Solved

RDP problems over Netscreen 5GT

Posted on 2009-04-09
9
1,114 Views
Last Modified: 2013-11-21
Hello,

In one of our offices we have two completely separate networks (due to business reasons this has to be the case), Network A & Network B.  Between the two networks I have placed a Netscreen 5GT to allow some traffic to pass between the two.  Some users from Network A need to RDP to a server in Network B.

The RDP session kicks off fine and allows the user to connect to the sever, however, after only a few seconds the session disconnects.  Some of these users are on XP, others are on thin client Winterms.  

I can run a constant ping from A to B without any drops.  Going in the opposite direction, ping is also constant and Citrix works flawlessly.  Unfortunately there are no Citrix farms on Network B so it has to be RDP into the terminal sever.  

Users on Network B can RDP into the server without any problems.  So it appears to me that the problem lies in the Netscreen, but I open to all suggestions.  

I did wonder if it could be a problem with MTU size.  I tried reducing it to 1300 on the Netscreen but it made no difference.   I have seen in some places that the MTU needs to be set on the client machine, but as some of the users are on Winterm thin clients, I don't think this can be configured.  But I fully admit I know very little about MTU so I am open to any suggestions.

Kind regards
0
Comment
Question by:laytonblackham
9 Comments
 
LVL 8

Expert Comment

by:MrMintanet
ID: 24107922
Connect the TS to a switch.  Connect the switch to the DMZ port of each separate network.

Then setup policies to only allow port 3389 through.
0
 

Author Comment

by:laytonblackham
ID: 24108402
MrMintanent - thank you for your response.
The policy on the netscreen is already allowing 3389 though, so will this make a difference to the problems I'm getting with the session disconnecting?

Thanks
0
 
LVL 8

Expert Comment

by:MrMintanet
ID: 24108415
Have you tried to lower the connection speed to 16 bit color, etc?
0
 

Author Comment

by:laytonblackham
ID: 24108512
No, I haven't actually - I'll try that this afternoon.  

Thanks
0
Backup Your Microsoft Windows Server®

Backup all your Microsoft Windows Server – on-premises, in remote locations, in private and hybrid clouds. Your entire Windows Server will be backed up in one easy step with patented, block-level disk imaging. We achieve RTOs (recovery time objectives) as low as 15 seconds.

 

Author Comment

by:laytonblackham
ID: 24139103
Hi, back after the bank holiday weekend.

Even with 256 colours and reduced display resolution I get the same issues.  

Thanks
0
 

Author Comment

by:laytonblackham
ID: 24146277
Raising the points to 500 in the hope that someone can help me.  Thanks!
0
 
LVL 2

Accepted Solution

by:
sfrancy earned 500 total points
ID: 24221342
I have seen this problem occur with an asymmetric routing situation.  This is where the routed path from network A -> B is not the same as B ->A.  If you have this situation, you can fix the routing problem or you can try issuing this command:  unset flow tcp-syn-check.

0
 

Author Comment

by:laytonblackham
ID: 24226264
Sfrancy, thank you very much for the response.
I've not had chance to try this today but will do on Monday.

Thanks
0
 

Expert Comment

by:trojan81
ID: 34518273
Did "unset flow tcp-syn-check" resolve the issue?
0

Featured Post

Is Your Active Directory as Secure as You Think?

More than 75% of all records are compromised because of the loss or theft of a privileged credential. Experts have been exploring Active Directory infrastructure to identify key threats and establish best practices for keeping data safe. Attend this month’s webinar to learn more.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

My previous article  (http://www.experts-exchange.com/OS/Microsoft_Operating_Systems/Server/Windows_Server_2008/A_4466-A-beginners-guide-to-installing-SCCM2007-on-Windows-2008-R2-Server.html)detailed one possible method to get SCCM 2007 installed an…
Issue: One Windows 2008 R2 64bit server on the network unable to connect to a buffalo Device (Linkstation) with firmware version 1.56. There are a total of four servers on the network this being one of them. Troubleshooting Steps: Connect via h…
Delivering innovative fully-managed cloud services for mission-critical applications requires expertise in multiple areas plus vision and commitment. Meet a few of the people behind the quality services of Concerto.
A company’s greatest vulnerability is their email. CEO fraud, ransomware and spear phishing attacks are the no1 threat to a company’s security. Cybercrime is responsible for the largest loss of money to companies today with losses projected to r…

943 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

10 Experts available now in Live!

Get 1:1 Help Now