Page 1
Page 1
Started By
Message

Thinking of turning remote desktop back on. How to 2FA?

Posted on 1/4/23 at 7:48 am
Posted by CAD703X
Liberty Island
Member since Jul 2008
86702 posts
Posted on 1/4/23 at 7:48 am
I've had to work around not having access to my local network for a couple years after being gun shy after being hacked.

The only way I would trust it again is if I can easily enable 2FA.

Anyone done this? Can it be done without installing or purchasing additional software?

Note: for various reasons TeamViewer is not an option.
Posted by dakarx
Member since Sep 2018
7830 posts
Posted on 1/4/23 at 7:57 am to
Exposing Windows to the public network is NEVER a good idea. A better alternative would be to use OpenVPN to create a secure tunnel to your LAN. Most decent firewalls (pfSense, OpenSense,etc) have this ability built in by default and are easily set up.

Posted by jdd48
Baton Rouge
Member since Jan 2012
22822 posts
Posted on 1/4/23 at 7:59 am to
If you don't want to have to purchase something, I'd likely use something like a self signed SSL certificate to secure the RDP connection. It's not MFA really, but it's better than just having it exposed with no other security in place other than a password. VPN is another alternative.
This post was edited on 1/4/23 at 8:00 am
Posted by t00f
Not where you think I am
Member since Jul 2016
99822 posts
Posted on 1/4/23 at 8:17 am to
quote:

Exposing Windows to the public network is NEVER a good idea. A better alternative would be to use OpenVPN to create a secure tunnel to your LAN. Most decent firewalls (pfSense, OpenSense,etc) have this ability built in by default and are easily set up.



100%
Posted by CAD703X
Liberty Island
Member since Jul 2008
86702 posts
Posted on 1/4/23 at 8:27 am to
If I plan to use my phone to connect, are those VPN options still viable?

I may use a PC occasionally to log in but primarily I will be using an Android phone to log in and restart services, etc.
Posted by j1897
Member since Nov 2011
3901 posts
Posted on 1/4/23 at 8:45 am to
I use SSH tunnel, if i need to do from phone i spin up an azure vm that has the ssh key on it. I would never trust RDP
Posted by dakarx
Member since Sep 2018
7830 posts
Posted on 1/4/23 at 9:36 am to
quote:

If I plan to use my phone to connect, are those VPN options still viable?


Definately! Wife uses it continuously to connect to the CCTV systems from remote using her android phone (they are blocked from talking outside of the local networks), when I'm at the office i'm able to connect via my phone or my personal laptop (or both if i need a hotspot) to access my home lab networks.
This post was edited on 1/4/23 at 9:37 am
Posted by mchias1
Member since Dec 2009
904 posts
Posted on 1/4/23 at 10:06 am to
OpenVPN will work for your phone as long as it's an android. Last I checked there was no apple openVPN app.

If you set up a home VPN you will need to set up a dynamic DNS as well.


If you want to connect to a computer try chrome RDP. It uses your Google login which already has 2FA if you set it up.
Posted by hogdaddy
Krotz Springs
Member since Feb 2010
5154 posts
Posted on 1/4/23 at 10:09 am to
Try Remote Utilities.
You can sign up and get a free license. LINK
Posted by t00f
Not where you think I am
Member since Jul 2016
99822 posts
Posted on 1/4/23 at 10:59 am to
quote:

Last I checked there was no apple openVPN app.


I have openvpn on my macbook
Posted by junkfunky
Member since Jan 2011
34969 posts
Posted on 1/4/23 at 11:20 am to
quote:

If you want to connect to a computer try chrome RDP. It uses your Google login which already has 2FA if you set it up.



This is what I do. It's not great but they are constantly adding features to make it more friendly. I use it often from a PC but have logged in on my phone to do something quick plenty of times.
Posted by HailToTheChiz
Back in Auburn
Member since Aug 2010
51954 posts
Posted on 1/5/23 at 10:02 pm to
quote:

for various reasons TeamViewer is not an option.


As someone who uses team viewer, what's the knock?
Posted by BabySam
FL
Member since Oct 2010
1528 posts
Posted on 1/6/23 at 6:16 am to
Vulnerabilities and not knowing who could potentially expose/exploit a connection/data
Posted by dakarx
Member since Sep 2018
7830 posts
Posted on 1/6/23 at 4:09 pm to
quote:

As someone who uses team viewer, what's the knock?


Team Viewer MUST talk to a 3rd party server on the public internet to function. If you can connect to it, others can as well.
Posted by td1
Baton Rouge
Member since Oct 2015
3069 posts
Posted on 1/8/23 at 12:24 pm to
Tailscale
Posted by lockthevaught
Member since Jan 2013
2596 posts
Posted on 1/10/23 at 3:15 pm to
You need VPN that directly connects to your firewall.

I have a Palo Alto Firewall and use Global Protect as my VPN client. I have Global Protect setup with Azure Active Directory single sign on (SSO) integration and use the Microsoft Authenticator app for my MFA.
Posted by OSoBad
Member since Nov 2016
2007 posts
Posted on 1/11/23 at 7:19 pm to
quote:

Tailscale


Bingo, this is what we use to access my Blue Iris camera server remotely. Almost an instant connection, works great.
Posted by CAD703X
Liberty Island
Member since Jul 2008
86702 posts
Posted on 1/16/23 at 1:32 pm to


THANK YOU FOR TAILSCALE!!

Loving it so far (and its free).

Quick question; how do you share files using tailscale? Is there a best practice to move files between machines?
Posted by ColdDuck
BR via da Parish
Member since Sep 2006
2892 posts
Posted on 1/19/23 at 7:44 am to
DUO supports RDP. Like $2 a month per account.
Posted by humblepie
Member since May 2008
536 posts
Posted on 1/19/23 at 8:53 am to
quote:

Quick question; how do you share files using tailscale? Is there a best practice to move files between machines?


Any way you would normally share files between two computers on your local network should work normally.

I have previously tested tailscale some and it seemed to work great. I stayed with using the wireguard app though because I can automate the vpn connection going up or down based on conditions on our android phones but couldnt get that to work with tailscale.
first pageprev pagePage 1 of 1Next pagelast page
refresh

Back to top
logoFollow TigerDroppings for LSU Football News
Follow us on X, Facebook and Instagram to get the latest updates on LSU Football and Recruiting.

FacebookXInstagram