Hello and welcome to CertForums.co.uk, here we host free active certification forums with links to the best free resources for Microsoft's MCSA MCSE MCDBA Cisco's CCNA CCDA and CCNP, and CompTIA's A+ Network+ i-NET+ and Security+ certifications in the UK. If you wish to post or use other advanced features you will need to register first. Registration is absolutely free and takes only a few minutes to complete so sign up today!

If you have any problems with the registration process or your account login, please contact support

Go Back   CertForums > Computing Support Forums > Security & Viruses
Home Forums Register Search Today's Posts Mark Forums Read

Secure Remote Desktop Web Connection.

Post New ThreadReply
 
Thread Tools Display Modes
  #1  
Old 06-Apr-2008, 09:27 AM
NightWalker's Avatar
NightWalker NightWalker is offline
Longterm Member
Posts: 710
Points: 679 NightWalker has over 500 pointsNightWalker has over 500 pointsNightWalker has over 500 pointsNightWalker has over 500 pointsNightWalker has over 500 pointsNightWalker has over 500 points
Power: 19
None
Join Date: 04 Apr 2005
Location: Devon, UK
Age: 29
Certifications: A+, Network+, MCP, MCSA:M 2003
WIP: Active Directory 70-294
Secure Remote Desktop Web Connection.

I want to setup Remote Desktop Web Connection so I can access my main PC at home from any other PC, at work or whatever. My home PC is running Vista Ultimate, I have a Netgear NAT router securing my LAN. Setting up IIS on Vista to get the Remote Desktop Web Connection is fairly straight forward, however opening port 80 and 443 on my router to accept incoming connections brings a degree of risk that I cant decide how best to minimise.

I want to use the standard HTTP ports 80 and 443 so I can access my PC from behind the ISA servers at work, ideally with SSL/TLS to keep my traffic nice and secure. The dilemma is how to secure the PC from the scum bags on the net who may discover an open port to my LAN. My PC is not a domain member, I could add it to my domain but want to avoid this if I can. I was thinking of setting up a standalone root CA on one of my domain controllers, install a certificate on the Vista machine and carry a second certificate on a USB drive and use this to authenticate SSL to my home PC, then Vista’s user name and password to log in through remote desktop. I am not sure if SelfSSL is provided in Vista, have to check this out. Perhaps it would be better to setup RRAS on a Server 2003 box in a DMZ, authenticate to that and RDP into the Vista machine across the LAN from there. I don’t want to leave too many PCs on all the time at home, maybe set them to allow wake on LAN.

Still in the very early planning stage at the moment, what do you guys think?


A+, Network+, MCP, MCSA:Messaging 2003, (70-270, 70-284, 70-290, 70-291, 70-293).
Microsoft Course 2576.

CPU: C2D E6600 @ 3.2 Ghz
HSF: Zalman CNPS9500A-LED
Mobo: Asus P5K Premium-Black Pearl
Ram: Corsair XMS2 2x1GB DDR2-675MHz
GPU: Asus EN8600GT DX10
HD: OS = 1xWD1600YS
HD: Data = 3xWD1600JS RAID5
PSU: Hiper Type-R 530W
Case: Thermaltake VC3000BWS
Display: Samsung SyncMaster 2232BW
 
Reply With Quote
  #2  
Old 06-Apr-2008, 10:24 AM
warrmr warrmr is offline
Valued Member
Posts: 108
Points: 33 warrmr has between 1 & 100 points
Power: 3
None
Join Date: 09 Sep 2007
Location: Solihull, Birmingham
Age: 22
Certifications: MCP 70-270, 70-290
WIP: MCSA + Messaging, MCSE + Security
or do it the way i do with www.logmein.com

you dont need to open any ports on teh pc or any firewall rules.

then all you need i s aPC with a web browser to access you loginto the site with your one user/pass then click on the pc and then type in the credntials for the pc in the other box and jobs a goodun.

the onlything it on the client end it downloads a activex control to the pc you are using to access your pc from not normally an issue but it may be blocked in a work enviro.

 
Reply With Quote
  #3  
Old 06-Apr-2008, 10:26 AM
hbroomhall hbroomhall is offline
Premium Member
Posts: 5,975
Points: 2032 hbroomhall has over 2000 pointshbroomhall has over 2000 pointshbroomhall has over 2000 pointshbroomhall has over 2000 pointshbroomhall has over 2000 pointshbroomhall has over 2000 pointshbroomhall has over 2000 pointshbroomhall has over 2000 pointshbroomhall has over 2000 pointshbroomhall has over 2000 pointshbroomhall has over 2000 points
Power: 85
None
Join Date: 08 Sep 2005
Location: Tunbridge Wells, Kent
Certifications: ECDL A+ Network+ i-Net+
WIP: Server+
Another way might be to use VNC over SSH, which is what I use.

Harry.

 
Reply With Quote
  #4  
Old 06-Apr-2008, 11:06 AM
The_Geek's Avatar
The_Geek The_Geek is offline
Longterm Member
Posts: 690
Points: 339 The_Geek has over 250 pointsThe_Geek has over 250 pointsThe_Geek has over 250 pointsThe_Geek has over 250 points
Power: 15
None
Join Date: 26 Jun 2005
Location: South Carolina, USA
Age: 39
Certifications: CompTIA and Micro$oft
WIP: PDI+
You could upgrade that Netgear router for a firewall that allows incoming connections only from the IP's that you list.

Or if you have a spare PC lying around you could install IP Cop firewall on it. That would do it.



Last edited by The_Geek : 06-Apr-2008 at 11:07 AM.
 
Reply With Quote
  #5  
Old 06-Apr-2008, 11:55 AM
NightWalker's Avatar
NightWalker NightWalker is offline
Longterm Member
Posts: 710
Points: 679 NightWalker has over 500 pointsNightWalker has over 500 pointsNightWalker has over 500 pointsNightWalker has over 500 pointsNightWalker has over 500 pointsNightWalker has over 500 points
Power: 19
None
Join Date: 04 Apr 2005
Location: Devon, UK
Age: 29
Certifications: A+, Network+, MCP, MCSA:M 2003
WIP: Active Directory 70-294
I wanted to avoid third party websites that allow you to remote desktop, rather set it all up myself. The consensus seems to be a decent firewall on a spare PC, smoothwall or IP Cop. This would give a good level of security, I have not used ISA before so this could also be an option. (the networks team look after the ISA servers at work). Wondering if I could use a PKI certificate to only allow the remote connection if the public and private keys match, that would keep out any attempted intrusion.


A+, Network+, MCP, MCSA:Messaging 2003, (70-270, 70-284, 70-290, 70-291, 70-293).
Microsoft Course 2576.

CPU: C2D E6600 @ 3.2 Ghz
HSF: Zalman CNPS9500A-LED
Mobo: Asus P5K Premium-Black Pearl
Ram: Corsair XMS2 2x1GB DDR2-675MHz
GPU: Asus EN8600GT DX10
HD: OS = 1xWD1600YS
HD: Data = 3xWD1600JS RAID5
PSU: Hiper Type-R 530W
Case: Thermaltake VC3000BWS
Display: Samsung SyncMaster 2232BW
 
Reply With Quote
Post New ThreadReply Spread this thread: Submit this thread to digg Submit this thread to del.icio.us


Go Back   CertForums > Computing Support Forums > Security & Viruses


Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump

Similar Threads
Thread Thread Starter Forum Replies Last Post
remote desktop builtin group dales Server Exams 12 25-Mar-2008 10:38 PM
Monitoring & load testing a web server Stoney Software 0 05-Feb-2008 05:14 PM
Remote Support and admin Jiser Networking 11 22-Jan-2008 01:25 AM
Remote assistance frustration: MS press book simply doesn't help csh Server Exams 4 17-Oct-2007 04:27 PM
Remote Desktop Help SolidSponge Server Exams 5 02-May-2007 07:23 PM


All times are GMT. The time now is 12:14 PM.

Powered by vBulletin® Version 3.6.10
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
CertForums.co.uk (C) copyright 2003-2007 All Rights Reserved. Content published on CertForums.co.uk requires permission for reprint.
Hosted by Lunarpages