if your ISA server is your default gateway(secure nat client) to the web you should not need the firewall client. Are you able to ping the remote server?
Main Topics
Browse All TopicsHello,
On our ISA Server we have just attempted to allow RDP outbound from one of our internal workstations.
The rule created was: Internal Network & Local Host - Allow Outbound RDP traffic - to External
Still unable to RDP to an external Host from the Internal Workstation. However, the Rule did allow RDP from the ISA Server itself to the External Host.
Wierd.
Anyone a Guru at ISA Server? - please help
Cheers,
-Craig
This Question has been solved and asker verified All Experts Exchange premium technology solutions are available to subscription members.
Experts Exchange has been collecting answers to technology questions since 1996…3 million and counting! If you have a question, chances are we already have your answer.
If you can't find the exact answer you're looking for, ask our exclusive community of 50,000 experts. You’ll get a personalized answer from a trusted professional.
Thousands of free tech tips, tricks, how-to’s and tutorials are available in our peer reviewed articles section. See for yourself how smart our experts are, no login required.
Access the answers to your technology questions today.
30-day free trial. Register in 60 seconds.
Members of the expert community talk about why the experience at Experts Exchange is different than what you will find anywhere else.

Try it out and discover for yourself.
30-day free trial. Register in 60 seconds.
Join the community of experts here and help other tech pros by answering question in your area of expertise. You can earn FREE access to all Experts Exchange's premium features and resources.
Sometimes you still need the FWC. This would be in situations where there is no Application Filter for the particular type of traffic,...the FWC acts as a universal Application Filter (with some limitations) while SecureNAT require a very specific Filter for complex protocols. If anything, installing the FWC is a good troubleshooting step, it can always be uninstalled or left disabled.
RDP, like a web browser such as IE, has the ability to pass user credentials to ISA Server and FTMG when requested for them.
Phil is correct that RDP should not be allowed from localhost to external - to be blunt, unless you are troubleshooting, localhost should be excluded wherever possible from as much as possible whilst still allowing the server to fuinction.
Have you confirmed that the remote work station operates on RDP from outside of the ISA environment?
Keith - ISA MVP
Thanks to the great replies so far...
- The remote Host I am trying to RDP to does work fine from other networks outside the safety of the ISA.
- The FWC is not currently installed on the Workstation that I am attempting to RDP from - hopefully this will be the reason?
Does the FWC simply need to be installed or is any configuration required on the Workstation?.
Thanks
-Craig
Business Accounts
Answer for Membership
by: pwindellPosted on 2009-09-04 at 09:58:16ID: 25261403
The Client machine will require the Firewall Client to be installed unless the rule is anonymous.
You should not involve the ISA in this. I would remove LocalHost from the Rule.