Jump to content

Recommended Posts

Posted

Anyone got an ideas about why a smoothwall UTM would stop access to RemoteApps hosted on a council 2012 Server?

 

We set this up and the school involved now cannot access their MIS systems anymore as they simply get the generic 'could not connect to the remote computer' message when they try to run an app. The can login ok but cannot run any apps.

 

I've whitelisted the entire domain involved, excluded it from https inspection and also authentication but still no joy.

 

I've contacted smoothwall support but no reply there yet and this is now time critical - in 24 hours I've got to fix this or pull the smoothwall out and replace it with something that will work (any suggestions?)

 

I've had this before where a smoothwall box mangles access to something, but the only way around that has been to bypass the smoothwall entirely, which isn't practical in this scenario!

Posted
Not sure I quite get what you are connecting to but if you are connecting to a rdp session you may need to allow port 3389 through your smoothwall to your councils rd server
Posted
Not sure I quite get what you are connecting to but if you are connecting to a rdp session you may need to allow port 3389 through your smoothwall to your councils rd server

 

It goes over HTTPS

 

 

We have the same issue, I haven't had chance to sort it, I am the only person it impacts and I can get around it.

Posted
It goes over HTTPS

 

 

We have the same issue, I haven't had chance to sort it, I am the only person it impacts and I can get around it.

 

How did you get round it? We have several users affected!

 

Smoothwall don't seem to have a solution to this as far as I can find, anyone done this with a Sophos UTM?

Posted

We had similar issue with dell vworkspace at our LA. The only way I could get around this short term was to bypass the whole firewall rules and filtering, turns out some file doesn't get downloaded and shows an error saying file missing.

 

Not sure what we changed but seems to work now anyway. Sorry I can't be more help on this issue.

 

Have you checked it is in authentication exception too?

Posted

Yeah it bypasses authentication, https inspection and is whitelisted!

 

Problem is this is a utm so it is the firewall as well as the filter so there's no other way to allow a bypass other than use a different firewall!

Posted
Sorry, I mean bypass the firewall rules as well, so within smoothwall interface allow all ports outbound from the device you need to connect.
Posted

I assume this is going out of the school to the council one and not coming back in.

 

Our setup defintiely allows conencting eternally to our RDS box (2016 though), as I was on it 2 nights a go. I have also tested my friends RDS boxes from my PC, not sure what version of RDS they were usign though.

Posted
Sorry, I mean bypass the firewall rules as well, so within smoothwall interface allow all ports outbound from the device you need to connect.

 

I've got a default allow everything out rule, but I'm missing something maybe, I don't suppose you could drop a picture of the firewall rule you put in on here?

Posted
I assume this is going out of the school to the council one and not coming back in.

 

Our setup defintiely allows conencting eternally to our RDS box (2016 though), as I was on it 2 nights a go. I have also tested my friends RDS boxes from my PC, not sure what version of RDS they were usign though.

 

Yes this is outbound, worked before the smoothwall went in so something is getting blocked somewhere

Posted
In Network, then Firewall Rules, you can add the source IP, desitnation IP then allow all ports. That should bypass the firewall completely, if nothing else it will prove or disprove what is causing the issue for you.
  • Thanks 1
Posted
In Network, then Firewall Rules, you can add the source IP, desitnation IP then allow all ports. That should bypass the firewall completely, if nothing else it will prove or disprove what is causing the issue for you.

 

Cheers, going to split this off to go directly out if I can!

  • 6 months later...
Posted
Did anyone fix this. It isn't being blocked by the firewall, I have set the public IP to be a proxy exception and it still doesn't work.
Posted

I tried to leverage all the functions of the Smoothwall UTM (VPN, Firewall, Guardian filter etc) but had to setup a DMZ outside of the UTM due to so many connectivity issues. When the Smoothwall UTM was in place, clients would hit the Remote Desktop Gateway first, then the connection broker with load balancing and then hit the relevant Session Host of which there were six. For some reason, the UTM would stop incoming connections on 3389. I chose to implement port translation and reconfigure the inbound ports on the TS gateway. This worked for while but soon stopped. In the end I stopped using the UTM as a firewall and routed everything through a vFirewall provided by our ISP. We now have a DMZ in the so called cloud.

 

Not knowing much about your setup, do you have a TS gateway and access policies and are any parts of your RemoteApp infrastructure visible on the DMZ part of your network?

  • 2 weeks later...
Posted (edited)

Have you checked that your la haven’t changed something which may be causing this.

Whilst you have an outbound rule setup, your la should have an inbound rule also set.

Someone may have unintentionally blocked you. Mistakes do happen

our la wanted to block 3389.

Edited by dapaulio
Posted
You don't need to allow 3389. 443 is the only port required.

 

By default yes but has it been checked whether they are using another custom port perhaps for remote apps. For example Can you connect using port 3389?

 

Are any other schools with a similar setup experiencing issues? That would narrow down whether you are dealing with a remote issue or localised issue

  • 1 year later...
Posted
Did anyone have any luck in resolving this from behind Smoothwall and were you trying to use it through Reverse Proxy or were you NATing the ports?
Posted
With RDS over HTTPS its very likely that certificate validation could be failing - in any case, lookup the address you are trying to connect to in the web filter logs to see if anything is getting blocked. If you find an address or domain request with a pink background, try to add that to a do not inspect policy in the https inspection section.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...