Jump to content

Recommended Posts

Posted

We're moving to PSF and I was surprised to see the 'cloud' implementation is simply an RDP file. Has anyone got a list of what IP/Ports needed to be open for this to work?

 

I can only see one domain on our firewall which is allowed, but its still not connecting

Posted
We may potentially look at this in the future.. So the "Cloud" implementation is presumably a Remote Desktop Server hosted by them?... mmm

 

Yes, that's exactly it.

 

The ordering can be through a webpage, which is more like a traditional cloud based system, but the actual management of the system that your finance team will use is RDC.

Posted
Interestingly I see this when i use a browser to connect to it?

Yes, you don't actually use it like that. You have a single Windows server that hosts everything, then an RDP file which connects via their gateway to your server.

 

The purchasing side of things is hosted in IIS on your server, and you connect to it via a dedicated URL for your server.

Posted
Urgh, this thing hits all sorts of IP ranges on our firewall on 80/443 and 3391, lots of amazon addresses mainly. Going to be a long slog to whitelist this lot!
Posted

Odd, as for ours, the IPs the RDP service run on are not AWS at all. They're dedicated machines hosted by Blackbox Hosting in a LINX datacenter.

 

That applies to both the gateway address and the website side of things.

 

I'm not sure what your connection is doing but it should literally be a connection to port 443 on the domains gateway.psfcloud.com and the domain for your PSPurchasing address. That's the lot. That's all that gets a connection when I look at our users.

 

I wonder if they've started hosting the non-gateway hosts on AWS since ours was set up.

Posted (edited)
We are about to go for PS Financials and weve been told we dont need anything installing our end.

 

I think that's correct, it is just an rdp file they send you, I'm just having issues with it getting through our smoothwall, which seems to be a config problem

Edited by Sheridan
Posted
I think that's correct, it is just an rdp file they send you, I'm just having issues with it getting through our smoothwall, which seems to be a config problem

 

This is really weird, my problem seems to be that when the user opens the RDP file, it will fail to connect 2-3 times, but on the next attempt it seems to work?

 

I'm not sure what could cause this behaviour on a smoothwall and it must be filtering related, as it works first time, every time for an admin!

  • 2 weeks later...
Posted
Hello, we had a bit of a nightmare when ours was installed but I found putting psfcloud.com and any custom links to your school in our staff whitelist as well as having a firewall rule that allows any source IP to a destination of the psfcloud server and gateway which allows HTTP, HTTPS, RDP and custom TCP/UDP port 777 worked for us. We then had a RDP connection on a shared staff desktop. However, they literally did an update the other day that allowed us to run it all from a web browser so no need for the rdp clients. We also had big issues with our invoice drive (moved across from PS Financials) which had 1000s of files, this completely crippled the connection so we had to make a new fresh drive and archive off the old data. Just check that you have compatible printers/barcode scanners as well.
  • Thanks 2
  • 5 months later...
Posted

Thread revival here, but I'm still having real problems with this. We're going through a smoothwall and the whole psfcloud.com domain is whitelisted, and bypasses https inspection. The firewall allows http/https/rdp to the same domain, yet it still takes up to 4 times to connect - and then it connects fine and works until logged out

 

Its bizarre as it implies its not being blocked as it does eventually connect, but the random nature of when it will work is annoying the hell out of me, let alone the people who are using it!

 

Has anyone got a smoothwall they could share their settings with for this?

Posted
Thread revival here, but I'm still having real problems with this. We're going through a smoothwall and the whole psfcloud.com domain is whitelisted, and bypasses https inspection. The firewall allows http/https/rdp to the same domain, yet it still takes up to 4 times to connect - and then it connects fine and works until logged out

 

Its bizarre as it implies its not being blocked as it does eventually connect, but the random nature of when it will work is annoying the hell out of me, let alone the people who are using it!

 

Has anyone got a smoothwall they could share their settings with for this?

 

We had a similar experience and we made changes to gpo - Turn off Automatic Root Certificates Update I think from memory is what we changed. We don’t use a smoothwall though

 

But they seem to be pushing everyone to move to their html5 client - https://webaccess.psfcloud.com

Posted
When I was using an old firewall last year I allowed all https traffic and rdp from specified clients and it worked ok, but I haven't tried that with smoothwall yet - the fact it connects after a few attempts suggests an initial connection is failing somewhere but once established it stays connected all day!
Posted
Just be aware most html5 rdp clients use websockets. This means you usually need to not proxy the domain. Due to the shortcomings of Smoothwalls firewall (no FQDN) this may prove difficult if the IP ever changes.
Posted
Just be aware most html5 rdp clients use websockets. This means you usually need to not proxy the domain. Due to the shortcomings of Smoothwalls firewall (no FQDN) this may prove difficult if the IP ever changes.

 

the HTML5 websockets does not work behind Microsoft's Web Application Proxy either, but apparently Azure Application Proxy can handle it all now :-) I learnt this after days of trying to figure out why the HTML5 client wouldn't work

 

(I have not played with AAP yet but that is on my list)

Posted
Its definitely something in the smoothwall firewall, as if I switch off the Default catch all rule to Allow traffic -and it works first time every time. Switch that rule back on and it works intermittently. Problem is nothing that showing as 'Dropped' seems to relate to this as when I allow them it still fails!
Posted

I think I've fixed it, tests are working so far anyway!

 

I noticed that a on the PCs I was testing a lot of random traffic was hitting the firewall, rather than the proxy. On these winhttp was set to direct (no proxy), and the users GPO specified the proxy in their policy. I put a policy on the PC to set the winhttp proxy to import from IE and now I can connect reliably to PS each time - the machine proxy is effectively the same as the user proxy as it uses authentication on the network

  • 8 months later...
Posted (edited)

Glad I'm not only one experiencing issues with rdp connction to psfinancials. Connection is fine in browser each time, but it seems to disconnect every 20 min, user experience not very good to start with.

When rdp file is downloaded and tested, it won't connect if user logs in with domain account. However if user logs in as local administrator, it works fine.

Error that currently cannot be fixed using domain account login looks like:

Component name:CClientProxyTransport, :: 'Gateway Error' in CClientProxyTransport::SetErrorStatus at 2853 err=[0x80004005], Error code:0x80004005

and

Component name:CAAHttpClientTunnel, :: 'Workspace ID was obtained, but it is not formatted as a GUID (PSFCB02.PSFCLOUD.COM)' in CAAHttpClientTunnel::ObtainWorkspaceId at 3766 err=[0x0], Error code:0x0

and

Component name:CAAClientAdapter, :: 'm_spHelper->ReadCreds failed' in CAAClientAdapter::CreateTunnel at 380 err=[0xffffffff], Error code:0xFFFFFFFF

And it sometimes won't even connect as local administrator, same errors seen.

Tried various fixes in gpo/registry - nothing seems to work.

 

Update:

this seems to have worked:

 

Windows Registry Editor Version 5.00

 

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa]

 

"LmCompatibilityLevel"=dword:00000003

 

Update

 

This has only helped on one workgroup computer but on domain computers it still only works under local admin login.

Edited by evasion

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...