Koldov Posted March 8, 2017 Posted March 8, 2017 (edited) Hi, Just wondering if anyone uses RDP through LGfL's Rav3 remote solution? Having a minor niggle when trying to log in to the server remotely and it is requesting I insert a smart card (Server 2012R2)... I have found a similar issue online and the answer seems to be a change in the GPO for interactive login (disable smart card). I have deployed that GPO and it shows as applying, but I am still getting the smart card prompt. I can log in though by using the 'other user' box and just supplying the same credentials as the original 'administrator' box I normally click on. The server is always logged off and I haven't tried leaving it logged on (and don't really want to), but just in case I leave a session open to finish a job and remote in later to close it off or reboot. I'd rather not use the other VPN\Cisco options and would like to keep it all standard software wise. Anyone else had this? I also had to disable 'Allow connections only from computers running Remote Desktop with Network Level Authentication (more secure)' seems like I'm making my server a bigger target just to try and get 'secure' remote access with a tool we've already paid for. Might just go back to Teamviewer.... Edited March 8, 2017 by Koldov
fiza Posted March 8, 2017 Posted March 8, 2017 I use RAV3 for remote access but I prefer the Cisco Anyconnect route.
DavR Posted March 9, 2017 Posted March 9, 2017 I assume this behavior is via remote access only, and it works fine locally? I'm RDPing to Server 2012 R2 via RAv3 without any difficulty... here are my settings if it's any help! System Properties | Remote: Allow Remote Connections - Yes Require NLA - No Group Policy | Local Policies | Security Options: Domain controller: LDAP server signing requirements - None Domain member: Digitally encrypt or sign secure channel data (always) - Disabled Domain member: Digitally encrypt secure channel data (when possible) - Enabled Microsoft network server: Digitally sign communications (always) - Disabled Microsoft network server: Digitally sign communications (if client agrees) - Enabled Network security: Force logoff when logon hours expire - Disabled Network security: LAN Manager authentication level - Send NTLM response only User Account Control: Turn on Admin Approval Mode - Disabled DISCLAIMER - these are my settings for reference, not suggesting this is adequate or otherwise security. 1
Koldov Posted March 9, 2017 Author Posted March 9, 2017 (edited) Thanks for that! Yes this issue presents purely via remote access, local log on at the machine is fine (also RDP from any other machine on the domain network also works ok). I'm interested to note that you have no 'smart card' settings at all. Yet when I click on the admin account to log on, I get the prompt to insert smart card even though I appear to have disabled the need for it via GPO... Also, are these the settings you have verified are definitely needed to get RDP via RAv3 to work? As in there are no extranious settings, these have been configured solely to get RDP to work via RAv3. Edited March 9, 2017 by Koldov
DavR Posted March 9, 2017 Posted March 9, 2017 Yeah, my smart card options are currently undefined, looking at the setting the default is disabled anyway. Those settings aren't necessarily required for RDP via RAv3, they're just the only settings I have that aren't still on the defaults. Tbh, I couldn't tell you what some of them do off the top of my head, I didn't set up this box. 1
DavR Posted March 9, 2017 Posted March 9, 2017 Only other thoughts are that it might take a reboot to disable the Smart Card prompt, or has the user got Smart Card Required box ticked on their AD account(Account tab | Account Options)?
Koldov Posted March 9, 2017 Author Posted March 9, 2017 (edited) Ok thanks. I've raised the issue with support, was just hoping to get a resolution before needing to do that. I'm hoping they don't turn round and say it's not their problem as they don't support our servers. I have researched, but can't find any other answers. Possibly only that with a local RDP session, the Username and Password are sent to the machine with the connection and it appears that with the remote session this is not the case (although see below). However, as mentioned I can choose 'other user' and log on as admin ok. Interestingly though it does appear there is a username pushed through the RDP session as when I do click on 'other user' my USO username is already entered into the field, I just clear it and type in my Domain Admin credentials. Unfortunately we do not use USO usernames and passwords on our domain as yet. I wondered if you do? Or are you logging on as Domain admin/user? Edited March 9, 2017 by Koldov
Koldov Posted March 9, 2017 Author Posted March 9, 2017 Only other thoughts are that it might take a reboot to disable the Smart Card prompt, or has the user got Smart Card Required box ticked on their AD account(Account tab | Account Options)? No, I haven't rebooted. I have run RSOP and it appears to be applying though. I will log in with the workaround method and try tonight. It's the Domain Admin account but no, it doesn't have that option ticked. Good shout though, I didn't even know it was there!
DavR Posted March 9, 2017 Posted March 9, 2017 Ok thanks. I've raised the issue with support, was just hoping to get a resolution before needing to do that. I'm hoping they don't turn round and say it's not their problem as they don't support our servers. I have researched, but can't find any other answers. Possibly only that with a local RDP session, the Username and Password are sent to the machine with the connection and it appears that with the remote session this is not the case (although see below). However, as mentioned I can choose 'other user' and log on as admin ok. Interestingly though it does appear there is a username pushed through the RDP session as when I do click on 'other user' my USO username is already entered into the field, I just clear it and type in my Domain Admin credentials. Unfortunately we do not use USO usernames and passwords on our domain as yet. I wondered if you do? Or are you logging on as Domain admin/user? Nah, we don't use USO for domain logons, I'm logging on with domain admin credentials. They're not passed through, I'm prompted for them on connection like this. I never actually see the RDP full screen until after logon. Another place you could look is in the settings of your RDP client. On your source PC off site, on Remote Desktop Client, click show options and check under Advanced tab. Under the Connect from Anywhere options there is a whole bunch of stuff about gateways, and one of the drop downs does have Smart Card options. 1
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now