Secure RDP behind ISA 2006 (Full Version)

All Forums >> [ISA 2006 Publishing] >> Server Publishing



Message


saturno -> Secure RDP behind ISA 2006 (1.Jul.2008 6:54:06 PM)

Hi everyone,

After carefull reading Dr. Tom Shinder articles about this matter (http://www.isaserver.org/tutorials/Publishing-Remote-Desktop-Web-Connection-Sites-ISA-Firewall-Part1.html) my configuration is done and working!

I have successfully published TSWEB and RDP behind ISA server 2006.

My question is:
I, and any of my users (this is not in production, yet!) can connect to RDP via public DNS name without the trouble of logging in TSWEB published rule. i.e. if I lunch "remote desktop connection" directly and put the public name used in TSWEB connection, the connection is successfully made.

Can I restrict this behaviour?
Is it possible to only allow RDP connection after successfull login in TSWEB?

My rules are:

1st - publish TSWEB with SSL to "All Authenticated Users"
2nd - publish RDP to specific server to (no user check is made because is published using "non web server protocols")


Thank's for any help




tshinder -> RE: Secure RDP behind ISA 2006 (15.Jul.2008 8:21:26 AM)

No. Remember that TSWEB is a convenience for the user, it is not, nor ever was, a security solution.

HTH,
Tom




saturno -> RE: Secure RDP behind ISA 2006 (15.Jul.2008 6:11:17 PM)

Thank's for clarifying Mr. Shinder.




Page: [1]