Creating an RDP Server¶
Note
A server object can be linked to only one anonymous account.
A server object can be linked to only one forward account.
Fudo Enterprise allows authenticating against RDP server with Kerberos.
Click + icon next to the tab of the sub-section, or
Select > and then click .
Enter server’s unique name.
Select Blocked option if the object should be unavailable after creation. A blocked server cannot be used to establish connections until it is manually unblocked. Providing a reason for blocking is required.
Optionally, click the Description checkbox and provide a text that will help identifying this server object.
SETTINGS TAB
Go to the SETTINGS tab.
In the Protocol section, select .
Warning
After server’s definition is saved, protocol’s field is uneditable.
Select the TLS enabled to connect to monitored server over TLS.
Check the NLA enabled option for additional security.
Note
Security mode must match the security mode setting in the RDP listener configuration. The NLA enabled option within a server corresponds to the Enhanced RDP Security (TLS) option within the listener.
Select Legacy crypto option to allow negotiating older encryption algorithms (DSA(1024), RSA(1024)) when establishing connections.
Check the Inform about existing connection option to have the users informed that other users are connected to the server, they are trying to connect to.
From the Bind address drop-down list, select Fudo Enterprise IP address used for communicating with this server.
Note
The Bind address drop-down list elements are IP address defined in the Network configuration menu (Network Interfaces Configuration) or labeled IP addresses (Labeled IP Addresses).
In case of cluster configuration, select a labeled IP address from the Bind address drop-down list and make sure that other nodes have IP addresses assigned to this label. For more information refer to the Labeled IP Addresses topic.
In the Destination section select
Host,IPv4orIPv6. Enter server’s IP address.
Note
Depending on selected option, default values for the Mask and Port fields are filled out automatically. This way the Fudo Enterprise system detects server as one with unique address. In order to set up address for entire subnet, provide a dedicated value for the Address and the Mask fields.
In the case of overlapping address definitions, during connection establishment the more specific configuration (higher network mask) is always selected, even if the user does not have permissions assigned to it. This mechanism enables defining exceptions within broader access rules (e.g., granting access to
/24while explicitly excluding/32).
If the TLS enabled was checked, in the Server verification section select one of the following options:
Server certificateorCA certificateand provide respective certificate data. SelectNoneto disable server verification. To learn more about the RDP server certificate management, please follow the Managing RDP Server Certificates in Windows Server section.Otherwise, provide server key.
Click .
OBJECT RIGHTS TAB
The OBJECT RIGHTS tab is used to define which users and roles are allowed to manage the object and which capabilities (Read, Modify, Delete, Block) are assigned to them.
Go to the OBJECT RIGHTS tab.
Open the USERS sub-tab.
Click , select the users from the list, and click .
In the Users list, select the capabilities for each user by enabling one or more of the following options: Read, Modify, Delete, or Block.
Open the Roles sub-tab.
Click , select the roles from the list, and click .
In the Roles list, select the capabilities for each role by enabling one or more of the following options: Read, Modify, Delete, or Block.
Related topics: