data that travel on untrusted nets) since RD has a weak encryption algorithm (RC4) while Microsoft End-to-End VPN uses a stronger one (L2TP/IPSec).

Changing the incoming port that RD is listening on can increase protection for the server side. The default port is 3389. Use the last 4 of a known phone number works (pick one but please write it down otherwise you will forget it). (see below details of how to change the default RD port)

How to change default Remote Desktop port in Windows XP: http://support.microsoft.com/kb/306759

How to setup Microsoft VPN in Windows XP: http://compnetworking.about.com/od/vpn/ht/newvpnwindowsxp.htm

How to setup Remote Desktop in Windows XP: http://www.microsoft.com/windowsxp/using/mobility/getstarted/remoteintro.mspx