Looking on MS technet under an article " Leveraging Security Features in
Windows 2000 for Exchange"
 
under services in Win 2000
 
Port    Prot     Service
3389   RDP    Terminal Services
 
Which is the port NT4 Terminal Server uses and that under NT4 is the only
incoming port you need to open. Can't see why it would change with 2000.
 
I actually whacked the object in the rulebase as a TCP port and it seems to
work. FW1 4.1 SP0 (yeah i know, we are close to installing SP2)
 
other thing to look for is that the servers are in your DNS that the client
uses.
 
oops.. here I found another gem from the w2k res kit
 

        Access Over Wide Area Network

        Determine if filters have been implemented on the routers or
firewalls that would prevent clients from remotely gaining access to a
Terminal server. Check to make sure that the Remote Desktop Protocol (RDP)
port (port 3389) is not blocked at the firewall and that access to specific
corporate segments is not limited to Internet Protocol (IP) or Internetwork
Packet Exchange (IPX) network addresses. If these blocks are in place and
they prevent remote connections, the team must address them during
deployment.

         

cheers
dean
 


-----Original Message-----
From: Peter Mueller [mailto:[EMAIL PROTECTED]]
Sent: Tuesday, 19 September 2000 10:35 AM
To: 'Andrew Fullagar'; fw-1-mailinglist@lists. us. checkpoint. com (E-mail)
Subject: RE: [FW1] 4.1 & terminal server?


nope.. win2k built in terminal server.  I confirmed app functionality.. did
a couple tcpdumps, it seems like connections are receiving requests but the
servers appear to just not send data back.. about the only thing I can think
of that could've caused this was an upgrade from 4.0 to 4.1?  Anyone else
having issues with 4.1?  (or maybe I should re-install those binaries...)
 
SF.client -> SF.firewall -> <encrypt> -> DS1 -> SC.firewall.stonebeat ->
<decrypt> -> SC.server ... and vice versa
 

-----Original Message-----
From: Andrew Fullagar [mailto:[EMAIL PROTECTED]]
Sent: Monday, September 18, 2000 3:08 PM
To: 'Peter Mueller'; fw-1-mailinglist@lists. us. checkpoint. com (E-mail)
Subject: RE: [FW1] 4.1 & terminal server?



Are you using Citrix metaframe  - That uses tcp 1494 but not termianl server
by itself - it uses something else 

-----Original Message----- 
From: Peter Mueller [ mailto:[EMAIL PROTECTED]
<mailto:[EMAIL PROTECTED]> ] 
Sent: Monday, September 18, 2000 1:18 PM 
To: fw-1-mailinglist@lists. us. checkpoint. com (E-mail) 
Subject: [FW1] 4.1 & terminal server? 



Anyone having any issues with win2k terminal services & firewall-1 version 
4.1?  Just doing a sanity check while I discourse into finer details... 

current ports I have listed for terminal server: 

1494 tcp 
1604 udp 


============================================================================
==== 
     To unsubscribe from this mailing list, please see the instructions at 
               http://www.checkpoint.com/services/mailing.html
<http://www.checkpoint.com/services/mailing.html>  
============================================================================
==== 

***************************************************
This e-mail is  not an  official  statement of  the
Waikato  Regional  Council unless otherwise stated.
Visit our website http://www.ew.govt.nz
***************************************************


================================================================================
     To unsubscribe from this mailing list, please see the instructions at
               http://www.checkpoint.com/services/mailing.html
================================================================================

Reply via email to