Unable to open RDP connection to Server 2008 through VPN tunnel.


hi,

at workplace, we're facing interesting situation. using work network environment can connect servers (windows 2000 server, windows 2003 server , windows 2008 server) using rdp without problem. can use rdp workstations administer systems, workstations being windows xp , windows 7

however, when using vpn tunnel home through cisco concentrator (3 different employees tried 3 different locations using 3 different computers), able connect windows 2000 , 2003 systems (and windows xp workstations matter) not windows 2008 server or windows 7 workstations.

so question is, missing in network settings on systems make them not accept rdp connections coming outside? ipv6 setting or more illustrious altogether? know rdp works because can hook them when we're working on inside network, if they're in different subnet (10.10.x.0/8 vs 10.10.y.0/8).

any light on issue appreciated.

so, here's caused issue in our setup. might not same other setup, ymmv.

we have redundant firewall setup. firewall main active one, firewall b backup/failover. results in our machines having 3 default gateways defined : main backplane switch, firewall , firewall b.

this never posed issue on machine os before windows server 2008 or windows vista. apparently newer version of microsoft's os have different metric on how handle default gateways. use algorithm tries use shortest or quickest path, unfortunately means using firewall b (failover) instead of firewall since has hardly load.

the result of when comes external rdp connections on vpn tunnel external workstation connects via vpn concentrator through firewall a. workstation tries initiate contact (ack packets), , machines on corporate network (the windows 7 , windows 2008 machines) reply packets promptly syn packet use quickest path, firewall b. 

of course, vpn concentrator not fact packets coming through different firewall, drops them, results in external computer resending packets. after few retries connection times out.

 

we ended resolving issue removing firewall b default gateway list on workstations , server time being, until can figure out how direct use of default gateways in more reliable manner using metric.

 

so basically, if use vpn concentrator that's sensitive packets coming using different path, should be, rdp connections not work. different path can caused packets coming in through different network interface if vpn concentrator supports this.

 

polkaroo, if feel comfortable sharing setup can try , figure out solution.

 

wannes



Windows Server  >  Remote Desktop Services (Terminal Services)



Comments

Popular posts from this blog

server manager error: ADAM.events.xml could not be enumerated.

Cannot access Anywhere Access using domain name?

WMI Failure: Unable to update Local Resource Group