Control RDP Access via Plesk Firewall Rules

Discussion in 'Installation and Configuration in Windows and Linux' started by prussell, Nov 12, 2010.

  1. prussell

    prussell Bit poster

    Messages:
    2
    I am trying to pass a PCI scan, and have one issue I need to deal with. It appears the scan is failing due to RDP access on port 3389. Below is the recommendation:

    Configure Terminal Services to utilize SSL for authentication of the
    server. It is important that the RDP clients be configured to trust the
    server's SSL Certificate, otherwise the opportunity for a man-in-themiddle
    attack still exists. Please reference the provided Microsoft Technet
    article that explains how to do this. Industry best practices recommend
    that access to RDP/Terminal Services be restricted by firewall rules.
    When using Remote Desktop across the Internet, consider a VPN to
    establish the remote link to your network prior to establishing an RDP
    session.

    As a quick solution, I disabled the RDP Firewall rule via 'Manage Firewall Rules' in Plesk. The problem is that I can still remote in even though the Plesk RDP Firewall Rule is disabled. My understanding is that if the rule is disabled it will not be allowed. The scan also still fails.

    Any ideas as to why I am still able to remote in on port 3389 when I have the rule disabled?
     

Share This Page