<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Drive sharing happens when connecting a windows machine via RDP using MSTC client. How to block that? in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/drive-sharing-happens-when-connecting-a-windows-machine-via-rdp/m-p/15094#M11073</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;When connecting a windows machine via RDP using mstsc client, we have an option to share the local resources like printer, clipboard, etc. By this way we can able to share the local hard disk drives with the remote machine that we connect to. Upon connecting, our local drives are shown as the network drives on the remote computer. I noticed two app-ids are popping in the traffic logs during this transaction... ms-rdp and t.120..... Blocking either of the app-id is not letting me to even connect to the remote computer... Is there any way to block the resource sharing while just allowing the RDP alone?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 24 May 2013 05:22:58 GMT</pubDate>
    <dc:creator>VinothV</dc:creator>
    <dc:date>2013-05-24T05:22:58Z</dc:date>
    <item>
      <title>Drive sharing happens when connecting a windows machine via RDP using MSTC client. How to block that?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/drive-sharing-happens-when-connecting-a-windows-machine-via-rdp/m-p/15094#M11073</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;When connecting a windows machine via RDP using mstsc client, we have an option to share the local resources like printer, clipboard, etc. By this way we can able to share the local hard disk drives with the remote machine that we connect to. Upon connecting, our local drives are shown as the network drives on the remote computer. I noticed two app-ids are popping in the traffic logs during this transaction... ms-rdp and t.120..... Blocking either of the app-id is not letting me to even connect to the remote computer... Is there any way to block the resource sharing while just allowing the RDP alone?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 24 May 2013 05:22:58 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/drive-sharing-happens-when-connecting-a-windows-machine-via-rdp/m-p/15094#M11073</guid>
      <dc:creator>VinothV</dc:creator>
      <dc:date>2013-05-24T05:22:58Z</dc:date>
    </item>
    <item>
      <title>Re: Drive sharing happens when connecting a windows machine via RDP using MSTC client. How to block that?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/drive-sharing-happens-when-connecting-a-windows-machine-via-rdp/m-p/15095#M11074</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The Remote Desktop protocol is encrypted so granular control over specific functions within the session is not possible from the firewall.&amp;nbsp; You will need to utilize group policies on the server side machine to disallow drive mapping from the client.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 24 May 2013 05:38:48 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/drive-sharing-happens-when-connecting-a-windows-machine-via-rdp/m-p/15095#M11074</guid>
      <dc:creator>kfindlen</dc:creator>
      <dc:date>2013-05-24T05:38:48Z</dc:date>
    </item>
    <item>
      <title>Re: Drive sharing happens when connecting a windows machine via RDP using MSTC client. How to block that?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/drive-sharing-happens-when-connecting-a-windows-machine-via-rdp/m-p/15096#M11075</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;What kfindlen said is completely true.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Another way we have restricted resource sharing (for servers/workstations that are not necessarily members of the same domain) is to use Microsoft's "Remote Desktop Gateway" service.&lt;/P&gt;&lt;PRE __jive_macro_name="quote" class="jive_text_macro jive_macro_quote"&gt;
&lt;P&gt;&lt;A class="active_link" href="http://technet.microsoft.com/en-us/library/dd560672.aspx"&gt;http://technet.microsoft.com/en-us/library/dd560672.aspx&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="color: #2a2a2a; font-family: 'Segoe UI', 'Lucida Grande', Verdana, Arial, Helvetica, sans-serif;"&gt;Remote Desktop Gateway (RD Gateway), formerly Terminal Services Gateway (TS Gateway), is a role service in the Remote Desktop Services server role included with Windows Server® 2008 R2 that enables authorized remote users to connect to resources on an internal corporate or private network, from any Internet-connected device that can run the Remote Desktop Connection (RDC) client. The network resources can be Remote Desktop Session Host (RD Session Host) servers, RD Session Host servers running RemoteApp programs, or computers and virtual desktops with Remote Desktop enabled. RD Gateway uses the Remote Desktop Protocol (RDP) over HTTPS to establish a secure, encrypted connection between remote users on the Internet and internal network resources.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="color: #2a2a2a; font-family: 'Segoe UI', 'Lucida Grande', Verdana, Arial, Helvetica, sans-serif;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;

&lt;/PRE&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Basically at the firewall you only allow RDP connections to the RDP gateway, and at the RDP gateway you can granularly control what resource sharing is allowed or disallowed.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Microsoft's RDP client natively supports the RDP gateway feature as well.&lt;/P&gt;&lt;P&gt;&lt;IMG __jive_id="6665" alt="rd_gateway.jpg" class="jive-image-thumbnail jive-image" height="439" src="https://live.paloaltonetworks.com/legacyfs/online/6665_rd_gateway.jpg" style="height: 439px; width: 531.9359331476323px;" width="532" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 24 May 2013 13:13:04 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/drive-sharing-happens-when-connecting-a-windows-machine-via-rdp/m-p/15096#M11075</guid>
      <dc:creator>ericgearhart</dc:creator>
      <dc:date>2013-05-24T13:13:04Z</dc:date>
    </item>
    <item>
      <title>Re: Drive sharing happens when connecting a windows machine via RDP using MSTC client. How to block that?</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/drive-sharing-happens-when-connecting-a-windows-machine-via-rdp/m-p/15097#M11076</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; Thank you for the post. Can we utilize the Remote Desktop Gateway service for RDP between end systems.&amp;nbsp; For example I am having two lab networks which needs RDP between each other. Each has about 250+ computers. Can we utilize the RDP Gateway service for this setup? &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 28 May 2013 08:31:15 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/drive-sharing-happens-when-connecting-a-windows-machine-via-rdp/m-p/15097#M11076</guid>
      <dc:creator>VinothV</dc:creator>
      <dc:date>2013-05-28T08:31:15Z</dc:date>
    </item>
  </channel>
</rss>

