sacrej Posted March 3, 2011 Posted March 3, 2011 None of our clients have been able to connect since applying the SP, so we're going to have to return to roll back, what we've found is that it wont let us turn off Network level authentication, if anyone can suggest a way to work around this then I would be very appreciative. We no longer have a support contract and I couldnt say what firmware they are on, but they did work with R2 previously with security set to negotiate on the server.
sukh Posted March 3, 2011 Posted March 3, 2011 Hi Have you downloaded the latest RDC Client to connect to the R2SP1 server? Regards Sukh
sacrej Posted March 3, 2011 Author Posted March 3, 2011 They are thin terminals, there is no downloadable client, desktop machines connect fine. we uninstalled the service pack, but they still cant connect. it's the only thing we have changed on that server in a very long time! if I change the wnos.ini answer file to point to a different terminal server (2003) that works okay...but thats a staff rd server, the weird thing is that this all worked prior to the sp. gah
sukh Posted March 3, 2011 Posted March 3, 2011 (edited) Hi Thin clients- What OS? How did you connect before? Can you check the R2 Server event logs and post the exact error message. Ensure no GPP is being applied controlling the setting. To configure Network Level Authentication for a connection On the RD Session Host server, open Remote Desktop Session Host Configuration. To open Remote Desktop Session Host Configuration, click Start, point to Administrative Tools, point to Remote Desktop Services, and then click Remote Desktop Session Host Configuration. Under Connections, right-click the name of the connection, and then click Properties. On the General tab, select the Allow connections only from computers running Remote Desktop with Network Level Authentication check box. If the Allow connections only from computers running Remote Desktop with Network Level Authentication check box is selected and is not enabled, the Require user authentication for remote connections by using Network Level Authentication Group Policy setting has been enabled and has been applied to the RD Session Host server. Click OK. Regards Sukh Edited March 3, 2011 by sukh
sacrej Posted March 3, 2011 Author Posted March 3, 2011 WYSE S10 with WTOS 5.3.0.09 machines pick up dhcp option to pick up WNOS.ini answer file from ftp server (this works) answer file tells them to run rdp connection to server 'studentRD; 172.16.45.103' this brings up an rdp connection on full screen normally, now we just get a short message saying "Connection "studentrd": connection failed. on the terminal event log I get loads of invalid statement:"random characters" after the 'Accessing system profile' event, may I reiterate that this event log is on the CLIENT the server doesnt really provide any information in the event log, before we removed the service pack it was showing some error messages specifically stating those machine names, but they seem to have disappeared now. i'm tempted to reinstall the service pack to see if they start showing up again
sukh Posted March 3, 2011 Posted March 3, 2011 Hi Have you tried to change the Network Level Authentication? Regards Sukh
sacrej Posted March 3, 2011 Author Posted March 3, 2011 re-read my original post, but to add security layer - negotiate Encryption Level - Client Compatible Cert - (Domain CA provided) Enforce NLA - greyed out due to Negotiate selected making it 'optional'
sukh Posted March 3, 2011 Posted March 3, 2011 Hi See Wyse S10 and WT1200LE with RDP/Win2k8 Does this help you. Regards Sukh
sacrej Posted March 10, 2011 Author Posted March 10, 2011 does anyone know if there is a way to force disable NLA in 2008r2sp1, as I think that this would solve all of our issues. all the options under remote connections are greyed out and the options in TS dont seem to do anything either.
sukh Posted March 10, 2011 Posted March 10, 2011 Hi The option "Allow connections only from computers running Remote Desktop with Network Level Authentication". Is this ticked or not? Thanks Sukh
alexsanger Posted March 10, 2011 Posted March 10, 2011 The RDP setting “Allow connections from all clients” worked for me when I had issues from XP clients to a 2008 SP1 box. Not using thin client though, so just a suggestion.
sacrej Posted March 14, 2011 Author Posted March 14, 2011 Hi The option "Allow connections only from computers running Remote Desktop with Network Level Authentication". Is this ticked or not? Thanks Sukh please read my previous posts as I have already provided this information. Enforce NLA - greyed out due to Negotiate selected making it 'optional'
sacrej Posted March 14, 2011 Author Posted March 14, 2011 The RDP setting “Allow connections from all clients” worked for me when I had issues from XP clients to a 2008 SP1 box. Not using thin client though, so just a suggestion. unfortunately this doesn't seem to be an option on R2 (that i can see)
kmount Posted March 14, 2011 Posted March 14, 2011 unfortunately this doesn't seem to be an option on R2 (that i can see) It's there on my 2008r2 SP1 TS. Right click my computer, properties, remote settings, 3 options, pick the middle one (any version of remote desktop)
sacrej Posted March 14, 2011 Author Posted March 14, 2011 It's there on my 2008r2 SP1 TS. Right click my computer, properties, remote settings, 3 options, pick the middle one (any version of remote desktop) Oh those options, yes I have those - however they are all grayed out with the bottom option selected (Enforce NLA) not sure how to 'un-gray' them :/ I am logged in as a domain admin, local admin has the same issue.
kmount Posted March 14, 2011 Posted March 14, 2011 Suspect that's going to be down to group policy or the tsconfig itself but you've eliminated the latter. Look at Computer Configuration > Remote Desktop Services > Remote Desktop Session Host > Security > "Require user authentication for remote connections by using Network Level Authentication" (of course you may have several policies so you may need to gpresult first)
FN-GM Posted March 14, 2011 Posted March 14, 2011 Oh those options, yes I have those - however they are all grayed out with the bottom option selected (Enforce NLA) not sure how to 'un-gray' them :/ I am logged in as a domain admin, local admin has the same issue. Find the setting in group policy to changed them and do a gpupdate /force on the server. That should force it on the server. Not sure where the setting is in group policy though. EDIT: Even Better follow that Kim says
sacrej Posted March 14, 2011 Author Posted March 14, 2011 set to disabled in gpo, tried to change to unconfigured - no joy :/
kmount Posted March 14, 2011 Posted March 14, 2011 If it's greyed out something is controlling it normally GPO. Do you have any apps on there that could be putting in this requirement? Do you have a spare box in the farm to shove in the Computers container with no GPOs applied to check?
EduTech Posted March 14, 2011 Posted March 14, 2011 In case it's maybe causing you an issue in regards to chasing down the Group Policy, Run gpresult /r on your box and see what is being applied. As kim says if it is greyed out it is generally being controlled somewhere... as he said generally GPO
Lloyd Posted May 17, 2012 Posted May 17, 2012 you indicated an issue RDP to Win7 from Wyse S10. we had same issue after upgrading from Wyse S10 v6 to V7. Wyse would connect to WinXp, Win2003 terminal servers, etc but not Win7, Win2008 Terminal servers. firewall or no firewall, could not connect. Issue resolved on Wyse S10 OS, Connection Manager, Global Connection Settings, RDP tab, Uncheck Enable NLA box. Lloyd
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now