< Home

Preventing Nested Remote Desktop Connection

Prerequisites

The basic SSL VPN configurations have been completed.

Procedure

  1. Choose Network > SSL VPN > SSL VPN.
  2. Click for an SSL VPN gateway.
  3. Choose Terminal Security > Host Check.
  4. Select Host Check Function under Global Configuration, click Add under Host Check Policy List, and create a host check policy.

    After the Double-Hop RDC Denial function is enabled, the system checks the Microsoft Terminal Services Client (mstsc), pcanywhere, and VNC remote applications by default. Users can also define their own rules and specify the remote applications to be prevented.

  5. Select Role Authorization/User, reference a created host check policy in the corresponding role, and click OK.

Verifying the Configuration

  1. Enter https://1.1.1.1:443 in the address bar of Internet Explorer to access the SSL VPN login page.
  2. In the login window, enter the user name and password, and then click Login.
  3. After the login is successful, the system automatically disconnects the remote request when other users access the user host through the remote desktop program.

    It should be noted that Double-Hop RDC Denial is not about the user host remotely accessing another host, but about the user host being remotely accessed.

Copyright © Huawei Technologies Co., Ltd.
Copyright © Huawei Technologies Co., Ltd.
< Previous topic Next topic >