Click here to get back home

remotely administering Bastion servers

 HomeNewsGroups | Search | About
 microsoft.public.windows.server.security    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content
Subject Author Date
remotely administering Bastion servers mmccaws2 04-02-2007
Posted by Anthony on April 7, 2007, 8:12 am
Please log in for more thread options
Overkill for what? For administering servers behind a firewall? It depends
what you are running and how secure you want it to be. The original poster
does not say what he is running on the server, and asks for ideas.
Anthony
www.airdesk.co.uk



> G'day:
>
>> VPN to behind the firewall then RDP back out to the DMZ.
>> Anthony
>> www.airdesk.co.uk
>
> Clearly an overkill.
>
> --
> Svyatoslav Pidgorny, MS MVP - Security, MCSE
> -= F1 is the key =-
>
> * http://sl.mvps.org * http://msmvps.com/blogs/sp *
>
>



Posted by S. Pidgorny on April 7, 2007, 8:23 am
Please log in for more thread options
Yes, for that. You are suggesting a secure encrypted protocol within a
secure, encrypted tunnel (which is kinda okay - VPN is useful for future
apps); but VPN to _behind_ the firewall is wrong - defeats the purpose of
the firewall, and renders it redundant in the infrastructure.

Which may be a symptom of another issue:
http://msmvps.com/blogs/sp/archive/2007/02/20/firewalls-are-a-thing-of-the-past.aspx

--
Svyatoslav Pidgorny, MS MVP - Security, MCSE
-= F1 is the key =-

* http://sl.mvps.org * http://msmvps.com/blogs/sp *

> Overkill for what? For administering servers behind a firewall? It depends
> what you are running and how secure you want it to be. The original poster
> does not say what he is running on the server, and asks for ideas.
> Anthony
> www.airdesk.co.uk
>
>
>
>> G'day:
>>
>>> VPN to behind the firewall then RDP back out to the DMZ.
>>> Anthony
>>> www.airdesk.co.uk
>>
>> Clearly an overkill.
>>
>> --
>> Svyatoslav Pidgorny, MS MVP - Security, MCSE
>> -= F1 is the key =-
>>
>> * http://sl.mvps.org * http://msmvps.com/blogs/sp *
>>
>>
>
>



Posted by Anthony on April 7, 2007, 10:26 am
Please log in for more thread options
You are misreading my suggestion. It is nothing more complicated than:
- use VPN to achieve secure remote access to the network behind the access
point (router, firewall, VPN device or whatever)
- use RDP to administer the server.
Anthony
www.airdesk.co.uk






> Yes, for that. You are suggesting a secure encrypted protocol within a
> secure, encrypted tunnel (which is kinda okay - VPN is useful for future
> apps); but VPN to _behind_ the firewall is wrong - defeats the purpose of
> the firewall, and renders it redundant in the infrastructure.
>
> Which may be a symptom of another issue:
>
http://msmvps.com/blogs/sp/archive/2007/02/20/firewalls-are-a-thing-of-the-past.aspx
>
> --
> Svyatoslav Pidgorny, MS MVP - Security, MCSE
> -= F1 is the key =-
>
> * http://sl.mvps.org * http://msmvps.com/blogs/sp *
>
>> Overkill for what? For administering servers behind a firewall? It
>> depends what you are running and how secure you want it to be. The
>> original poster does not say what he is running on the server, and asks
>> for ideas.
>> Anthony
>> www.airdesk.co.uk
>>
>>
>>
>>> G'day:
>>>
>>>> VPN to behind the firewall then RDP back out to the DMZ.
>>>> Anthony
>>>> www.airdesk.co.uk
>>>
>>> Clearly an overkill.
>>>
>>> --
>>> Svyatoslav Pidgorny, MS MVP - Security, MCSE
>>> -= F1 is the key =-
>>>
>>> * http://sl.mvps.org * http://msmvps.com/blogs/sp *
>>>
>>>
>>
>>
>
>



Posted by S. Pidgorny on April 7, 2007, 7:06 pm
Please log in for more thread options
Perhaps I do - my apologies. The thing is, I have seen so many
overengineered solutions, like VPN gateways running on firewalls protected
by another layer of firewalls, that I've become too suspicious.

--
Svyatoslav Pidgorny, MS MVP - Security, MCSE
-= F1 is the key =-

* http://sl.mvps.org * http://msmvps.com/blogs/sp *

> You are misreading my suggestion. It is nothing more complicated than:
> - use VPN to achieve secure remote access to the network behind the access
> point (router, firewall, VPN device or whatever)
> - use RDP to administer the server.
> Anthony
> www.airdesk.co.uk
>
>>>>> VPN to behind the firewall then RDP back out to the DMZ.



Posted by Anthony on April 7, 2007, 10:16 pm
Please log in for more thread options
I agree, no point in over-engineering
Anthony
www.airdesk.co.uk


> Perhaps I do - my apologies. The thing is, I have seen so many
> overengineered solutions, like VPN gateways running on firewalls protected
> by another layer of firewalls, that I've become too suspicious.
>
> --
> Svyatoslav Pidgorny, MS MVP - Security, MCSE
> -= F1 is the key =-
>
> * http://sl.mvps.org * http://msmvps.com/blogs/sp *
>
>> You are misreading my suggestion. It is nothing more complicated than:
>> - use VPN to achieve secure remote access to the network behind the
>> access point (router, firewall, VPN device or whatever)
>> - use RDP to administer the server.
>> Anthony
>> www.airdesk.co.uk
>>
>>>>>> VPN to behind the firewall then RDP back out to the DMZ.
>
>



Similar ThreadsPosted
Win2003 SP1 remotely restart service June 14, 2005, 1:02 pm
Allow user to restart service remotely July 27, 2007, 11:28 pm
Service writing on Win2003 remotely. October 26, 2007, 8:59 am
Remotely query local policies January 10, 2008, 4:42 pm
How to allow non-admin to run scheduled tasks remotely? July 24, 2008, 1:18 pm
Error in my security log when attempting to browse site remotely September 6, 2005, 3:20 pm
Re: Grant user right to remotely start stop server - can anybody help? March 10, 2006, 12:32 pm
Re: Grant user right to remotely start stop server - can anybody help? March 10, 2006, 12:41 pm
Start and Stop Services Remotely Under Non-Administrative User April 26, 2006, 5:01 pm
Account lock out when accessing computer management remotely September 27, 2006, 11:32 am

Our other projects:

Art Dolls, Fairies and Mermaids - Sunnyfaces.net

Roy's Linux, Programming and Search Engines messages

1-Script XML SitemapXML Sitemap