Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

WAF and Remotedesktopgateway 2019 SFOS 18

Hi,

actually i fail with installing a Remotedesktogateway and the Webserver Protection.

Reverseproxy Error when try to login to RDGW.

[Sat Dec 11 13:02:04.941531 2021] [proxy_http:error] [pid 3252:tid 139836996437760] (104)Connection reset by peer: [client 93.XXX.XXX.XXX:58154] AH01102: error reading status line from remote server 172.17.2.14:443
[Sat Dec 11 13:02:04.941561 2021] [proxy:error] [pid 3252:tid 139836996437760] [client 93.XXX.XXX.XXX:58154] AH00898: Error reading from remote server returned by /KdcProxy
[Sat Dec 11 13:02:04.929358 2021] timestamp="1639224124" srcip="93.XXX.XXX.XXX" localip="91.XXX.XXX.XXX" user="-" method="POST" statuscode="502" reason="-" extra="-" exceptions="-" duration="12316" url="/KdcProxy" server="rdgw.mydomain.com" referer="-" cookie="-" set-cookie="-" recvbytes="905" sentbytes="5758" protocol="HTTP/1.1" ctype="text/html" uagent="kerberos/1.0" querystring="" websocket_scheme="-" websocket_protocol="-" websocket_key="-" websocket_version="-" ruleid="32"
[Sat Dec 11 13:02:04.952762 2021] timestamp="1639224124" srcip="93.XXX.XXX.XXX" localip="91.XXX.XXX.XXX" user="-" method="RDG_OUT_DATA" statuscode="401" reason="-" extra="-" exceptions="-" duration="11398" url="/remoteDesktopGateway/" server="rdgw.mydomain.com" referer="-" cookie="-" set-cookie="-" recvbytes="1004" sentbytes="5974" protocol="HTTP/1.1" ctype="text/html" uagent="MS-RDGateway/1.0" querystring="" websocket_scheme="-" websocket_protocol="-" websocket_key="VFFqnASo6NkIEuRyuKXeIg==" websocket_version="13" ruleid="32"
[Sat Dec 11 13:02:05.044540 2021] [proxy_http:error] [pid 3252:tid 139836996437760] (104)Connection reset by peer: [client 93.XXX.XXX.XXX:58154] AH01102: error reading status line from remote server 172.17.2.14:443
[Sat Dec 11 13:02:05.033875 2021] timestamp="1639224125" srcip="93.XXX.XXX.XXX" localip="91.XXX.XXX.XXX" user="-" method="POST" statuscode="200" reason="-" extra="-" exceptions="-" duration="10801" url="/KdcProxy" server="rdgw.mydomain.com" referer="-" cookie="-" set-cookie="-" recvbytes="488" sentbytes="31" protocol="HTTP/1.1" ctype="-" uagent="kerberos/1.0" querystring="" websocket_scheme="-" websocket_protocol="-" websocket_key="-" websocket_version="-" ruleid="32"
[Sat Dec 11 13:02:05.050997 2021] timestamp="1639224125" srcip="93.XXX.XXX.XXX" localip="91.XXX.XXX.XXX" user="-" method="RDG_IN_DATA" statuscode="401" reason="-" extra="-" exceptions="-" duration="9853" url="/remoteDesktopGateway/" server="rdgw.mydomain.com" referer="-" cookie="-" set-cookie="-" recvbytes="802" sentbytes="6031" protocol="HTTP/1.1" ctype="text/html" uagent="MS-RDGateway/1.0" querystring="" websocket_scheme="-" websocket_protocol="-" websocket_key="-" websocket_version="-" ruleid="32"
[Sat Dec 11 13:02:05.067768 2021] timestamp="1639224125" srcip="93.XXX.XXX.XXX" localip="91.XXX.XXX.XXX" user="-" method="RDG_IN_DATA" statuscode="200" reason="-" extra="-" exceptions="-" duration="2853" url="/remoteDesktopGateway/" server="rdgw.mydomain.com" referer="-" cookie="-" set-cookie="-" recvbytes="1174" sentbytes="176" protocol="HTTP/1.1" ctype="-" uagent="MS-RDGateway/1.0" querystring="" websocket_scheme="-" websocket_protocol="-" websocket_key="-" websocket_version="-" ruleid="32"
[Sat Dec 11 13:02:25.191959 2021] [proxy_http:error] [pid 3252:tid 139836988045056] (70007)The timeout specified has expired: [client 93.XXX.XXX.XXX:58155] AH01095: prefetch request body failed to 172.17.2.14:443 (172.17.2.14) from 93.XXX.XXX.XXX ()
[Sat Dec 11 13:02:05.076745 2021] timestamp="1639224125" srcip="93.XXX.XXX.XXX" localip="91.XXX.XXX.XXX" user="-" method="RDG_IN_DATA" statuscode="408" reason="-" extra="-" exceptions="-" duration="20115368" url="/remoteDesktopGateway/" server="rdgw.mydomain.com" referer="-" cookie="-" set-cookie="-" recvbytes="487" sentbytes="420" protocol="HTTP/1.1" ctype="text/html" uagent="MS-RDGateway/1.0" querystring="" websocket_scheme="-" websocket_protocol="-" websocket_key="-" websocket_version="-" ruleid="32"
[Sat Dec 11 13:02:25.193040 2021] [proxy_http:error] [pid 3252:tid 139837004830464] (104)Connection reset by peer: [client 93.XXX.XXX.XXX:58153] AH01110: error reading response
[Sat Dec 11 13:02:04.971265 2021] timestamp="1639224124" srcip="93.XXX.XXX.XXX" localip="91.XXX.XXX.XXX" user="-" method="RDG_OUT_DATA" statuscode="200" reason="-" extra="-" exceptions="-" duration="20221862" url="/remoteDesktopGateway/" server="rdgw.mydomain.com" referer="-" cookie="-" set-cookie="-" recvbytes="1376" sentbytes="144" protocol="HTTP/1.1" ctype="-" uagent="MS-RDGateway/1.0" querystring="" websocket_scheme="-" websocket_protocol="-" websocket_key="VFFqnASo6NkIEuRyuKXeIg==" websocket_version="13" ruleid="32"

Is anybody there who has installed RDGW and WAF?



This thread was automatically locked due to age.
Parents
  • Hi, 

    i just found a solution for me. 

    I enabled Path Specific Routing without anything else and now RDGW with Azure MFA works fine.

    Regards

  • Hi,

    I wanted to thank you as your reply helpded me figure out how to configure the WAF to make RDGW 2019 work properly. On my end, Path Specific Routing with "WebSocket Passthrough" enabled allowed for the RPC over HTTPS connection to work.

    I also had Static URL Hardening rules defined but couldn't get /RDWeb to work as it is dynamically generating a part of the URL so I had to make an exception for that entry point in the WAF rule.

    Note that entry points are case sensitive, that is why I have multiple /RDWeb entries.

    Thanks 

Reply
  • Hi,

    I wanted to thank you as your reply helpded me figure out how to configure the WAF to make RDGW 2019 work properly. On my end, Path Specific Routing with "WebSocket Passthrough" enabled allowed for the RPC over HTTPS connection to work.

    I also had Static URL Hardening rules defined but couldn't get /RDWeb to work as it is dynamically generating a part of the URL so I had to make an exception for that entry point in the WAF rule.

    Note that entry points are case sensitive, that is why I have multiple /RDWeb entries.

    Thanks 

Children
Share Feedback
×

Submitted a Tech Support Case lately from the Support Portal?