Avatar of steves1217
steves1217
 asked on

Cisco VPN connects to network and can rdp to server cannot rdp to workstations SBS 2011

I have created a new sbs 2011 domain. I have an existing ASA 5505 (7.2(4))
I can establish a VPN commection and RDP to the server. I cannot RDP to any workstaion on the remote network. I cannot ping by name or IP.

This domain replaced a SBS 2003 domain that crashed badly. The VPN and RDP was working.
SBSMicrosoft Legacy OSVPN

Avatar of undefined
Last Comment
steves1217

8/22/2022 - Mon
Sjizzel

check firewall rules. there may be a rule that allows only rdp to the server
ASKER CERTIFIED SOLUTION
Rob Williams

THIS SOLUTION ONLY AVAILABLE TO MEMBERS.
View this solution by signing up for a free trial.
Members can start a 7-Day free trial and enjoy unlimited access to the platform.
See Pricing Options
Start Free Trial
GET A PERSONALIZED SOLUTION
Ask your own question & get feedback from real experts
Find out why thousands trust the EE community with their toughest problems.
steves1217

ASKER
Tried the above with no resolution. I ca ping by IP not by name. Any other suggestions would be greatly appreciated.
Rob Williams

Can you RDP to a Workstation by IP?  Pings are allowed by default on an SBS domain, RDP from outside is not.  Not being able to ping by name is a different issue with DNS.  

-You can ping by IP so it is not a routing issue
-Try RDP by IP , if that doesn't work it is likely still a firewall rule
-If by IP works, you will need to set the SBS IP as the only DNS IP for the VPN client
Experts Exchange has (a) saved my job multiple times, (b) saved me hours, days, and even weeks of work, and often (c) makes me look like a superhero! This place is MAGIC!
Walt Forbes
steves1217

ASKER
I cannot RDP by ip or name. This is a new server and an existing Cisco firewall and ipsec vpn. The old domain was sbs 2003 the new is sbs2011. I am using the same IP scheme as before.
Rob Williams

I am still betting on the software firewall. ICMP's (Ping's) are allowed by default and RDP blocked.  It is a VERY common problem.  If there is a 3rd party firewall on the PC, the same applies.

The fact that you cannot ping by name is a different issue.
steves1217

ASKER
Thanks
⚡ FREE TRIAL OFFER
Try out a week of full access for free.
Find out why thousands trust the EE community with their toughest problems.