Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations SkipVought on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

Terminal Services through Firebox 700

Status
Not open for further replies.

sborsos

MIS
Sep 2, 2002
10
0
0
CA
Could someone point me to some documentation on how to allow access to my terminal servers for remote administration? Thanks a lot.
 
MS Terminal Services? I do not know of any tutorial/docs for this, however it should be easy enough to determine what ports the services require and create a filter for them. I personally use VNC w/SSH2 exclusively for remote administration - great performance and exceptional security.
 
Most secure method is to use VPN. If you need assitance with this, let us know what type of VPN you would like to employ (PPTP or IPSec).
 
Thank you guys for responding.
I am reading the VPN guide for watchguard, but it is 140 pages long...
I am able to use Terminal Services from within the trusted interface. If i add a new service to do 1-1 NAT with port 3389 (the port that TS requires) would that allow TS access from the external?
 
Try it and let us know lol :)

Keep in mind you are walking on a slippery slope if you are using remote adminstration through the Firebox to the internal network WITHOUT a *secure* transport (encrypted tunnel).
 
Truly as ant2112 mentioned, that can be quite dangerous. If you are dead set against VPN, at the very least you should configure the service with a source and dest. IP to isolate the traffic.

Regarding VPN - if you have a license for MUVPN I can walk you through that configuration, or if you do not, PPTP is free and quite simple to configure on both the FB and the client.
 
Sorry to HiJack this thread but I notice NTrOP could probably help me with my problem.

I've connected to our Firebox using MUVPN, I can ping our network but I can't gain access to any resources. What Services in Policy Manager should I set up to enable me to access things like Exchange Server and Shared resources.

Sorry once again, any help would be greatly appreciated.

Thanks
 
To let TS through the FB you can create a custom service on the following ports:

TCP 3389 Ignore
TCP 1494 Ignore
TCP 80 Ignore

I would also recommend that you set up source and destination IPs for added security
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top