Jump to content

Recommended Posts

Posted

Hi, new setup for work we're trying to do, however have had some problems.

 

We've installed a new 2012 R2 setup with Remote Desktop and RemoteApp, Web Access, Gateway etc on different servers. Works great internally and we can publish Apps and access Desktops. Our internal domain is along the lines of "ad.contoso.com". Our office has a dynamic IP and we are using the .myfirewall.co domain provided by Sophos as a DDNS host which refreshes every 4 minutes.

 

We want to publish RD Gateway for users over port 433, we're not worried about certificate errors as we can fix this by deploying the certificate via Group Policy. However, we are confused regarding the setup and how to get it all working over the internet. We want all RemoteApps/Desktops to be accessible over SSL over the internet, however forwarding port 433 to the gateway does nothing, as it's not on the same server as the web role. We are confused at the setup also, as our AD FQDN is internal only and doesn't resolve in the public DNS records for obvious reasons?!

 

What do I have to do to get this working? You can be general with instructions, or specific to Sophos XG if you know! First time we're doing a setup like this, however want this to work.

 

Any ideas you've got, let me know!

 

Thanks,

 

Whistler.

Posted

Hi there,

 

TCP Port 443 to the gateway will mean mstsc / rdp client will work but not rd web access unless you put web access on the same server as the gateway.

 

Typically people co-host these together for this reason, otherwise it's a second public IP on port 443 pointing to rdweb access box.

 

You probably also want UDP 3391 to the gateway for better performance too.

Posted
Hi there,

 

TCP Port 443 to the gateway will mean mstsc / rdp client will work but not rd web access unless you put web access on the same server as the gateway.

 

Typically people co-host these together for this reason, otherwise it's a second public IP on port 443 pointing to rdweb access box.

 

You probably also want UDP 3391 to the gateway for better performance too.

 

Hi, I've done as you said and migrated the Web role to the Gateway box, works fine. I'm able to connect to the box locally and access apps etc.

 

However, when working remotely (or more specifically over a 4G connection - only thing we've got to test), I can sign into the portal fine, however it won't connect to any apps etc because it's using the internal DNS name "e.g rd-broker01.ad.contoso.com" How do I fix this?

 

Thanks,

 

Whistler.

Posted

UPDATE: I have got everything working internally, as I didn't have a certificate I needed. However, when accessing externally, I still tries to connect to the broker server and won't resolve as it's under our internal DNS. Any advice anyone can give would be great.

 

Thanks.

Posted (edited)
UPDATE: I have got everything working internally, as I didn't have a certificate I needed. However, when accessing externally, I still tries to connect to the broker server and won't resolve as it's under our internal DNS. Any advice anyone can give would be great.

 

Thanks.

 

We had this issue here and for the life of me, it was so simple i cant even remember how to fix it.

Let me check my documents.

 

Quick Question - Does the logs mention anything about SSL?

Edited by mukz
Posted
We had this issue here and for the life of me, it was so simple i cant even remember how to fix it.

Let me check my documents.

 

Quick Question - Does the logs mention anything about SSL?

 

Doesn't mention anything to do with SSL in any logs that I can see. I have all of the certs, although self signed installed in Trusted Root. The only issue I can see is that for the gateway server it's still using the internal FQDN, rather than anything external which I think may be the problem.

 

If you can give an explanation on what to do as easy as possible I'd appreciate it. Thanks for your help. :)

Posted

Another update, I've changed some DNS settings and it connects to the gateway fine (using myfirewall.co domain) , gives the security warning for the broker server, accepts cert but gives this error "The Gateway server could not reach the target server. Please make sure that the target hostname is correct." (OS X). Anything anyone suggests. I think we're nearly there, but not sure!

 

Whistler.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...