Sheridan Posted June 29, 2017 Posted June 29, 2017 Anyone got an ideas about why a smoothwall UTM would stop access to RemoteApps hosted on a council 2012 Server? We set this up and the school involved now cannot access their MIS systems anymore as they simply get the generic 'could not connect to the remote computer' message when they try to run an app. The can login ok but cannot run any apps. I've whitelisted the entire domain involved, excluded it from https inspection and also authentication but still no joy. I've contacted smoothwall support but no reply there yet and this is now time critical - in 24 hours I've got to fix this or pull the smoothwall out and replace it with something that will work (any suggestions?) I've had this before where a smoothwall box mangles access to something, but the only way around that has been to bypass the smoothwall entirely, which isn't practical in this scenario!
dapaulio Posted June 29, 2017 Posted June 29, 2017 Not sure I quite get what you are connecting to but if you are connecting to a rdp session you may need to allow port 3389 through your smoothwall to your councils rd server
FN-GM Posted June 29, 2017 Posted June 29, 2017 Not sure I quite get what you are connecting to but if you are connecting to a rdp session you may need to allow port 3389 through your smoothwall to your councils rd server It goes over HTTPS We have the same issue, I haven't had chance to sort it, I am the only person it impacts and I can get around it.
Sheridan Posted June 29, 2017 Author Posted June 29, 2017 It goes over HTTPS We have the same issue, I haven't had chance to sort it, I am the only person it impacts and I can get around it. How did you get round it? We have several users affected! Smoothwall don't seem to have a solution to this as far as I can find, anyone done this with a Sophos UTM?
forkies Posted June 29, 2017 Posted June 29, 2017 We had similar issue with dell vworkspace at our LA. The only way I could get around this short term was to bypass the whole firewall rules and filtering, turns out some file doesn't get downloaded and shows an error saying file missing. Not sure what we changed but seems to work now anyway. Sorry I can't be more help on this issue. Have you checked it is in authentication exception too?
Sheridan Posted June 29, 2017 Author Posted June 29, 2017 Yeah it bypasses authentication, https inspection and is whitelisted! Problem is this is a utm so it is the firewall as well as the filter so there's no other way to allow a bypass other than use a different firewall!
forkies Posted June 29, 2017 Posted June 29, 2017 Sorry, I mean bypass the firewall rules as well, so within smoothwall interface allow all ports outbound from the device you need to connect.
FN-GM Posted June 29, 2017 Posted June 29, 2017 How did you get round it? Used my Chromebook instead! Sorry I can't be much help.
Achandler Posted June 30, 2017 Posted June 30, 2017 I assume this is going out of the school to the council one and not coming back in. Our setup defintiely allows conencting eternally to our RDS box (2016 though), as I was on it 2 nights a go. I have also tested my friends RDS boxes from my PC, not sure what version of RDS they were usign though.
Sheridan Posted June 30, 2017 Author Posted June 30, 2017 Sorry, I mean bypass the firewall rules as well, so within smoothwall interface allow all ports outbound from the device you need to connect. I've got a default allow everything out rule, but I'm missing something maybe, I don't suppose you could drop a picture of the firewall rule you put in on here?
Sheridan Posted June 30, 2017 Author Posted June 30, 2017 I assume this is going out of the school to the council one and not coming back in. Our setup defintiely allows conencting eternally to our RDS box (2016 though), as I was on it 2 nights a go. I have also tested my friends RDS boxes from my PC, not sure what version of RDS they were usign though. Yes this is outbound, worked before the smoothwall went in so something is getting blocked somewhere
Achandler Posted June 30, 2017 Posted June 30, 2017 In Network, then Firewall Rules, you can add the source IP, desitnation IP then allow all ports. That should bypass the firewall completely, if nothing else it will prove or disprove what is causing the issue for you. 1
Sheridan Posted June 30, 2017 Author Posted June 30, 2017 In Network, then Firewall Rules, you can add the source IP, desitnation IP then allow all ports. That should bypass the firewall completely, if nothing else it will prove or disprove what is causing the issue for you. Cheers, going to split this off to go directly out if I can!
FN-GM Posted January 19, 2018 Posted January 19, 2018 Did anyone fix this. It isn't being blocked by the firewall, I have set the public IP to be a proxy exception and it still doesn't work.
tuxtopia Posted January 19, 2018 Posted January 19, 2018 I tried to leverage all the functions of the Smoothwall UTM (VPN, Firewall, Guardian filter etc) but had to setup a DMZ outside of the UTM due to so many connectivity issues. When the Smoothwall UTM was in place, clients would hit the Remote Desktop Gateway first, then the connection broker with load balancing and then hit the relevant Session Host of which there were six. For some reason, the UTM would stop incoming connections on 3389. I chose to implement port translation and reconfigure the inbound ports on the TS gateway. This worked for while but soon stopped. In the end I stopped using the UTM as a firewall and routed everything through a vFirewall provided by our ISP. We now have a DMZ in the so called cloud. Not knowing much about your setup, do you have a TS gateway and access policies and are any parts of your RemoteApp infrastructure visible on the DMZ part of your network?
markwilfan Posted January 20, 2018 Posted January 20, 2018 Never had any issues with our rds farm through smoothwall or accessing any external rds
dapaulio Posted January 28, 2018 Posted January 28, 2018 (edited) Have you checked that your la haven’t changed something which may be causing this. Whilst you have an outbound rule setup, your la should have an inbound rule also set. Someone may have unintentionally blocked you. Mistakes do happen our la wanted to block 3389. Edited January 28, 2018 by dapaulio
dapaulio Posted January 28, 2018 Posted January 28, 2018 Do you know your public Ip that you connect to? Try putting it into port scanner looking at open ports on 443 and 3389
TechMonkey Posted January 28, 2018 Posted January 28, 2018 Just to say our RDS works through Smoothwall without issue.
FN-GM Posted January 28, 2018 Posted January 28, 2018 You don't need to allow 3389. 443 is the only port required.
dapaulio Posted January 28, 2018 Posted January 28, 2018 You don't need to allow 3389. 443 is the only port required. By default yes but has it been checked whether they are using another custom port perhaps for remote apps. For example Can you connect using port 3389? Are any other schools with a similar setup experiencing issues? That would narrow down whether you are dealing with a remote issue or localised issue
Cache Posted March 12, 2019 Posted March 12, 2019 Did anyone have any luck in resolving this from behind Smoothwall and were you trying to use it through Reverse Proxy or were you NATing the ports?
ibpalle Posted March 15, 2019 Posted March 15, 2019 With RDS over HTTPS its very likely that certificate validation could be failing - in any case, lookup the address you are trying to connect to in the web filter logs to see if anything is getting blocked. If you find an address or domain request with a pink background, try to add that to a do not inspect policy in the https inspection section.
leegcvcc Posted March 15, 2019 Posted March 15, 2019 I've had to port forward as reverse proxy broke the SSL 1
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now