<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic RDP Access-List in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/rdp-access-list/m-p/1747673#M533472</link>
    <description>&lt;P style="margin: 0in; margin-bottom: .0001pt;"&gt;Dear Experts,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="margin: 0in; margin-bottom: .0001pt;"&gt;Just want to ask you if&amp;nbsp; can i permit RDP connection to AD Server but at the same time deny all outgoing traffics from such server - if I am connected through RDP ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="margin: 0in; margin-bottom: .0001pt;"&gt;Example :&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="margin: 0in; margin-bottom: .0001pt;"&gt;AD : 192.168.0.100&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="margin: 0in; margin-bottom: .0001pt;"&gt;Exchange : 192.168.0.200&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="margin: 0in; margin-bottom: .0001pt;"&gt;If someone connects to AD through RDP , I need to deny him to make telnet to Exchange or make any access to LAN servers (Just if he connected&amp;nbsp; through RDP)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
    <pubDate>Mon, 11 Mar 2019 21:12:10 GMT</pubDate>
    <dc:creator>islam.irshaid</dc:creator>
    <dc:date>2019-03-11T21:12:10Z</dc:date>
    <item>
      <title>RDP Access-List</title>
      <link>https://community.cisco.com/t5/network-security/rdp-access-list/m-p/1747673#M533472</link>
      <description>&lt;P style="margin: 0in; margin-bottom: .0001pt;"&gt;Dear Experts,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="margin: 0in; margin-bottom: .0001pt;"&gt;Just want to ask you if&amp;nbsp; can i permit RDP connection to AD Server but at the same time deny all outgoing traffics from such server - if I am connected through RDP ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="margin: 0in; margin-bottom: .0001pt;"&gt;Example :&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="margin: 0in; margin-bottom: .0001pt;"&gt;AD : 192.168.0.100&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="margin: 0in; margin-bottom: .0001pt;"&gt;Exchange : 192.168.0.200&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="margin: 0in; margin-bottom: .0001pt;"&gt;If someone connects to AD through RDP , I need to deny him to make telnet to Exchange or make any access to LAN servers (Just if he connected&amp;nbsp; through RDP)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 21:12:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/rdp-access-list/m-p/1747673#M533472</guid>
      <dc:creator>islam.irshaid</dc:creator>
      <dc:date>2019-03-11T21:12:10Z</dc:date>
    </item>
    <item>
      <title>RDP Access-List</title>
      <link>https://community.cisco.com/t5/network-security/rdp-access-list/m-p/1747674#M533475</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;If you want to do that then you really need to have the AD server on a separate DMZ. Even private vlans would not help in this situation because the AD server needs to communicate with other LAN servers.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So you would need a DMZ on the firewall for the AD server or at the very least a different vlan for the AD server that you can apply an access-list to.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Having said that if you did move your AD server to a DMZ then you would have to open a fair few ports to allow it to communicate to the servers on the LAN. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It's not an easy thing to do either way.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jon&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 16 Aug 2011 12:12:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/rdp-access-list/m-p/1747674#M533475</guid>
      <dc:creator>Jon Marshall</dc:creator>
      <dc:date>2011-08-16T12:12:41Z</dc:date>
    </item>
  </channel>
</rss>

