Link to home
Start Free TrialLog in
Avatar of Exchange User
Exchange User

asked on

Unable to RDP on VPN

Hi All,

I opened a similar question last month. I have more information now. The issue is that when an RDP request comes over the VPN, our DCs are rejecting it but not all the time. It works sometimes and sometimes it doesnt. We have 2008 R2 domain and forest functional level and all DCs running 2008 R2 in 3 sites. Any ideas ?

The network team used wire shark to test the packets during RDP over VPN. Thats how I know that it is being rejected on the DC level.
Avatar of aditya Bodapati
aditya Bodapati
Flag of India image

Try testing with in the firewall using different workstations if it's connecting then look DF and MTU section of Tcp packets .

Find out whether tcp request is only one way or other?

Firewall policies check ?
Avatar of Qlemo
Can you be more precise about "rejecting"? Do the clients get an active RST (reset) of the connection out of the blue - which indicates a denial -  or is it more of a timeout?

MTU/DF issues usually lead to hanging RDP sessions (either on connect or while using the session), so I would not count that as "rejected".
Avatar of Exchange User
Exchange User

ASKER

Qlemo,

When you are connected to the VPN and try to RDP on any server, you just cannot even get to the login screen. It  probably says connection time out. Problem is that I cannot reproduce it whenever I want because this issue is intermittent.

aditya,

I will be meeting the firewall guys today but just want to be sure if there would be anything on the DC end. But all other services are working fine which are dependent on the DC so I am not sure.
SOLUTION
Avatar of Qlemo
Qlemo
Flag of Germany image

Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
Thats what I thought. But my networking guy ran a wireshark network packet analyzer report and he came to me saying that the RDP request is being dropped by the domain controller ?
SOLUTION
Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
Run tracert and see if the interface assigned  for managing vpn access points is destined 'any' or 'named group'
I forgot to ask did you check the replication is going fine?
Yes replication is fine, PDC is working fine. I just ran a dcdiag /v /e and couldnt find any issues and also with dcdiag /test:dns /v /e
Qlemo,

I'll have your answers by Monday probably :)
ASKER CERTIFIED SOLUTION
Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial