Solved

RDP problem

Posted on 2013-01-20
7
299 Views
Last Modified: 2013-02-01
Hi - I do work for a restaurant where we want to have RDP access to one of the machines in the office accessible from outside the router. We have a Verizon DSL router that has to connections to it. The first is connected to a sonicwall firewall that ONLY is connected to the POS system, and the other is connected to a Linksys wireless router which has DHCP enabled and is pushing addresses to all of the other machines on the network, including the one we are trying to access. I've configured RDP on the machine (windows firewall/system-remote access) as well as opening the ports on the Verizon DSL modem/router, as well as opening the port on the Linksys router. BUT, for some reason, cant access the machine outside the network, but CAN from within the network. This is a simple network, no AD, no server. I've attached a diagram on how we have it setup - any help would be appreciate!
DIAGRAM.jpg
0
Comment
Question by:hodgem
7 Comments
 
LVL 10

Expert Comment

by:joelsplace
ID: 38798778
Have you checked to make sure that RDP works inside the network?
The Verizon router should have it's RDP port open to the Linksys external IP.
I have had issues with Linksys routers and private IPs on the external interface.
Is there a reason you can't get rid of the Linksys and just run the SonicWall?
Have you tried connecting a PC on the WAN side of the Linksys to see it you can get through the Linksys with the current settings?  If yes, try connecting the RDP PC in place of the Linksys and see if you can get to it from outside.  That will isolate the problem to the Verizon router or the Linksys.
You could try flashing DD-WRT on the Linksys.
0
 
LVL 25

Expert Comment

by:Tony Giangreco
ID: 38798805
For RDP to work properly, you have to setup port forwarding for port 3389 to that Pc. If you don't know how to set that up properly or have difficulty with the Linksys and Verison routers, you can simply go to www.logmein.com and setup a free account. After that is done, you can install Logmein on the Pc you want to access. From that point on, you can log into logmein from any Pc outside of the resturant and connect to the desktop of that Pc in the resturant just like RDP.

The free version of Logmein does not provide remote printing, but you can gerate a report file on that Pc and send it to yourself by email.

We use Logmein central to access all our client's Pc's remotely and it works great.

Hope this helps.
0
 
LVL 10

Expert Comment

by:joelsplace
ID: 38798810
Sorry about that first ?  I just noticed you already answered it.
0
Top 6 Sources for Identifying Threat Actor TTPs

Understanding your enemy is essential. These six sources will help you identify the most popular threat actor tactics, techniques, and procedures (TTPs).

 

Author Comment

by:hodgem
ID: 38798819
Yes, RDP is working internally. One thing I forgot to mention, I created a custom RDP port for this machine (4010), and made the appropriate change in the registry. The reason I can't use Sonicwall is because it was provided by POS company ONLY for POS system (credit card transactions etc) and we're using the linksys for wireless or I'd get rid if that and just use the Verizon router - I was assuming that since all necessary ports were open, and gateway was correct that it should get through
0
 
LVL 10

Accepted Solution

by:
joelsplace earned 250 total points
ID: 38798830
It's easy to use the Linksys for wireless only and not a router.
Connect to the Linksys and give it a LAN address that works on the Verizon LAN.
Turn off DHCP on the Linksys LAN.
Connect a Linksys LAN port to a Verizon LAN port.
You won't use the Linksys WAN port.
Done.
I have 3 on my home network setup like this.
0
 
LVL 1

Assisted Solution

by:cgitek
cgitek earned 250 total points
ID: 38799034
This question has been answered numerous times. You have a double-nat condition which can cause you other problems but this is specifically what you need to do.

Assign Linksys Router Static IP Address from 192.168.1.x /24 subnet. Make sure to use one outside the DHCP range or exclude that address.

In DSL Modem port forward TCP 3389 to the newly created static IP address of the Linksys Router.

In Linksys Router port forward TCP 3389 to the Statically Assigned IP address of the PC.

Done.

Note - you may have problems going from inside the LAN network to the Public IP of the DSL modem and routing back into the LAN again. Some devices do not handle this well.

Edit: You may also want to change the listening port on the DSL modem to something other than TCP 3389 for security reasons. Then in the RDP window after the FQDN or IP include a ":<port_number>".
0
 
LVL 6

Expert Comment

by:airwrck
ID: 38809008
Call Verizon and ask them if they're permitting port 3389 to your network.  They are notorious for filtering inbound port 80, 25, 443, 1723, and 3389 on residential networks.
0

Featured Post

What Security Threats Are You Missing?

Enhance your security with threat intelligence from the web. Get trending threat insights on hackers, exploits, and suspicious IP addresses delivered to your inbox with our free Cyber Daily.

Join & Write a Comment

At the beginning of the year, the IT world was taken hostage by the shareholders of LogMeIn. Their free product, which had been free for ten years, all of the sudden became a "pay" product. Now, I am the first person who will say that software maker…
Trying to figure out group policy inheritance and which settings apply where can be a chore.  Here's a very simple summary I've written which might help.  Keep in mind, this is just a high-level conceptual overview where I try to avoid getting bogge…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…

744 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

11 Experts available now in Live!

Get 1:1 Help Now