Score:0

Securely connecting to clients via RDP over VPN

in flag

I have a network connectable by VPN, and want to limit most users to only be able to access certain hosts, indirectly.

It consists of several Windows hosts that will be connected by RDP. I'm more of a general guy and don't have so much knowledge about Windows Server and Terminal Services to be honest.

My goal is that the user will be able to RDP to one single machine, and from there be allowed to RDP to the the other internal servers / computers. I intend to do this by making a separate VLAN for this machine and make access rules in the firewall. The connecting users will only be able to access this VLAN, and must use this machine to access the other computers by RDP exclusively. I have planned to implement a new server that will run admin tasks such as WSUS and backup. This might be a dumb question, but do I have to use a blank separate computer for this task, or is it a good idea to do this on the new server? I guess make a blank desktop for each user that logs in via RDP to this server without any rights on the machine other than to use RDP, from where they can make a forward RDP connection to their desired server.

Thanks in advance for any input..

joeqwerty avatar
cv flag
If your servers are only available via the VPN connection, why do you need/want a jumphost?
in flag
If you really need a jump box (which I see no reason for) you should consider rdpgw instead. If not, have you thought about all the licenses and resources that is needed to run RDP in RDP?
Vincent Vega avatar
in flag
There will be only a couple of users of the system, so I’m not too worried about system resources. But this is a high security system. I’m not worried about the remote connection per se, what I’m concerned about is exposing the internal hosts to my clients computers that I have no control over. Right now, connecting to the system assigns an IP in the same subnet and I can freely talk to any host on any port. Open for alternative suggestions. Maybe making a profile where the VPN client gets an IP on another VLAN and from there can RDP to the inside hosts with strict access rules?
mangohost

Post an answer

Most people don’t grasp that asking a lot of questions unlocks learning and improves interpersonal bonding. In Alison’s studies, for example, though people could accurately recall how many questions had been asked in their conversations, they didn’t intuit the link between questions and liking. Across four studies, in which participants were engaged in conversations themselves or read transcripts of others’ conversations, people tended not to realize that question asking would influence—or had influenced—the level of amity between the conversationalists.