Quantcast
Channel: Symantec Connect - Products - Articles
Viewing all articles
Browse latest Browse all 818

SEP 12.1 Firewall - How to Block RDP while allowing only specific connections

$
0
0

This article will go into some detail on how to block RDP while allowing only specific connections using the SEP 12.1 firewall. This is also applicable to SEP 11.x.

Often times, a request comes in to block the RDP protocol for a group of machines but allow it to one "special" machine. Here's how we can accomplish that.

First, we need to Add a Network Service. Login to your SEPM and go to Policies >> Policy Components >> Network Services >> Add a Network Service

1_2.JPG

 

Add the necessary info for the RDP protocol. RDP works over TCP 3389:

2_2.JPG

 

3_2.JPG

 

Once finished, click OK to save your work. You now have a new network service added for RDP.

Now, you need to create the rules to block/allow RDP. You can either create a new firewall policy or edit your existing one. For this article, I started with a new one.

Let's first start by adding the "Block ALL RDP" rule

In your firewall policy, click Add Rule

Give it a name, click Next

Tick the radio button for Block connections, click Next

4_2.JPG

 

Tick the radio button for Only the applications listed below, click Add

5_2.JPG

 

Add the RDP filename, mstsc.exe, click OK

6_1.JPG

 

Select Any computer or site so all computers and sites will be blocked from using RDP, click Next

7_0.JPG

 

Add the RDP network services that you created earlier

8_0.JPG

 

Tick the radio for Yes to create a log entry, click Finish

The Block ALL RDP rule will be placed at the top.

Now, to create our Allow Specific RDP exclusion

Add another rule and give it a name, click Next

Tick the radio button for Only the applications listed below, click Add

5_2.JPG

 

Add the RDP filename, mstsc.exe, click OK

6_1.JPG

 

Now, we need to add what computer we want to have RDP access to. Tick the radio button for Only the computers and sites listed below, click Add:

9_0.JPG

 

You have a few options to choose from but I will add it by IP address

10_0.JPG

 

Add the RDP network services that you created earlier

8_0.JPG

 

Tick the radio button for Yes to create a log entry, click Finish

Move the Allow Specific RDP rule to the top, above the Block rule that you created. This ensures only the PC you specified as an exception can be RDP'd to.

11_0.JPG

 

Make sure you save your settings and that the firewall policy is correctly applied to the group.

First, let's attempt to RDP to a random machine:

Seems we cannot:

12_0.JPG

 

Upon checking the Traffic log, we see the following entry confirming our rule is working:

13_0.JPG

 

Let's try an RDP to our exception machine

14.JPG

 

Working as expected...

I hope this article will be helpful for you. Comments/Questions/Criticisms are encouraged

Brian

 

 

 

 


Viewing all articles
Browse latest Browse all 818

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>