Y
yo.natan
Hi
First let me describe the current network setup. I have an ADSL modem
connected to a D-Link DI604 router. A server running Windows 2003 Server R2
and two Windows XP Professional SP3 workstations are all directly connected
to the DI604 router. This is a workgroup network!
At the moment I access all three machines remotely using Remote Desktop
Connection. The router forwards port 3389 to the server, 3390 and 3391 for
each workstation, respectively.
I don't believe that this is the most secure setup for remote access and I
am looking for advice on how to improve.
My first idea is to change the setup, so that I would remotely access the
server using RDP and once on the server I would use RDP on the server to
access each workstation when necessary. This way I figure I need to open only
one port on the router and this will be more secure.
Now some questions:
- Which is more secure, to run RDP over SSL or RDP over VPN?
- IF RDP over SSL is chosen, then I guess only solution is to install an SSL
server on the server?
- If RDP over VPN is chosen above, is it better to get a new router to
replace the DI604 which has VPN capabilities or to install a software VPN
server on the server?
- If it is better with a VPN router which of the following is a good choice
(money not the deciding factor):
1. CISCO RVS4000 4-PORT GIGBABIT SECURITY ROUTER
2. D-LINK DFL-200 FIREWALL
3. D-LINK DFL-210 FIREWALL
4. LINKSYS BEFVP41 4-PORT SWITCH VPN
If any hardware not mentioned is better please let me know!!
Ok that should be all my questions for now. By the way the remote computer
accessing the corporate network is not important as it can use either VPN or
SSL and will use software not hardware in case of VPN solution.
Thanks for any advice and help!
First let me describe the current network setup. I have an ADSL modem
connected to a D-Link DI604 router. A server running Windows 2003 Server R2
and two Windows XP Professional SP3 workstations are all directly connected
to the DI604 router. This is a workgroup network!
At the moment I access all three machines remotely using Remote Desktop
Connection. The router forwards port 3389 to the server, 3390 and 3391 for
each workstation, respectively.
I don't believe that this is the most secure setup for remote access and I
am looking for advice on how to improve.
My first idea is to change the setup, so that I would remotely access the
server using RDP and once on the server I would use RDP on the server to
access each workstation when necessary. This way I figure I need to open only
one port on the router and this will be more secure.
Now some questions:
- Which is more secure, to run RDP over SSL or RDP over VPN?
- IF RDP over SSL is chosen, then I guess only solution is to install an SSL
server on the server?
- If RDP over VPN is chosen above, is it better to get a new router to
replace the DI604 which has VPN capabilities or to install a software VPN
server on the server?
- If it is better with a VPN router which of the following is a good choice
(money not the deciding factor):
1. CISCO RVS4000 4-PORT GIGBABIT SECURITY ROUTER
2. D-LINK DFL-200 FIREWALL
3. D-LINK DFL-210 FIREWALL
4. LINKSYS BEFVP41 4-PORT SWITCH VPN
If any hardware not mentioned is better please let me know!!
Ok that should be all my questions for now. By the way the remote computer
accessing the corporate network is not important as it can use either VPN or
SSL and will use software not hardware in case of VPN solution.
Thanks for any advice and help!