I would like to setup RDP for a small office of 7 users, I can easily set them up with the usual setup and opening ports on router, but I am pretty sure this is not the most secure method, I read that if I put all the machines behind a proper firewall this would make it more secured but I am not finding a lot of info on how much more secure it is and also how best to set one up.<\/p>","upvoteCount":12,"answerCount":10,"datePublished":"2022-06-07T18:22:28.000Z","author":{"@type":"Person","name":"robertlee9","url":"https://community.spiceworks.com/u/robertlee9"},"suggestedAnswer":[{"@type":"Answer","text":"
Advertisement
I would like to setup RDP for a small office of 7 users, I can easily set them up with the usual setup and opening ports on router, but I am pretty sure this is not the most secure method, I read that if I put all the machines behind a proper firewall this would make it more secured but I am not finding a lot of info on how much more secure it is and also how best to set one up.<\/p>","upvoteCount":12,"datePublished":"2022-06-07T18:22:28.000Z","url":"https://community.spiceworks.com/t/how-can-i-best-secure-rdp-connections-with-firewall/834571/1","author":{"@type":"Person","name":"robertlee9","url":"https://community.spiceworks.com/u/robertlee9"}},{"@type":"Answer","text":"
Advertisement
Never allow RDP over the Internet.<\/p>\n
Have people connect to your firewall / router via VPN. Then they are on the local network and can RPD as needed.<\/p>\n
Or, don’t use RDP at all. What are you trying to do here? Allow remote access to work machines? There are dozens of programs out there that do this and wouldn’t require VPN because they have their own secure connection methods.<\/p>\n
But, whatever you do, don’t open ports and allow RDP.<\/p>","upvoteCount":4,"datePublished":"2022-06-07T22:27:07.000Z","url":"https://community.spiceworks.com/t/how-can-i-best-secure-rdp-connections-with-firewall/834571/2","author":{"@type":"Person","name":"DragonsRule","url":"https://community.spiceworks.com/u/DragonsRule"}},{"@type":"Answer","text":"
I personally access RDP over the Internet and I used to find people accessing it online. I came up with simple solutions which are as follows;<\/p>\n
\n
I created an IP range<\/strong>, then I specified that only that IP range can connect over RDP.<\/li>\n
There was a tutorial online I read that changed the RDP port<\/strong> to any port that you wish (I didn’t do this though, much as it’s a good alternative as well<\/em>).<\/li>\n
I created a logon notification<\/strong> that lets me know the last time there was a sign in on the machine and if there were any failed sign in attempts, they are counted and displayed before the desktop is shown. The same script sends an email when a login is detected.<\/li>\n<\/ol>","upvoteCount":0,"datePublished":"2022-06-08T03:09:47.000Z","url":"https://community.spiceworks.com/t/how-can-i-best-secure-rdp-connections-with-firewall/834571/3","author":{"@type":"Person","name":"dedanrwakishaija","url":"https://community.spiceworks.com/u/dedanrwakishaija"}},{"@type":"Answer","text":"
The proper method to secure RDP is to funnel its traffic via a secure tunnel. The most straightforward and fastest way to implement it at your scale is to use Zerotier IMO. There are extra rules in Zerotier Central that you can use to narrow the remote access down to RDP protocol.<\/p>","upvoteCount":0,"datePublished":"2022-06-08T03:33:00.000Z","url":"https://community.spiceworks.com/t/how-can-i-best-secure-rdp-connections-with-firewall/834571/4","author":{"@type":"Person","name":"victorchupov","url":"https://community.spiceworks.com/u/victorchupov"}},{"@type":"Answer","text":"