StephenPink Posted April 9, 2024 Posted April 9, 2024 Hi all, Having a play with Microsoft Entra Private Access, but can't seem to get it to play ball. Anyone had issues? Was thinking of using for RDP access to specific subnets - but the RDP client doesn't get any further than "Configuring remote session", then just bums out with a generic error. Cheers, Stephen
free780 Posted April 9, 2024 Posted April 9, 2024 I found its unclear if UDP traffic is supported. I managed to get RDP to work with DNS (maybe use TCP). There is a drawback that there is no inbound access to clients as you get with VPNs.
StephenPink Posted April 9, 2024 Author Posted April 9, 2024 Yeah I can only select TCP anyway, so it should be 3389 TCP. Just doesn't seem to get anywhere!
free780 Posted April 9, 2024 Posted April 9, 2024 Does it work if you try using the IP instead or hostname/FQDN ? Presumably your Connector can rdp to the destination?
StephenPink Posted April 9, 2024 Author Posted April 9, 2024 Yeah I'm just testing using the IP, trying to keep it simple. Yep the server with the Connector installed can ping/RDP the destination fine. Have quadruple checked all the settings and nothing obvious jumping out...
StephenPink Posted April 9, 2024 Author Posted April 9, 2024 Thinking it may be to do with the filtering - one site uses Securly, the other Smoothwall, both of which are proxies. I've opened tickets with both of them, will see what happens. Found a bit more information on Microsoft's sites that led me down this path: Work with existing on-premises proxy servers and Microsoft Entra ID - Microsoft Entra ID | Microsoft Learn
free780 Posted April 9, 2024 Posted April 9, 2024 Yep you need to make sure there’s no SSL Inspection or security checking for the domains.
StephenPink Posted April 10, 2024 Author Posted April 10, 2024 Cheers - yeah I've checked what I can in both, but not spotted anything. Securly have come back and said they're not proxying any of that traffic, so not sure what's left to check on that site. Smoothwall as far as I can tell it's exempt from SSL/auth but still not working, waiting on them to respond. When runninng the "ConnectorTroubleshooterLauncher" I get the below output: [h=2]Azure AD Application Proxy Connector Troubleshooter[/h] Connectivity to update service failed Error connecting to URL: 'https://updater.msappproxy.net:8080/'. Error: 'The remote name could not be resolved: 'updater.msappproxy.net''. Make sure firewall and proxy configuration are properly and that the necessary outgoing ports are open – see http://go.microsoft.com/fwlink/?LinkID=401510 [*]Connectivity to bootstrap service failed Error connecting to URL: 'https://00000000-0000-0000-0000-000000000000.bootstrap.msappproxy.net:8080/'. Error: 'The underlying connection was closed: An unexpected error occurred on a send.'. Make sure firewall and proxy configuration are properly and that the necessary outgoing ports are open – see http://go.microsoft.com/fwlink/?LinkID=401510 [*]Connectivity to registration service failed Error connecting to URL: 'https://register.msappproxy.net:9090/'. Error: 'The remote name could not be resolved: 'register.msappproxy.net''. Make sure firewall and proxy configuration are properly and that the necessary outgoing ports are open – see http://go.microsoft.com/fwlink/?LinkID=401510 [*]Connectivity to registration Trust Renewal service failed Error connecting to URL: 'https://register.msappproxy.net:9091/'. Error: 'The remote name could not be resolved: 'register.msappproxy.net''. Make sure firewall and proxy configuration are properly and that the necessary outgoing ports are open – see http://go.microsoft.com/fwlink/?LinkID=401510 [*]Checking endpoint connectivity to service on port 10100 failed Error connecting to URL: 'https://cwap-cu-2.connector.msappproxy.net:10100/'. Error: 'The remote name could not be resolved: 'cwap-cu-2.connector.msappproxy.net''. Make sure firewall and proxy configuration are properly and that the necessary outgoing ports are open – see http://go.microsoft.com/fwlink/?LinkID=401510 [*]Checking endpoint connectivity to service on port 10101 failed Error connecting to URL: 'https://cwap-cu-2.connector.msappproxy.net:10101/'. Error: 'The remote name could not be resolved: 'cwap-cu-2.connector.msappproxy.net''. Make sure firewall and proxy configuration are properly and that the necessary outgoing ports are open – see http://go.microsoft.com/fwlink/?LinkID=401510 [*]Checking endpoint connectivity to service on port 10102 failed Error connecting to URL: 'https://cwap-cu-2.connector.msappproxy.net:10102/'. Error: 'The remote name could not be resolved: 'cwap-cu-2.connector.msappproxy.net''. Make sure firewall and proxy configuration are properly and that the necessary outgoing ports are open – see http://go.microsoft.com/fwlink/?LinkID=401510 [*]Checking endpoint connectivity to service on port 10103 failed Error connecting to URL: 'https://cwap-cu-2.connector.msappproxy.net:10103/'. Error: 'The remote name could not be resolved: 'cwap-cu-2.connector.msappproxy.net''. Make sure firewall and proxy configuration are properly and that the necessary outgoing ports are open – see http://go.microsoft.com/fwlink/?LinkID=401510
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now