Re: RWW via VPN only partially working

Tech Tip: Click here to run a free scan for Windows Errors and optimize PC performance



See the "CEICW Walkthrough" link I posted:

CEICW Walkthrough
http://www.sbs-rocks.com/sbs2k3/sbs2k3-n2.htm

It will show you the screen for Web Server Certificate creation. (about half
way down the page; the screen shot is for the Web Server Certificate page in
CEICW)

--
Merv Porter [SBS-MVP]
============================


"Mitch Reno" <mitch@xxxxxxxxxxxxxxxxxxxxxx> wrote in message
news:5500E672-6DBC-4C32-86B2-0C1952F39C23@xxxxxxxxxxxxxxxx
I'm clear on everything you wrote except " create the Web Server
Certificate". Where do I look for that item. Thanks

Mitch


"Merv Porter [SBS-MVP]" wrote:

Hi Mitch,

While VPN is one way to access your server, it can be a path for malware
and
viruses. RWW or a straight RDC session (without connecting the hard
drives
of the remote machine and the server/workstation) is generally a better
way.
VPN also exacts some additional connection "overhead", which can affect
the
end user experience (i.e., slow performance).

Make sure ports 4125 and 443 are forwarded to your SBS NIC (or your SBS
external NIC if you have 2 NICs in the SBS server).

Then, as Jim said, re-run CEICW, enable the firewall, select the services
you want, create the Web Server Certificate with your WAN IP address (the
one given you by your ISP) and then complete the rest of CEICW. Then,
RWW
directly using: https://<WANIPAddress>/remote

CEICW Walkthrough
(for two SBS NICs but most screen will alos work for single SBS NIC)
http://www.sbs-rocks.com/sbs2k3/sbs2k3-n2.htm

What is my IP address
http://whatismyip.com/

If you have a dynamic (not static) WAN IP address assigned by your ISP,
it
may change over time. You will need a (free) service like www.dyndns.com
to
keep track of these changes so you can always have access to your server
and
workstations. This will also give you a hosyname like:
yourcompany.dyndns.org that will be constantly mapped to your
(potentially
changing) WAN IP address. When you get this set up with www.dyndns.com,
re-run CEICW and recreate the Web Server Certificate using your new
hostname
(yourcompany.dyndns.org). From that point, you can access RWW with:
https://yourcompany.dyndns.org/remote

More info on how to set up SBS 2003 using a dynamic WAN IP address:

SBS 2003 DDNS and Email Setup Procedure
(includes RWW info)
http://groups.google.com/group/microsoft.public.windows.server.sbs/msg/be1d68ee2e0ba0d4?hl=en


--
Merv Porter [SBS-MVP]
============================

"Mitch Reno" <mitch@xxxxxxxxxxxxxxxxxxxxxx> wrote in message
news:D2FD8658-6772-45A3-9899-6FDF6B37B079@xxxxxxxxxxxxxxxx
I don't have a registered domain name. The domain we use ends with
.local
.
The ip address doesn't get me through either. In fact less
connectivity
than
if I use the VPN that has been created.
--
Mitch


"SteveB" wrote:

Do you have a registered domain name? If so you can use something like
https://remote.domain.com/remote with the proper externally hosted DNS
records and rerunning the CEICW. Otherwise you can use the external
address.
As Colin says there's no need for the extra configuration of VPN and
potential security risks.

"Mitch Reno" <mitch@xxxxxxxxxxxxxxxxxxxxxx> wrote in message
news:C2B2FC7F-D35A-453B-A083-9394874289B0@xxxxxxxxxxxxxxxx
Maybe I'm misunderstanding something, but our Server's URL ends with
a
.local. I thought to access RWW directly I needed a publicly
available
URL.
Or do I get to it just using the external IP address?

Thanks for your help.
--
Mitch


"Colin" wrote:

Hi Mitch,

Why are you trying to use RWW via VPN ? You can do away with the
VPN
and
use
RWW on it's own. Much more secure and also faster. Were the Vista
PC's
connected to the domain via CEICW ? If so, make sure ports 443 and
4125
are
forwarded from your firewall to your server and you should be good
to
go.

Regards Colin.

"Mitch Reno" <mitch@xxxxxxxxxxxxxxxxxxxxxx> wrote in message
news:907AF4A9-6A1F-490A-8DBB-258BB4DB4D0D@xxxxxxxxxxxxxxxx
I have an SBS2003 network with three workstations running Vista
Business.
Before I changed out the network workstations to new machines
running
Vista
Business, I could connect via VPN and use RWW to access my old
networked
XP
desktops. NOW I can connect via VPN to the SBS server and get to
the
RWW
screen from my laptop at home (which is running Vista Home
Premium).
I
can
access the help desk screen. I can use Outlook web access. But
I
can't
get
to the main objects I need; which are the desktops. I keep
getting
the
message that the computer to which I am trying to connect - must
be
turned
off.

Any suggestions would be appreciated.

--
Mitch









.



Relevant Pages

  • Re: SBS 2003 and self signed SSL certificate
    ... When you re-ran CEICW, did you select "enable" on the ... the Remote Web Workplace service? ... Then create the Web Server Certificate ... If I ignore the cert error after a few clicks I can get in and run RWW ...
    (microsoft.public.windows.server.sbs)
  • Re: Trouble getting RWW from "outside."
    ... Then run CEICW, enable the firewall, ... select your services (including RWW), ... CEICW, enable the firewall, and complete the rest of CEICW so that ISA is ... If you set up the Web Server Certificate with your WAN IP address, ...
    (microsoft.public.windows.server.sbs)
  • RE: A bit confused on the Web Server Certificate
    ... the name is you should input in Web Server Certificate when you run CEICW. ... Microsoft CSS Online Newsgroup Support ... This newsgroup only focuses on SBS technical issues. ...
    (microsoft.public.windows.server.sbs)
  • Re: Exchange 2003 Best Practices Analyzer - HELP PLEASE
    ... If you're using a self-signed certificate, on the Web Server Certificate ... it asks for the full Internet name of your server. ... your server with your WAN IP address assigned by your ISP. ... CEICW Walkthrough ...
    (microsoft.public.windows.server.sbs)
  • Re: Remote Web Workplace
    ... I am confused as to what to put for the Web Server Certificate. ... I understand that you unable access RWW from ... On the SBS 2003 Server open the Server Management console. ...
    (microsoft.public.windows.server.sbs)