Is VPN necessary with RDS over the Internet


first off can negate gateway role discussion it's not option devices using. question this, if rdp traffic encrypted default still necessary further secure rdp connection on internet vpn?

cheers
c


hibs ya bass!

hi,

whether or not vpn or rd gateway necessary judgement call make based on security needs/concerns.  if have trusted certificate installed on server with security layer set ssl (tls 1.0) , encryption level set high, and the rd clients configured server authentication, yes, traffic encrypted and a mitm attack unlikely.

the key consideration rdsh server still exposed directly internet, if rdp port.  if vulnerability discovered in rdp (like has occurred in past) server @ risk.  example, vulnerability allow unknown attacker send few packets server , crash it, or compromise in way.

there automated attack bots attempt connect default rdp port (tcp 3389) on different ip addresses , when response start trying username/password combinations.  if have strong usernames , passwords (which should) these attacks may waste server resources on rdsh server.

if plan on exposing rdsh server internet recommend change default port different , use instead, example, tcp 11633.  recommend setting server allow network level authentication (nla).  requiring nla rdp connections reduce resource consumption caused unsuccessful attempts authenticate/connect via rdp.

having vpn server or rd gateway between internet , rdsh server(s) provides layer of security.  vpn servers more hardened against attack compared rdsh server.  benefit of having rdg or vpn if attacks internal users may able keep working since attack not happening against rdsh servers directly.

when using rd gateway companies prefer have incoming connections terminated @ firewall first, , firewall initiates new connection rdg.  known ssl bridging , provides layer of security since firewall device may inspect incoming requests , potentially block harmful packets before reach rdg.

in general firewall/security/vpn device better equiped handle/detect attacks.

it possible have rdsh server directly exposed internet , not have problems, however, preferred (at least) use rd gateway or vpn instead give layer of protection.

-tp



Windows Server  >  Remote Desktop Services (Terminal Services)



Comments

Popular posts from this blog

WIMMount (HSM) causing cluster storage to go redirected (2012r2 DC)

Failed to delete the test record dcdiag-test-record in zone test.com

Azure MFA with Azure AD and RDS