Re: ISA 2004, remote desktop issue to internal clients



Are you running the xp firewall, if so turn it off and then test access.
"James Wright" <CMCGroup@xxxxxxxxxxxxxx> wrote in message
news:4F93F699-C59B-4A1E-8DD1-90AF224BD0E3@xxxxxxxxxxxxxxxx
Yes, that rule is fine. VPN clients can access everything on the
network--even RD to our file server (10.0.0.251).. but cannnot RD to this
XP
Pro box (10.0.0.64).
--
-James Wright



"Kevin Longley" wrote:

Have you created a rule that allows vpn clients access to the internal
network?

"James Wright" <CMCGroup@xxxxxxxxxxxxxx> wrote in message
news:B620B705-6FAF-4757-90CE-C62ADAEC5602@xxxxxxxxxxxxxxxx
I have a SBS 2003 server, XP Pro SP2 client (internal network), and ISA
2004
(acting as VPN and firewall) with a T1 for the WAN interface.

My issue:
Domain Users and Domains Admins CAN while VPNed in:
Open a remote desktop session (RDP 3389) with the SBS 2003 box just
fine.
10.0.0.251

BUT-
Domain Users and Domain Admins cannot open a RD session with a XP Pro
SP2
box on the internal network. Domain Users and Domain Admins can get to
this
computer just fine when connected to the LAN (just not with VPN).
10.0.0.64

Things I've already done:
Remote Desktop is enabled on my XP Pro client
Both the above user groups are added for permissions
Tried to connect to both host and IP address
Tried adding the client IP to the host file

I check the logs on the ISA 2004 server, and I see the VPN client
session
initiates a connection for RDP 3389 with the IP address of the XP Pro
box.
But, it will just time out and close the connection. I don't see any
traffic
logs that point to a rule denying the service.

Why won't RD work?

-James Wright





.



Relevant Pages

  • Re: ISA 2004, remote desktop issue to internal clients
    ... VPN clients can access everything on the ... network--even RD to our file server.. ... Domain Users and Domain Admins cannot open a RD session with a XP Pro SP2 ...
    (microsoft.public.isa)
  • Re: make one group a member of another
    ... one would do this on the Pro machine and there add the ... > and add domain users to the administrators local group. ... You want to avoid making users local administrators ... >> windows 2000 server on certain PCs a member of the local admin group of ...
    (microsoft.public.win2000.security)
  • Finding the UID for samba users
    ... File server which runs FC3. ... I know the GID for the domain users, ... I know that I can do it by logging in as each individual user, ... Jeremiah 33:3 ...
    (Fedora)
  • Re: Finding the UID for samba users
    ... > File server which runs FC3. ... I know the GID for the domain users, ... > I know that I can do it by logging in as each individual user, ... Substitute "username" with the username you're interested in. ...
    (Fedora)
  • Re: GPO Firewall Issues
    ... I found the correct GPO so I could let domain users decide if they want to ... so I haven't been able to try installing it yet. ... My plan of action is to turn of firewall and run installed, ...
    (microsoft.public.windows.server.sbs)

Quantcast