Link to home
Start Free TrialLog in
Avatar of smithware
smithware

asked on

Terminal Services & Security

Hey All,

   I don't have one actual question, I'm looking for suggestions/advice and a couple of answers.  I am setting up a TS server inside my firewall.  The people I will have using it need access to Outlook (& conversely, our exchange server), a db client app, and possibly a network share or two.  What is the most secure method of setting this up?  Some of the issues I have are:  

- Should I have them VPN into the TS machine (NAT on a non standard port) itself rather than our regular VPN server?
- Should/can this sever be on it's own domain or workgroup?
- Should/can this server be on it's own subnet?
- What else should I consider in locking down this access?

Basically, I need the MOST secure setup I can have in this situation.  If the network share is a problem (as I see it), that's not critical.  Outlook and the Client app are.
ASKER CERTIFIED SOLUTION
Avatar of Rich Rumble
Rich Rumble
Flag of United States of America image

Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
Avatar of smithware
smithware

ASKER

Decent suggestions, but perhaps I should clarify myself....  I'm not really worried about security from the outside.... what I really want to do is secure my network from one of the people I have to give TS access to... I want to make sure he doesn't have access to the rest of my network....  while my internal security is fairly strong, I'd like to know how to make it even more secure....   definately I'd like to put him on a different domain, I think.... that would take my normal security right out of play.... and he doesn't really need access to domain resources.   He'll need to have a domain account on my main domain for the exchange ser ver, but it doesn't have to have logon rights.  What else can I do?  different subnet with routing tables to connect to the 2 servers he needs?