Jump to content

Recommended Posts

Posted (edited)

Hi,

 

Just wondering if anyone uses RDP through LGfL's Rav3 remote solution?

 

Having a minor niggle when trying to log in to the server remotely and it is requesting I insert a smart card (Server 2012R2)...

 

I have found a similar issue online and the answer seems to be a change in the GPO for interactive login (disable smart card).

 

I have deployed that GPO and it shows as applying, but I am still getting the smart card prompt.

 

I can log in though by using the 'other user' box and just supplying the same credentials as the original 'administrator' box I normally click on.

 

The server is always logged off and I haven't tried leaving it logged on (and don't really want to), but just in case I leave a session open to finish a job and remote in later to close it off or reboot.

 

I'd rather not use the other VPN\Cisco options and would like to keep it all standard software wise.

 

Anyone else had this?

 

I also had to disable 'Allow connections only from computers running Remote Desktop with Network Level Authentication (more secure)' seems like I'm making my server a bigger target just to try and get 'secure' remote access with a tool we've already paid for.

 

Might just go back to Teamviewer.... :getmecoat:

Edited by Koldov
Posted

I assume this behavior is via remote access only, and it works fine locally?

 

I'm RDPing to Server 2012 R2 via RAv3 without any difficulty... here are my settings if it's any help!

 

System Properties | Remote:

Allow Remote Connections - Yes

Require NLA - No

 

Group Policy | Local Policies | Security Options:

Domain controller: LDAP server signing requirements - None

Domain member: Digitally encrypt or sign secure channel data (always) - Disabled

Domain member: Digitally encrypt secure channel data (when possible) - Enabled

Microsoft network server: Digitally sign communications (always) - Disabled

Microsoft network server: Digitally sign communications (if client agrees) - Enabled

Network security: Force logoff when logon hours expire - Disabled

Network security: LAN Manager authentication level - Send NTLM response only

User Account Control: Turn on Admin Approval Mode - Disabled

 

DISCLAIMER - these are my settings for reference, not suggesting this is adequate or otherwise security.

  • Thanks 1
Posted (edited)

Thanks for that!

 

Yes this issue presents purely via remote access, local log on at the machine is fine (also RDP from any other machine on the domain network also works ok).

 

I'm interested to note that you have no 'smart card' settings at all. Yet when I click on the admin account to log on, I get the prompt to insert smart card even though I appear to have disabled the need for it via GPO...

 

Also, are these the settings you have verified are definitely needed to get RDP via RAv3 to work? As in there are no extranious settings, these have been configured solely to get RDP to work via RAv3.

Edited by Koldov
Posted

Yeah, my smart card options are currently undefined, looking at the setting the default is disabled anyway.

 

Those settings aren't necessarily required for RDP via RAv3, they're just the only settings I have that aren't still on the defaults. Tbh, I couldn't tell you what some of them do off the top of my head, I didn't set up this box.

  • Thanks 1
Posted
Only other thoughts are that it might take a reboot to disable the Smart Card prompt, or has the user got Smart Card Required box ticked on their AD account(Account tab | Account Options)?
Posted (edited)

Ok thanks.

 

I've raised the issue with support, was just hoping to get a resolution before needing to do that. I'm hoping they don't turn round and say it's not their problem as they don't support our servers.

 

I have researched, but can't find any other answers. Possibly only that with a local RDP session, the Username and Password are sent to the machine with the connection and it appears that with the remote session this is not the case (although see below).

 

However, as mentioned I can choose 'other user' and log on as admin ok. Interestingly though it does appear there is a username pushed through the RDP session as when I do click on 'other user' my USO username is already entered into the field, I just clear it and type in my Domain Admin credentials. Unfortunately we do not use USO usernames and passwords on our domain as yet.

 

I wondered if you do? Or are you logging on as Domain admin/user?

Edited by Koldov
Posted
Only other thoughts are that it might take a reboot to disable the Smart Card prompt, or has the user got Smart Card Required box ticked on their AD account(Account tab | Account Options)?

 

No, I haven't rebooted. I have run RSOP and it appears to be applying though. I will log in with the workaround method and try tonight.

 

It's the Domain Admin account but no, it doesn't have that option ticked. Good shout though, I didn't even know it was there!

Posted
Ok thanks.

 

I've raised the issue with support, was just hoping to get a resolution before needing to do that. I'm hoping they don't turn round and say it's not their problem as they don't support our servers.

 

I have researched, but can't find any other answers. Possibly only that with a local RDP session, the Username and Password are sent to the machine with the connection and it appears that with the remote session this is not the case (although see below).

 

However, as mentioned I can choose 'other user' and log on as admin ok. Interestingly though it does appear there is a username pushed through the RDP session as when I do click on 'other user' my USO username is already entered into the field, I just clear it and type in my Domain Admin credentials. Unfortunately we do not use USO usernames and passwords on our domain as yet.

 

I wondered if you do? Or are you logging on as Domain admin/user?

 

Nah, we don't use USO for domain logons, I'm logging on with domain admin credentials. They're not passed through, I'm prompted for them on connection like this. I never actually see the RDP full screen until after logon.

 

Another place you could look is in the settings of your RDP client. On your source PC off site, on Remote Desktop Client, click show options and check under Advanced tab. Under the Connect from Anywhere options there is a whole bunch of stuff about gateways, and one of the drop downs does have Smart Card options.

  • Thanks 1

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...