Re: Outgoing RWW connections - Getting blocked - How to fix?



Alan wrote:


Hi All,

We are having trouble making outgoing RWW (RDP) connections.

I have currently worked aroung this by placing the workstation that needs to make those connections outside the ISA Server 2004, but still behind the external hardware firewall (ie parallel with the SBS 2003 Prem server running ISA Server 2004).

If I then allow that workstation to make direct outgoing connections using port 3389 (destination) by changing the firewall rules, it all works fine.

However, I would like to be able to keep that workstation 'behind' the ISA Server 2004 and have it 'proxy' the connection as it does for, say, HTTP requests.

I have tried making a total access rule for the workstation in ISA (Allow access using any protocol for any user on that one machine at any time - make it top priority rule), but that still doesn't seem to allow the connection to be made.

The standard SBS Internet Access rule should cover RWW RDP, assuming that the Firewall Client is installed on the workstation.

If you're not using the Firewall Client, then you would need to define an Access Rule as follows:

Allow, Selected Protocols, "SBS_Custom_Protocol_Outbound_4125" (something like that - it's under User-Defined Protocols), From Internal To External for All Users.

I usually rename the predefined protocol definition for SBS RWW RDP from the naff name SBS uses to "RDP (RWW)".

The Access Rule you create simply needs to have a higher priority (lower rule #) than the "SBS Internet Access" rule.

--
Steve Foster [SBS MVP]
---------------------------------------
MVPs do not work for Microsoft. Please reply only to the newsgroups.
.



Relevant Pages

  • Re: ISA 2004 problem
    ... Remote connections might not be enabled or the computer might be too busy to ... I cannot ping to the workstation, but from the local lan yes. ... RDP to the server but not to the workstations. ...
    (microsoft.public.windows.server.sbs)
  • Re: ISA 2004 problem
    ... Remote connections might not be enabled or the computer might be too busy ... I cannot ping to the workstation, but from the local lan yes. ... RDP to the server but not to the workstations. ...
    (microsoft.public.windows.server.sbs)
  • Re: Duplicate printers apearing via TS
    ... RDP works fine, you can have as many connections open as you can practially ... Les Connor [SBS Community Member - SBS MVP] ... Your workstation has this printer installed. ...
    (microsoft.public.windows.server.sbs)
  • Re: Cannot conntect to ActiveSync 4.1 / WM 5
    ... my workstation LAN should be able to remain on static IP ... if, while the PPC device was plugged in, you couldn't connect to ISA ... you've followed the steps in the Troubleshooting ActiveSync 4.1 ... connections from www.microsoft.com/mobile? ...
    (microsoft.public.pocketpc.activesync)
  • Re: SBS Slow user logons problem
    ... Also a detailed description of your network connections will help ... in if the workstation they are loging into is connected to the network. ... I have deleted the Reverse DNS zone on the SBS server and recreated it. ...
    (microsoft.public.windows.server.sbs)