Re: Accessing RWW through a proxy server



OK - Thanks - I need to contact the administrator of the other network


"Robert Li [MSFT]" <v-robeli@xxxxxxxxxxxxxxxxxxxx> wrote in message
news:g8nstMmJIHA.4268@xxxxxxxxxxxxxxxxxxxxxxxxx
Hi Roger,

Thanks for your reply.

Based on my research, please take the following steps to narrow down this
issue:

Please ask the problematic user to connect to Internet directly (such as
using ADSL modem at home) and visit RWW. If this time, the user can
connect
to other computer's desktop successfully, is proves the problem is caused
by the Proxy Server. Please contact the administrator of the remote
organization to check if the ports 3389 and 4125 are open. Also, if that's
third party product, please contact the manufacture on how to configure
the
server.

Hope this helps.

I am looking forward to hear from you.

If you need further assistance, please don't hesitate to let me know.

Best regards,

Robert Li(MSFT)

Microsoft CSS Online Newsgroup Support

Get Secure! - www.microsoft.com/security

=====================================================

This newsgroup only focuses on SBS technical issues. If you have issues
regarding other Microsoft products, you'd better post in the corresponding
newsgroups so that they can be resolved in an efficient and timely manner.
You can locate the newsgroup here:
http://www.microsoft.com/communities/newsgroups/en-us/default.aspx

When opening a new thread via the web interface, we recommend you check
the
"Notify me of replies" box to receive e-mail notifications when there are
any updates in your thread. When responding to posts via your newsreader,
please "Reply to Group" so that others may learn and benefit from your
issue.

Microsoft engineers can only focus on one issue per thread. Although we
provide other information for your reference, we recommend you post
different incidents in different threads to keep the thread clean. In
doing
so, it will ensure your issues are resolved in a timely manner.

For urgent issues, you may want to contact Microsoft CSS directly. Please
check http://support.microsoft.com for regional support phone numbers.

Any input or comments in this thread are highly appreciated.

=====================================================

This posting is provided "AS IS" with no warranties, and confers no
rights.

--------------------
<Reply-To: "Roger Cook" <roger-nospam-or-junk-at-redpuma.co.uk>
<From: "Roger Cook" <roger-nospam-or-junk-at-redpuma.co.uk>
<References: <etiJKARJIHA.748@xxxxxxxxxxxxxxxxxxxx>
<izXHDwcJIHA.360@xxxxxxxxxxxxxxxxxxxxxx>
<Subject: Re: Accessing RWW through a proxy server
<Date: Tue, 13 Nov 2007 23:07:28 -0000
<Lines: 134
<X-Priority: 3
<X-MSMail-Priority: Normal
<X-Newsreader: Microsoft Outlook Express 6.00.2900.3028
<X-RFC2646: Format=Flowed; Original
<X-MimeOLE: Produced By Microsoft MimeOLE V6.00.2900.3028
<Message-ID: <uPHT4nkJIHA.2480@xxxxxxxxxxxxxxxxxxxx>
<Newsgroups: microsoft.public.windows.server.sbs
<NNTP-Posting-Host: dsl-217-155-20-126.zen.co.uk 217.155.20.126
<Path: TK2MSFTNGHUB02.phx.gbl!TK2MSFTNGP01.phx.gbl!TK2MSFTNGP05.phx.gbl
<Xref: TK2MSFTNGHUB02.phx.gbl microsoft.public.windows.server.sbs:75739
<X-Tomcat-NG: microsoft.public.windows.server.sbs
<
<Answered inline
<
<
<"Robert Li [MSFT]" <v-robeli@xxxxxxxxxxxxxxxxxxxx> wrote in message
<news:izXHDwcJIHA.360@xxxxxxxxxxxxxxxxxxxxxxxxx
<> Hi Roger,
<>
<> Thanks for posting in our newsgroup.
<>
<> Before we go further on this issue, please let me know the following to
<> make your situation more clearly:
<>
<> 1. Where is the Proxy Server, is it in anther organization?
<> Yes
<> 2. Is the proxy server Microsoft product or third party product?
<> Unknown, probably non-Microsoft
<> 3. What is the network topology of your SBS network?
<> Single NIC behind Sonicwall TZ 170. No ISA
<> 4. Does the RWW user in remote site have problem access to the computer
<> Yes - I believe its the "remote connectivity cannot be established"
<> message but not sure. OWA works fine
<> desktop? If so, what's the error message?
<>
<> Based on my experience, if the Proxy Server is in the remote
organization
<> and the ISA server is the proxy server, the remote desktop connection
<> should work OK. The following is how the RWW works:
<>
<> 1. The client workstation sends http connection request to ISA server.
<> 2. The ISA server forward the request to SBS with source IP address of
its
<> external NIC. (Note: Not from the IP address of the client computer).
<> 3. SBS TS Proxy is used to forward TS requests through a firewall on
TCP
<> port 4125.
<> 4. Once the connection is established on port 4125, the traffic is then
<> redirected to another dynamically allocated port.
<> 5. All subsequence traffic will flow through the new port at the server
to
<> the client at port 3389.
<>
<> The Remote Desktop ActiveX Control network traffic is still from the
<> External NIC of the ISA, not from client workstation. this will not
create
<> the source IP address mismatch since they are all from the IP of ISA's
<> external NIC.
<>
<> Hope this helps.
<>
<> I am looking forward to hear from you.
<>
<> If you need further assistance, please don't hesitate to let me know.
<>
<>
<> Best regards,
<>
<> Robert Li(MSFT)
<>
<> Microsoft CSS Online Newsgroup Support
<>
<> Get Secure! - www.microsoft.com/security
<>
<> =====================================================
<>
<> This newsgroup only focuses on SBS technical issues. If you have issues
<> regarding other Microsoft products, you'd better post in the
corresponding
<> newsgroups so that they can be resolved in an efficient and timely
manner.
<> You can locate the newsgroup here:
<> http://www.microsoft.com/communities/newsgroups/en-us/default.aspx
<>
<> When opening a new thread via the web interface, we recommend you check
<> the
<> "Notify me of replies" box to receive e-mail notifications when there
are
<> any updates in your thread. When responding to posts via your
newsreader,
<> please "Reply to Group" so that others may learn and benefit from your
<> issue.
<>
<> Microsoft engineers can only focus on one issue per thread. Although we
<> provide other information for your reference, we recommend you post
<> different incidents in different threads to keep the thread clean. In
<> doing
<> so, it will ensure your issues are resolved in a timely manner.
<>
<> For urgent issues, you may want to contact Microsoft CSS directly.
Please
<> check http://support.microsoft.com for regional support phone numbers.
<>
<> Any input or comments in this thread are highly appreciated.
<>
<> =====================================================
<>
<> This posting is provided "AS IS" with no warranties, and confers no
<> rights.
<>
<> --------------------
<> <Reply-To: "Roger Cook" <roger-nospam-or-junk-at-redpuma.co.uk>
<> <From: "Roger Cook" <roger-nospam-or-junk-at-redpuma.co.uk>
<> <Subject: Accessing RWW through a proxy server
<> <Date: Mon, 12 Nov 2007 09:40:17 -0000
<> <Lines: 16
<> <X-Priority: 3
<> <X-MSMail-Priority: Normal
<> <X-Newsreader: Microsoft Outlook Express 6.00.2900.3028
<> <X-RFC2646: Format=Flowed; Original
<> <X-MimeOLE: Produced By Microsoft MimeOLE V6.00.2900.3028
<> <Message-ID: <etiJKARJIHA.748@xxxxxxxxxxxxxxxxxxxx>
<> <Newsgroups: microsoft.public.windows.server.sbs
<> <NNTP-Posting-Host: dsl-217-155-20-126.zen.co.uk 217.155.20.126
<> <Path: TK2MSFTNGHUB02.phx.gbl!TK2MSFTNGP01.phx.gbl!TK2MSFTNGP04.phx.gbl
<> <Xref: TK2MSFTNGHUB02.phx.gbl microsoft.public.windows.server.sbs:75284
<> <X-Tomcat-NG: microsoft.public.windows.server.sbs
<> <
<> <I have RWW running fine for several people, apart from one user who
<> works
<> <three days a week at another organisation., where internet access is
<> routed
<> <through a proxy server - I presume that the problem is related to the
<> issue
<> <below (quoted from elsewhere). Is there a way around this?
<> <
<> <=============
<> <When you connect to RWW, it knows your source IP as you've connected
on
<> port
<> <443 - later when the activeX control makes the connection via port
4125,
<> it
<> <checks to see that the inbound connection is coming from the same IP
as
<> the
<> <443 connection - if not then it terminates the connection. This can be
a
<> <problem though if the user is coming through any form of proxy server
<> that
<> <is interfering with ports 80 and 443 - the IP will not match with that
<> for
<> <4125 and it will fail as described
<> <============
<> <
<> <
<> <
<>
<
<
<



.



Relevant Pages

  • Re: open port in isa 2004 ?
    ... thank you for using Microsoft newsgroup. ... | Subject: Re: open port in isa 2004? ... |> How to configure networks in ISA Server 2004 ...
    (microsoft.public.windows.server.sbs)
  • Re: GRC.com shows port 80 open
    ... the port 80 is open whether you put a hardware firewall or not ... Microsoft CSS Online Newsgroup Support ... This newsgroup only focuses on SBS technical issues. ...
    (microsoft.public.windows.server.sbs)
  • RE: Cant access SBS from the Internet
    ... through port 444, so I added a new port ... If you visit companyweb from Internet, ... Microsoft CSS Online Newsgroup Support ... This newsgroup only focuses on SBS technical issues. ...
    (microsoft.public.windows.server.sbs)
  • Re: Weird 529 Errors in Security Log
    ... Port 80 has always been closed on both my router/firewall and ISA 2004. ... Les Connor [SBS MVP] ... click to check the "Hide All Microsoft ... This newsgroup only focuses on SBS technical issues. ...
    (microsoft.public.windows.server.sbs)
  • RE: Printing from the DMZ zone
    ... If your printer is local shard printer, you have to change the port 9100 to ... Microsoft CSS Online Newsgroup Support ... This newsgroup only focuses on SBS technical issues. ... Printing from the DMZ zone ...
    (microsoft.public.windows.server.sbs)

Loading