Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
mike1
New Contributor

RDP with forwarding ports or VPN with Forticlient?

Have a dilemma -

I have clients accessing there network server off site via RDP (example port 3391 forwarding over to 3389). Due to the potential risks using RDP I was thinking about using IPsec forticlient VPN then running RDP through the tunnel. Problem of course is a VPN has its own security risks potentially linking an undetected virus ridden PC to the companies lan. 

This is my dilemma...

Any thoughts and strong arguments on both would be appreciated

 

 

5 REPLIES 5
Toshi_Esumi
SuperUser
SuperUser

I'm assuming you would terminate the IPSecs at a FortiGate. Then you have an option to set AV and other UTM services on the tunnel policies.

mike1

Exactly,

only problem is I don't have control of the users home PC that would be connecting using the fortclient sw, this invites issues even if the proper policies are setup for the  tunnel, you agree or am I in error? 

 

Toshi_Esumi

I don't see much difference between two if you're concerning about the untrusted client devices injecting malicious stuff/attemps into inside of the protected network. You can use UTM for RDP VIP policy on the FortiGate as well. IPSec is to encrypt data over the internet not to be intercepted/eavesdropped by 3rd parties. For that part, of course, it's much better. FortiClient comes with Endpoint control, which I haven't used yet (I was hoping somebody else would comment about it), that would probably block from connecting for those contaminated client devices.

theFWdude

@Mike, why not use the SSL VPN Portal and enable "RDP" on the Portal?  This should launch a pre-configured RDP session in the browser to the remote host.  The concern you have with "Extending the wire" to an un-trusted host is very real.  Personally, this is the route I would go.

-TFWD

-TFWD
mike1

thank you ,

great suggestion, I will consider that

Announcements
Check out our Community Chatter Blog! Click here to get involved
Labels
Top Kudoed Authors