3
1
I have a small server behind my router which runs Windows 10. It's pretty easy to set up remote desktop directly to the internet and expose the required port by changing the configuration of the router.
Question: Do I have to be aware of security issues refering to that? I mean my server is at least accessable by everyone who knows a valid username/password combination.
If you want to restrict who can access your PC, choose to allow access only with Network Level Authentication (NLA). When you enable this option, users have to authenticate themselves to the network before they can connect to your PC. Allowing connections only from computers running Remote Desktop with NLA is a more secure authentication method that can help protect your computer from malicious users and software. To learn more about NLA and Remote Desktop, check out Configure NLA for RDS Connections.
Read some of this over.... https://security.berkeley.edu/resources/best-practices-how-articles/system-application-security/securing-remote-desktop-rdp-system. The NLA will prompt for username and password without showing the login screen I believe and exposing usernames that may be setup as local user accounts on the machine. I personally prefer not exposing RDP to the Internet but if so I block all public IP addresses and whitelist only the one or range that is allowed to access it. (cont...)
– Pimp Juice IT – 2018-12-12T14:07:44.6931If those aren't possible, change the port to use something other than 3389, ensure NLA is enabled, be sure to allow only the user account RDP access that needs it and restrict all other accounts, be sure that account has a super long and complex password (e.g.
H3llo & welcome to my party@#911
), and be sure the account lockout thresholds are setup as well. Don't have time to add an answer right now, but wanted to share the detail in case it helps you so just tag me back and let me know what you think if you want. I'll be freed up more here in a few hours. – Pimp Juice IT – 2018-12-12T14:07:47.543Mr. Sponge Bob's Snail - Did you go with something specific or what to help with this exposure? – Pimp Juice IT – 2018-12-13T20:47:00.257