YIguchi said:
Hi Sooner Al
Well apart from establishing the secure connection. Is it possible to
enforce it?
Actually i want my users can connect ONLY through tunnel .
I want to block the direct access of rdp. Is it possible to do it ?
Regards,
Y Iguchi
You only allow access to your network from outside through a VPN or SSH
tunnel. That is what I do. In my case I only allow certain users to access
my home LAN via a PPTP VPN tunnel. Once those users are connected through
the VPN tunnel access to specific desktops with Remote Desktop is limited to
users with administrator permissions on the particular desktop or to members
of the Remote Desktop Users Group on the particular desktop.
If your talking about local access to a particular desktop with Remote
Desktop then you could configure the Windows Firewall (or any other software
firewall for that matter) so Remote Desktop will only accept incoming
connections from specific IP addresses. Those addresses could be limited to
the IP range you assign to your VPN clients for example.
This example is for File & Print Sharing but it would be the same for Remote
Desktop. In the example the 10.8.0.31 address is an IP assigned to a VPN
client PC. The 10.8.0.12 and 10.8.0.101 addresses are other local PCs on the
LAN. You might configure to only allow access to the 10.8.0.31 address. Of
course you need to substitute your VPN client and/or LAN IP addresses.
http://theillustratednetwork.mvps.org/ScreenShots/SP2WindowsFirewall/FirewallCustomScope.JPG
--
Al Jarvi (MS-MVP Windows Networking)
Please post *ALL* questions and replies to the news group for the
mutual benefit of all of us...
The MS-MVP Program -
http://mvp.support.microsoft.com
This posting is provided "AS IS" with no warranties, and confers no
rights...