Solved

Terminal Services refusing connections.

Posted on 2009-07-15
12
1,644 Views
Last Modified: 2013-11-21
We have an SBS2003 Premium machine that is running as DC, Exchange and SQL Server and ISA. We are preparing to upgrade to SBS2008 so i have had to reconfigure the network topology, we used to have a dual WAN setup with ISA, but yesterday i removed ISA and reconfigured the server to use a single NIC for Net access and Network. The second NIC is disabled within network connection on the server.

All was fine until i rebooted the server to complete the uninstall of ISA, the server has come back up fine, but i cannot get an RDP connection to the system. Any attempt is immediately rejected by the server, this is from both Mac OSX and WinXP client machines.

I can ping the machine fine by both IP and Hostname, so DNS seems to be functioning correctly. I can also browse shares e.t.c and access to the SQL database is fine.

I have done a port scan and 3389 reports open and reports ms-wbt-server is listening. I have also done a netstat on the server and it shows the something is listening on 3389.

I have tried initiating and RDP connection directly on the server to localhost/127.0.0.1 as well as ip and that also fails.

Interestingly all the Terminal Service controls in Services on the server seem to be grayed out, so i am unable to restart the service.

Help please!!!!

Thanks

Gareth
0
Comment
Question by:gazzer1982
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 6
  • 5
12 Comments
 
LVL 12

Expert Comment

by:marcustech
ID: 24858357
Is administrative tools > services > terminal services started?
0
 

Author Comment

by:gazzer1982
ID: 24858488
Yes it does say it is started. However weirdly when i check it's properties it is set to start manually. I will set it to automatic start and give the server a reboot later once everyone has gone for the day.

Can't believe i didn't notice that before, thanks for the memory jog!
0
 
LVL 12

Expert Comment

by:marcustech
ID: 24858627
Funnily enough, on my SBS server, it's also set to Manual, I believe the service is set to start on demand rather than automatically with the OS. I'm not terribly convinced this will fix your issue.

Try disable the windows firewall on the server and see if it then allows the connection, it may need RDP added as an expection.

In administrative tools > terminal services configuration > connections > "your RDP connection"

under network adapter tab, is "all network adapaters configured with this protocol" selected? and in remote control tab is "use remote control with the following settings" selected? (I suggest in the level of control box below selecting "interact with the session" as well.

let me know,

-js
0
Office 365 Training for Admins - 7 Day Trial

Learn how to provision tenants, synchronize on-premise Active Directory, implement Single Sign-On, customize Office deployment, and protect your organization with eDiscovery and DLP policies.  Only from Platform Scholar.

 

Author Comment

by:gazzer1982
ID: 24858746
Thanks for that, i am running as a single NIC setup so windows firewall is disabled.

I have taken a look at the settings you suggested and they are all correct.

Any other ideas, i think it's still worth a reboot later, especially as you cannot manually restart the Terminal Services service without rebooting the server. Dull!
0
 
LVL 12

Expert Comment

by:marcustech
ID: 24858793
No problem mate, and dispite being on a single NIC the server will still be running a standard (xp like) firewall on the network connection.

You can see if this is switch on by going to start > control panel > windows firewall. It may well be switched off, but still none the less it's worth checking.

And yeah I await to see how you get on with the reboot later :)
0
 

Author Comment

by:gazzer1982
ID: 24858845
I guess there may be a firewall running there somewhere, but i remember ICW telling me that firewall would be disabled. Also when i go to firewall in Control Panel i get an error telling me that window cannot control the firewall as a program or service is using the network address translation component (Ipnat.sys).
0
 
LVL 12

Expert Comment

by:marcustech
ID: 24858893
Try stopping the routing and remote access service (since it won't be needed in 1NIC mode) and then try to access the firewall. Also at this point try the RDP again.
0
 

Author Comment

by:gazzer1982
ID: 24859269
Isn't routing and remote access required for VPN access?
0
 
LVL 12

Accepted Solution

by:
marcustech earned 400 total points
ID: 24859363
Yes it is, it might be worth re-running through the wizard with the new setup, to set it up though if you're using VPN.

Sorry I over looked the fact your using VPN, on our server we're forwarding the RDP ports rather than PPTP.
0
 

Author Comment

by:gazzer1982
ID: 24859982
As i see, yeah we don't expose the RDP ports externally, connections are via PPTP passed through a pfSense firewall.

I was forced to re-run the ICW at the end of the ISA uninstall. But it can't hurt to run it again, i will do so before i reboot, hopefully one will sort it out.

Cheers

Gareth
0
 
LVL 31

Assisted Solution

by:Henrik Johansson
Henrik Johansson earned 100 total points
ID: 24863790
Is the checkbox for allowing RDP-connection ticked under System Properties -> Remote ?

If it's ticked, untick the checkbox, click apply and tick the checkbox again to re-enable RDP and close the dialog with ok. I've seen on one of our TS that the RDP-permissions get corrupt sometimes and nead to be reset by temporary disabling RDP-access to fix some stuff in registry.
0
 

Author Comment

by:gazzer1982
ID: 24864922
Well i re-ran the ICW and restarted the server, and it is now working again so something seems to have sorted it. Hopefully it's now fixed permanently and i can start my SBS 2008 migration .i performed a live image of the system to our new Esxi server tonight, and it seems have gone without a hitch. So i can now take a snapshot incase it all goes tits. Not that i don't trust Microsofts online migration or anything . . .
0

Featured Post

SharePoint Admin?

Enable Your Employees To Focus On The Core With Intuitive Onscreen Guidance That is With You At The Moment of Need.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

On July 14th 2015, Windows Server 2003 will become End of Support, leaving hundreds of thousands of servers around the world that still run this 12 year old operating system vulnerable and potentially out of compliance in many organisations around t…
Know what services you can and cannot, should and should not combine on your server.
There's a multitude of different network monitoring solutions out there, and you're probably wondering what makes NetCrunch so special. It's completely agentless, but does let you create an agent, if you desire. It offers powerful scalability …
Do you want to know how to make a graph with Microsoft Access? First, create a query with the data for the chart. Then make a blank form and add a chart control. This video also shows how to change what data is displayed on the graph as well as form…
Suggested Courses

617 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question