Jump to content

Recommended Posts

Posted

I'm trying to get my head around an issue we have using an external RDP connection. We have the RDP file and its domain is whitelisted in smoothwall. However when anyone (admin or staff) tries to connect it will usually timeout for the first, second and probably third attempt. On the third/fourth attempt it connects fine and the connection is stable!

 

I've checked the logs and it seems that when the connection is failing, nothing is being logged against the domain specified in the RDP file, when the connection suceeeds I can see allowed traffic to that domain on our smoothwall. I can't see any reason why the first few attempts seem to do nothing, but it must be related to our smoothwall as when hotspotted to a phone, it works first time, every time?

 

If I had the rules wrong in smoothwall, it surely would fail every time? As it is after you manage to get a connection it will then work (and reconnect) OK for a while until you reboot or logoff and login again later.

 

Anyone got any ideas? I've tried everything I can think of! I've tried on Windows and also Mac and get the same results

Posted (edited)
can you try giving it a helping hand with an local DNS entry?

 

I did add their domain to our dns, but dns resolution seems to be ok and instantaneous anyway. It like the first few attempts don't go anywhere!

Edited by Sheridan
Posted

Interesting one!

 

Are you using a URL or IP for the RDP connection?

Does the user need to connect a VPN before using the RDP?

 

If you're seeing no logs on the firewall unless they make a successful connection, then the traffic isn't getting there. If you're using a URL, could it be the DNS on the domain name provider?

Posted
Interesting one!

 

Are you using a URL or IP for the RDP connection?

Does the user need to connect a VPN before using the RDP?

 

If you're seeing no logs on the firewall unless they make a successful connection, then the traffic isn't getting there. If you're using a URL, could it be the DNS on the domain name provider?

It is a weird one! I've tried with IP and url - for the gateway and address but it doesn't make any difference. It seems like the two urls are resolved OK though. If I change the url of the gateway to the ip I get a certificate error which suggests its getting through at some point.

 

I've tried via the smoothwall, and bypassed the urls to go direct out of the (separate) firewall but I see the same behaviour on both - ie. nothing until a successful connection. Our network is simply routed and the default gateway is the firewall or smoothwall so its not complicated and has worked for years like this.

 

The oddest thing of all though, is that it works every single time on one single machine - which is my PC and I'm using the same proxy/port as the others!

 

This 'golden' PC is the same version of Windows, has the same firewall settings, the same policies are ones that don't work so I am genuinely mystified by this. If I run a tracert on two to compare they're both the same with no delays or nslookup errors.

Posted

What version of RDP Gateway server are you running, if it is 2019 you could enable the HTML5 client and direct them to https:///RDWeb/webclient/

 

Be warned though, this only works is the gateway has a secondary NIC with a direct DMZ on port on 443 and will not work through Web application proxy.

Posted
What version of RDP Gateway server are you running, if it is 2019 you could enable the HTML5 client and direct them to https:///RDWeb/webclient/

 

Be warned though, this only works is the gateway has a secondary NIC with a direct DMZ on port on 443 and will not work through Web application proxy.

 

Its an external company so I've got no idea - they just sent us the RDP file. I'm testing it at home right now and it works fine, so its got to be our internal filtering thats causing the problems

Posted
hmmmmm, wonder what port that one is using (hopefully it isn't the standard RDP Port) as it could be MiM proxy certs kicking in, or it could be the port being blocked most of the time by a firewall rule, which although you are using the same proxy, you may have a different rule which allows the port (sorry plucking at straws here)
Posted
When it does connect, it shows https connections being established with the gateway url, which sounds about right. I just don't see anything that would cause this to fail a few times before finally working. The simple fact it can (eventually!) establish a connection and work normally seems to suggest the firewall is fine.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...