Solved

cisco anyconnect vpn user cannot connect to windows 7 virtual machine[s]

Posted on 2013-05-14
4
1,671 Views
Last Modified: 2013-05-20
hi everyone, strange issue, we have Cisco VPN anyconnect users unable to RDP to some windows 7 PC's that are virtual on a hyper-v host. They can connect to VPN and RDP to virtual servers but for some reason the windows 7 guests give the "unavailable" message. We CAN VPN in and RDP to a virtual server, once inside, we can RDP to the win 7 guests. Physical win 7 machines are working also. Weird one. thanks in advance.
0
Comment
Question by:WAMSINC
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 2
4 Comments
 
LVL 57

Assisted Solution

by:Pete Long
Pete Long earned 250 total points
ID: 39167634
Odd? Can you add the AnyConnect IP range to the allowed RDP (EVEN If THE FIREWALLS Are OFF!) See

Cannot RDP to machines via VPN or from other sites
Pete
0
 
LVL 28

Assisted Solution

by:asavener
asavener earned 250 total points
ID: 39167955
Are the Win 7 virtual machines on a different subnet from the hosts?
0
 

Accepted Solution

by:
WAMSINC earned 0 total points
ID: 39168932
ok so we had to open a TAC on this. What they did was run wireshark on a dual nic machine after setting up a port span to mirror traffic. We could see ping packets getting there but not rdp through the VPN. On the firewall they could see from a capture that the packets were sending rdp and ping to the inside, which looked ok so RDP traffic was getting dropped somewhere after that...  We have a barracuda webfilter 410 in line, between our core switch and the firewall. Removing the cuda allowed RDP traffic to get to its destination. SO turns out the cuda had an application policy blocking RDP by default for "unauthenticated policy" which was getting applied because the VPN users are using a AAA local user database to connect to VPN, not LDAP and the cuda sees them as unauthenticated. So out of the box the cuda blocks RDP and a ton of other ports/apps too. The ridiculous part is that it was working intermittently so who knows what else its not doing the way its supposed to. Anyone reading this in the future should check that out if it applies. Case closed thanks for everyone's help.
0
 

Author Closing Comment

by:WAMSINC
ID: 39180452
had to open a TAC see details
0

Featured Post

Visualize your virtual and backup environments

Create well-organized and polished visualizations of your virtual and backup environments when planning VMware vSphere, Microsoft Hyper-V or Veeam deployments. It helps you to gain better visibility and valuable business insights.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
SSL VPN to Fortigate 100D 2 18
Cisco 4400 will not take SFP module ? SFP 10 GB module 1 45
TZ400 VPN Clients 5 26
Cisco Switch slow_Faulty Link 7 15
Are you one of those front-line IT Service Desk staff fielding calls, replying to emails, all-the-while working to resolve end-user technological nightmares? I am! That's why I have put together this brief overview of tools and techniques I use in o…
This article offers some helpful and general tips for safe browsing and online shopping. It offers simple and manageable procedures that help to ensure the safety of one's personal information and the security of any devices.
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
As a trusted technology advisor to your customers you are likely getting the daily question of, ‘should I put this in the cloud?’ As customer demands for cloud services increases, companies will see a shift from traditional buying patterns to new…

763 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question