For a Microsoft Windows 2000 version of this article, see
the following Knowledge Base article:
315055 (http://support.microsoft.com/kb/315055/EN-US/) HOW TO: Use IPSec Policy to Secure Terminal Services Communications in Windows 2000
On This Page
SUMMARY
You can use Windows Server 2003 Terminal Services to access
programs in a multiple-user Terminal server environment. Communications between
the Terminal Services client computer and the server that has Terminal Services
enabled may contain sensitive information. Therefore, you may want to optimize
security between the Terminal Services client and the Terminal server. This
step-by-step article describes how to secure Terminal Services communications
by configuring the Terminal server to require varying degrees of encryption by
using the RC4 algorithm.
Many organizations use standardized Internet
Protocol security (IPSec) for network security. You can configure IPSec
policies on Terminal servers to make sure that IPSec protects all the Terminal
Services communications.
This article assumes that you are
configuring computers that are a part of a domain structure. If the computer is
not part of a domain structure, you may also have to configure encryption and
authentication services.
For additional information about troubleshooting
IPSec, click the following article number to view the article in the Microsoft
Knowledge Base:
257225 (http://support.microsoft.com/kb/257225/EN-US/)
Basic IPSec Troubleshooting in
Windows 2000
To enable IPSec protection for Terminal
Services:
1.
Create an IPSec filter list to match the Terminal Services
packets.
2.
Create an IPSec policy to enforce IPSec protection, and
then enable the policy.
3.
Enable the Client (respond-only) policy on the Terminal
Services clients.
How to Create the IPSec Filter List for Terminal Services Communications
1.
Click Start, click Run,
type gpedit.msc, and then click OK.
2.
Expand Computer Configuration, expand Windows Settings, expand Security Settings, right-click IP Security Policies, and then click Manage IP filter lists and filter actions.
3.
Click the Manage IP Filter Lists tab, and
then click Add.
4.
Type terminal services in the
Name box, and then type for terminal services
connections in the Description box.
5.
Click to clear the Use Add Wizard check
box, and then click Add.
6.
Click the Addressing tab, click My
IP Address in the Source address box, and then click
Any IP Address in the Destination address
box.
After you complete this step, the filter is applied to outbound
packets.
7.
Verify that the Mirrored check box is
selected.
If this check box is selected, a packet filter is created to
match the inbound packets. You must protect all the IPSec-secured
communications in both directions. You cannot have IPSec security in only one
direction.
8.
Click the Protocol tab, click
TCP in the Select a protocol box, and then
click From this port .
9.
Type 3389 in the From this
port box, click To any port, and then click
OK.
Contact Microsoft Phone Numbers, Support Options and Pricing, Online Help, and more.
Customer Service For non-technical assistance with product purchases, subscriptions, online services, events, training courses, corporate sales, piracy issues, and more.
Newsgroups Pose a question to other users. Discussion groups and Forums about specific Microsoft products, technologies, and services.