Re: ISA - RDP and Citrix

From: Kilgore Troute (troute_kilgore_at_yahoo.com)
Date: 06/15/04


Date: 15 Jun 2004 04:35:41 -0700

My access policies look like this:
  1. HTTP -> TYPE PROTOCOL -> Applies to ALL IP TRAFFIC -> ANY REQUEST

The HTTP rule was origionaly limitted to certain protocols, but I did
all IP traffic hoping that would allow the RDP connection

Under protocol definitions I created one named RDP. It is setup as
follows:
RDP -> DEFINED BY USER -> PORT 4125 -> TCP -> OUTBOUND
ISA already had one named RDP on port 3389 inbound TCP

Our users / vendors aren't having trouble accessing anything but
Citrix / RDP sites.

Thanks for your timely reply.

Actually, I think I just figured out what is happening. We are
switching internet providers - I can't fully switch over the T1 yet,
so, what I did was put the ISA server on the NEW T1's gateway - a
10.1.20.3 internal address. Our core router still points to 10.1.1.1
the old T1's gateway. So users initially connect to ISA and retreive
the Webpage to connect, but once the RDP session tries to start, it
gets routed to the OLD T1.. which is an outsourced, or, managed
firewall. Err.

"Jim Harrison [MSFT]" <jmharr@online.microsoft.com> wrote in message news:<Ov8tAchUEHA.4088@TK2MSFTNGP09.phx.gbl>...
> You don't say what your ISA policies are..?
> Q1 - Do you have a protocol rule allowing RDP?
> Q2 - Can your vendors get access for other non-HTTP protocols through your ISA?
>
> --
> Jim Harrison [ISASE]
> Read the help, books and articles!
>
> This posting is provided "AS IS" with no warranties, and confers no rights.
>
>
> "Kilgore Troute" <troute_kilgore@yahoo.com> wrote in message news:bb51ccd2.0406140424.4d109a4c@posting.google.com...
> Set up: We have a cisco Pix and an ISA 2000 box. The pix is setup to
> allow internet traffic from ISA. All Clients use the ISA box as
> their proxy.
>
> A few of our employees need to be able to RDP to a remote server
> (vendor site). The vendor appears to be using the TSWEB module,
> running terminal services.
>
> When they try to connect to the remote desktop they get the error:
> Remote Desktop Disconnected, the server may not be accepting
> connections... yada yada yada.
>
> I've ruled out the firewall because I can RDP to this site directly
> from the ISA box.
>
> I've tried searching google and MS, and haven't found anything that
> works. Any help would be great.



Relevant Pages

  • Re: ISA SP3 lockdown?
    ... that size ("Remote Desktop for VPN access") doesn't fit. ... either use RDP or VPN, or RDP over VPN, but RDP does not "replace" VPN, nor ... What is in the ISA logs? ... protocols") is that you're trying to to solve all the problems at once using ...
    (microsoft.public.isa)
  • Re: ISA SP3 lockdown?
    ... It looks like "RDP over VPN" would be ... address for the PIX and external NIC on the ISA to another range. ... comes with RDP predefined in its list of protocols but neither it or any ... What's becoming clear ("I also added ICA, RDP Server, Rlogin and SSH ...
    (microsoft.public.isa)
  • RE: RDP through ISA 2000 for a non-domain user on SBS2003
    ... SBS domain cannot access external RDP. ... the web proxy and the ISA firewall client can provide ... You can access the external web sites from the laptop, ...
    (microsoft.public.windows.server.sbs)
  • RE: ISA 2000 on SBS2003
    ... Could you tell me the detailed symptom of the RDP service? ... Help to gather the ISA Logs: ... Double click ISA Server Firewall Service in the right pane, ... Microsoft CSS Online Newsgroup Support ...
    (microsoft.public.windows.server.sbs)
  • RDP Suddenly Stopped?
    ... After physically going to the ISA server we saw that ... internet traffic and email started flowing again, however RDP still won't ... Remote desktop is enabled in the system properties, ... Destination IP - 192.168.0.1 ...
    (microsoft.public.isa)