small client - added and RDP for 3 users and DUO. RDP is facing the internet with a different port then 3389. Client does not want a VPN in addition to Duo - Any thoughts if this is secure enough or if there is some other security feature to add?
@NetworkWizkid2 жыл бұрын
Have you thought about using the Duo Network Gateway? This is VPNless and would allow you the ability to allow remote users to connect to RDP clients without exposing 3389 directly to the Internet. Let me know if you want more details.
@Shabab24262 жыл бұрын
@@NetworkWizkid Thanks for the reply - no, I was not aware of it. Please send more info.
@NetworkWizkid2 жыл бұрын
Here are some resources that will help: - DNG Deployment Series Playlist - This will give you a good idea of what the DNG is, how its deployed and how you can protect RDP sessions amongst other things: kzbin.info/aero/PLe-X5QS7NJKVKOyPc82Y6zf94LDg5LA_h - Duo DNG documentation: duo.com/docs/dng - Duo licensing: duo.com/editions-and-pricing The DNG should help meet your requirements while adding 2FA and additional security features as called out in the above links. I hope that helps but if you've got any other questions do let me know.
@colbyliy90582 жыл бұрын
Good information. Thank you 👍
@NetworkWizkid2 жыл бұрын
Thank you and thank you for watching
@alexandra.vasquez Жыл бұрын
Hi, thank you for sharing. I would appreciate your help cause i have 2 local account on my win. the new user that you create at the min 43 would replace one of these local accounts on windows or they are only who can acces to the windows general screen ? thank you
@NetworkWizkid Жыл бұрын
Hey, The users you add to Duo are the user accounts that will be used to access the machine. If the machine is domain joined, then you would need to make sure that the relevant accounts are in Duo. Likewise, if the users are local accounts, then you would also add those users to Duo too. Adding accounts to Duo doesn't replace any Windows account, we are simply just matching your local users and/or domain-joined users with the users in Duo so that we can carry out MFA. I hope that helps and thank you for watching.
@alexandra.vasquez Жыл бұрын
@@NetworkWizkid allright, Ill try thx :)
@truwarrior222 жыл бұрын
What if you lock the machine? Does it require Duo to unlock?
@NetworkWizkid2 жыл бұрын
If it has been configured to secure Windows logon and you lock the PC without the remember me (kzbin.info/www/bejne/Y6uUhGd7d82nf5I) policy configured then yes, you'll be required to perform 2FA again. Hope that helps.
@dhjoubert39 Жыл бұрын
I tried Duo o Windows server 2016. Logging in on RDP, it didn't show me the Duo page, it just refused to log me in. I had to disable it. Do you have any idea why?
@NetworkWizkid Жыл бұрын
It could be a number of things, so its hard to say without seeing it. I recommend that you take a look at the Duo FAQ's: duo.com/docs/rdp-faq and the installation guide: duo.com/docs/rdp
@dhjoubert39 Жыл бұрын
@@NetworkWizkid Thanks.
@dhjoubert39 Жыл бұрын
@@NetworkWizkid I found the issue. I tested on my desktop, but my server login username was different. I had to delete the test user account and create one for the server. Duo is actually great. I dig it. I had it hacked once before, but now I'm sure that would be much less likely to happen again.
@NetworkWizkid Жыл бұрын
Hey Deon, thank you for getting back to me! I'm glad that you got it working. Enjoy!