Consider these items.

Install most everything Windows Update suggests, including W2K SP2, SRP1,
and whatever hot fixes HFNETCHK suggests.  You can skip things like MSN
instant messenger, items related to multimedia (unless the purpose of this
box is multimedia).  Disable Net Meeting.

Bob

 -----Original Message-----
From:   Dean Cunningham [mailto:[EMAIL PROTECTED]] 
Sent:   Friday, February 01, 2002 9:08 PM
To:     NT 2000 Discussions
Subject:        RE: Terminal Server Security

and to really complement that and avoid hackers scanning that port look at
using firewall authentication off a radius server (in w2k/nt it is called
IAS). this requires the user to log in twice but then only exposes you to FW
hacks, which should be less prevalent than TS hacks...........

cheers
Dean

-----Original Message-----
From: Dennis Depp [mailto:[EMAIL PROTECTED]]
Sent: Saturday, 2 February 2002 9:55 a.m.
To: NT 2000 Discussions
Subject: Re: Terminal Server Security


Place it behind a firewall and only allow port 3389 thru.  Use High 
encryption.  Keep everything patched.

Denny

At 03:23 PM 2/1/2002 -0500, Phil wrote:
>I want to put a terminal server on the internet directly. What kind of
>precautions do I need to do in order to secure the box?
>I mean that I do not want to have people VPN into the network first.
>What are the security holes associated with doing this?
>When people lob in is it sent with plain text?
>
>Thanks!
>
>
>
>_________________________________________________________
>
>Do You Yahoo!?
>
>Get your free @yahoo.com address at http://mail.yahoo.com
>
>
>
>
>------
>You are subscribed as [EMAIL PROTECTED]
>Archives: http://www.swynk.com/sitesearch/search.asp
>To unsubscribe send a blank email to [EMAIL PROTECTED]


------
You are subscribed as [EMAIL PROTECTED]
Archives: http://www.swynk.com/sitesearch/search.asp
To unsubscribe send a blank email to [EMAIL PROTECTED]
***************************************************
This e-mail is  not an  official  statement of  the
Waikato  Regional  Council unless otherwise stated.
Visit our website http://www.ew.govt.nz
***************************************************

------
You are subscribed as [EMAIL PROTECTED]
Archives: http://www.swynk.com/sitesearch/search.asp
To unsubscribe send a blank email to [EMAIL PROTECTED]

CONFIDENTIALITY NOTICE: This E-Mail is intended only for the 
use of the individual or entity to which it is addressed and 
may contain information that is privileged, confidential and 
exempt from disclosure under applicable law. 
If you have received this communication in error, please 
do not distribute and delete the original message.  
Please notify the sender by E-Mail at the address shown. 
Thank you for your compliance.

------
You are subscribed as [email protected]
Archives: http://www.swynk.com/sitesearch/search.asp
To unsubscribe send a blank email to [EMAIL PROTECTED]

Reply via email to