Setting Up A Remote Desktop Connection (Somewhat) Securely

(If you have a Mac at home go to this page)

This guide assumes that you want to connect from your home computer off campus to your office computer on campus. However, it works equally well for connecting from any off campus computer to any on campus computer you have control of that is on the wired or secure wireless network.

From your office PC

First you have to set up your office computer to accept incoming RDC.

Set up the RDC server

Right click My Computer and choose Properties. Choose the Remote tab and check the box that 'Allows users to connect remotely to this computer'.

Click Apply then click OK to close System Properties.

Modify the firewall to only allow connections through the VPN

  1. Go to Start>Settings>Control Panel

  2. Double click Security Center then choose to manage security settings for: Windows Firewall.

  3. Once in the settings for Windows Firewall, choose the Exceptions tab and make sure that Remote Desktop is checked and if not, check the box. Then click Edit.

    <
  4. Highlight TCP 3389 and click 'Change Scope'.

  5. Select Custom list and type in the following: 129.64.4.0/24

  6. Save settings by clicking OK to all the open windows.

Find out your office IP address

Open https://unet.brandeis.edu/my_ip.php.

A webpage will open, displaying your IP address. Copy down the IP Address which will need to be entered from the home computer being used to connect. You can then close the webpage.

From your home PC

Open a web browser and navigate to http://wormhole.brandeis.edu

At the log in screen, enter your UNet username and password and click Sign In.

An Internet Security window will pop up. Check the box to 'remember this decision' and click 'allow'.

Once successfully logged into Wormhole for the first time a Terminal Session will need to be established. This will only have to be done once and the settings will be saved for future logins.

Step 4: Click the computer icon denoted below to create a new terminal session.

Step 5: Enter in a Bookmark name and a Description for what you would like this session to be called. For the Host enter in your Brandeis computer's IP Address obtained in Step 3. The Screen Size should be set to Full Screen. Change the Color Depth to 16-bit. Session type should be set to Windows Terminal Services. When finished click 'Add'.

Step 6: You can now choose to log into the session just created by clicking the bookmark name.

A security warning will appear. Choose to always trust Juniper Networks.

NOTE: The first time running this a software install will occur.

You may also recieve a Windows Firewall prompt asking whether to unblock 'dsTermServ Module'. Choose Unblock. (This prompt will only appear the first time you log in)

You will now see your Brandeis computer terminal. Use your Unet username and password to log in.

When connecting from off campus in the future, enter the address http://wormhole.brandeis.edu into any PC web browser and continue through the login process.

Important Notes on Policy and Security

Using the Brandeis VPN service subjects the user to the same restrictions and responsibilities as a campus user (http://lts.brandeis.edu/about/policies/computingpolicies.html). Connections via VPN are considered direct connections to the campus network. All connection attempts are logged.

VPN users will be automatically disconnected from the Brandeis network after a predetermined amount of inactivity. The user can immediately logon again to reconnect to the Brandeis network - no work will have been lost.

Additionally, please be mindful of where you use the VPN to connect to your desktop. All computers connected to Brandeis internal networks via VPN must use the most up-to-date anti-virus software; this includes personal computers. Malicious software can log your keystrokes and steal your password. Do not use the VPN in cyber cafes, public clusters or from any computer that you do not completely trust.

This page was last modified on: Apr 14, 2008