This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Running Remote Desktop Gateway using WAF?

Hi!

I'm trying to migrate from UTM to XG and I can't get my Remote Desktop Gateway working.

In my network, I've got a Win2012R2 server which hosts the RDG-, Broker- and Webgateway-role.

In order to access it from outside of my private LAN, I've created the following business application rule (basically as I did in UTM):

  • HTTP-Template
  • hosted address: (my WAN port)
  • HTTPS: enabled
  • Redirect HTTP: enabled
  • Listening Port: 443
  • Certificate: (selfsigned using the correct FQDN)
  • Domains: (same as in the certificate)
  • protected server: the private IP of the server in my LAN
  • authentication: none
  • allow from: Any IPv4
  • exceptions: none
  • Application Protection: none (also tried a self made rule containing only "Outlook Web Access")
  • Intrusion Prevention: none
  • Traffic shaping: none
  • disable compression: off
  • rewrite HTML: off
  • pass Host Header: on

Now, if I access the server's Remote Desktop webfeed (https://myserver.mydomain.com/RDWeb/Feed/webfeed.aspx) or it's main URL (/RDWeb), I can access its ressources without problems or certificate warnings. Windows even creates shortcuts for the published RemoteApps.

But whenever I try to actually *use* the gateway (for accessing workstations in my LAN) or one of the RemoteApps, my client tries to connect a couple of seconds without success. It simply says "Cannot connect. Please check your connection".

I'm not yet very familiar with XG's log structure but so far I haven't seen any blocked packets or something similiar. I've even set up a rule that allows the Terminal Server to access the WAN zone without any authentification.

When I'm inside my LAN, everything works perfectly, as well as when using UTM 9.

Is there anything I could try?



This thread was automatically locked due to age.
Parents
  • I know this is an older thread, but I can't get this to work against a 2016 RDS Gateway with an RDP8.1 client.  It never attempts to fall back to /rpc and thus fails (I'm guessing due to the RDG_DATA_IN, etc issue).  When you look in the logs, it only attempts to connect to /remoteDesktopGateway.

    Does anyone else have this working on a 2016 Gateway?

    Thanks,

    John

  • Hi John,

    i had the same Problem and had opened a case with Sophos

    .
    Sophos is not interrested in supporting Windows 2016 and RDG through WAF.
    They will not and can`t support RDG in UTM or XG Firewall.

    I think it´s time to seek another Firewall vendor ...

     

Reply
  • Hi John,

    i had the same Problem and had opened a case with Sophos

    .
    Sophos is not interrested in supporting Windows 2016 and RDG through WAF.
    They will not and can`t support RDG in UTM or XG Firewall.

    I think it´s time to seek another Firewall vendor ...

     

Children