Link to home
Start Free TrialLog in
Avatar of EE_User12
EE_User12Flag for United States of America

asked on

Pass Remote Desktop through the SonicWALL VPN tunnel

I would like to know if you can pass MIcrosoft's Remote Desktop app through an encrypted SonicWALL VPN tunnel?

I have a remote user that is accessing a server using either Global VPN Client or SSL-VPN.

I'm assuming if you just run Remote Desktop off a client's computer, it's just running parallel to the VPN client's software and establishing its own PPTP connection with the sever.

I have read articles on how to setup and secure a Remote Desktop but I would like to pass the Remote Dektop through the actual encrypted tunnel.  How would one accomplish this and is it possible to do?

I'm using a SonicWALL TZ-200 UTM appliance.
Avatar of ZabagaR
ZabagaR
Flag of United States of America image

I think you're making it more difficult than it seems. In my environment, we have sonicwall site to site VPN tunnels as well as Global VPN client tunnels (desktop w/ gvc software VPN to sonicwall appliance).  We RDP to our servers thru the tunnel.....we have a few hundred instances of this happening...lots of sonicwalls, lots of terminal servers.

Just either build the site to site VPN between the routers or configure & connect to your sonicwall thru the GVC (global vpn client software). When you connect over GVC client, you'll be assigned an IP address, subnet mask, gateway, etc...from the sonicwall.

There's nothing running parallel. As long as your routing is configured properly your RDP session will be inside the tunnel.


Avatar of jgutz20
jgutz20

Once you've established the proper VPN connection, you should be able to run RDP and access any other resources on this network as desired.  

Is your user currently unable to make any connections to RDP or have you not yet configured the VPN tunnel?   I too use sonicwall appliances with Site to Site connections and GlobalVPN clients for individuals outside of the network and have never come across a problem with RDP unless its a software firewall issue on the computer you attempt to RDP into?
SOLUTION
Avatar of digitap
digitap
Flag of United States of America image

Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
Avatar of EE_User12

ASKER

My setup is a remote access to site not site to site.

I usually connect with GVC and have no problems establishing the VPN tunnel.  I have yet to setup the Remote Desktop app.

So if I have a server on a private IP address like 192.168.1.200 and I'm able to connect to it via the VPN, all I have to do is point the RD app to this address and this will allow the RD to pass through the encrypted tunnel of the GVC client?

I don't have to point the RD at the WAN static IP address?  May be this is where I'm confusing things as running parallel.  

I can connect to the server and see its shared resources but I haven't enabled Remote Dektop on the server.  I'm still in the planning phase.

@ZabagaR:  Do I need to configure any special routes on the SonicWall?

Thanks
ASKER CERTIFIED SOLUTION
Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
SOLUTION
Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
@ZabagaR:

Yes, I have the SonicWall giving out DHCP addresses just as you described.

I'll try to configure this over the weekend and see what happens.
are my responses appearing here...I get the feeling they are not.
SOLUTION
Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
@digitap:

Yes, your responses are appearing and I appreciate your input.  Thanks to everyone.
OK...good.  I was worried there for a second...>GRIN<!
Okay, it's working beautifully.  Thanks digitap and everyone else.
Make sure to connect to the IP address of the private network PC and not the IP address of the WAN.
you're welcome and thanks for the points!