Huge number of RDP connections blocked

CrucialTech
Conversationalist

Huge number of RDP connections blocked

I am showing about 83,000 'Microsoft Windows Terminal server RDP over non-standard port attempt ' in the security center of an MX65 in the last 2 weeks. Mostly from Russia but also from other European countries and the US too.

 

I do have port forwarding set up for RDP but client VPN is set up and being used by authorized users. I have one other port open for an ACT database sync. My understanding is that if the VPN is set up that is the only way in and these attempts will always fail. Do I have anything to worry about? Is there anything I can do to prevent this... seems like they've got my number!

 

Thanks

 

8 Replies 8
PhilipDAth
Kind of a big deal
Kind of a big deal

If you don't have any externally exposed RDP ports then you have nothing to worry about.

Sorry I mis-read.  You do have a NAT allowing RDP from the outside world.

 

Considering you have client VPN configured - I'd remove that RDP NAT.

To be clear, I do not have any 1:1 NAT rules or 1:many NAT rules. I do have several port forwarding rules so that individuals can RDP into their specific machine.

 

With the client VPN running on my home machine I can RDP into the site. Without the VPN running, I can't. So I'm thinking all is fine but was just checking to be sure that no RDP is possible without the client running through the VPN.

 

Thank you

You shouldn't need port forwarding if you VPN in?

Really? We can set up RDP without port forwarding? Can you point me in the right direction to accomplish that? Thank you

There is literally nothing to do.  Just VPN in and RDP directly to the machines private IP address.

Allowing external RDP conections is very risky. As suggested I would use VPN instead and then your users can RDP to the machine using its LAN IP. 

Of course... easy peasy. I will do that and then remove the port forwarding rules. Thanks for the tip.

Get notified when there are additional replies to this discussion.
Welcome to the Meraki Community!
To start contributing, simply sign in with your Cisco account. If you don't yet have a Cisco account, you can sign up.
Labels