Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

RDP from external network

I have tried Dnat to allow RDP access to internal network via XG 210 to no avail

I was going to use the business app template for non http policy to get remote access with port forwarding but it is no longer listed in the templates

Very frustrating when you follow the articles but they are either out of date or dont work as stated

 

I need to get RDP remote access to the internal server via the XG210 working first so then I can set up site to site ipsec vpn or ssl vpn via 2 remote sites with xg's

 

Need help

Thanks

 



This thread was automatically locked due to age.
Parents
  • Nigel,

    Can you share the dnat you have created?

    Make sure windows firewall is allowing the rdp traffic too.

    Thanks

  • Hi Luk

    The remote sites were connecting to the server via RDP with no probs until I added the xg into the equation

    The server has a static IP and receives RDP traffic on port 10000

    Here is the link I followed.. https://community.sophos.com/kb/en-us/122976

    • Source Zones: WAN
    • Allowed Client Networks: Any
    • Destination Host/Network: WAN Interface    192.168.3.3
    • Forward Type: Select the port, port range or port list that need to be forward from the WAN to the internal server    10000
    • Protected Servers: Select or create an existing host entry for the server     Server_IP (172.16.30.10)
    • Protected Zone: Select the Zone in which the host resides (LAN or DMZ)    LAN
    • Change Destination Port(s): Only check this if you wish to change ports like redirecting port 80 to port 9000   Not Applicable
    • Rewrite source address (Masquerading): Check    Enabled
    • Optional
    • Create Reflexive Rule: Check if the server will be initiating outgoing connections.

     

    I was going to use this KB ... https://community.sophos.com/kb/en-us/123070 but non http based template no longer listed

    So is the DNat Rule the closest to the non http based template

    Thanks

    Nigel

Reply
  • Hi Luk

    The remote sites were connecting to the server via RDP with no probs until I added the xg into the equation

    The server has a static IP and receives RDP traffic on port 10000

    Here is the link I followed.. https://community.sophos.com/kb/en-us/122976

    • Source Zones: WAN
    • Allowed Client Networks: Any
    • Destination Host/Network: WAN Interface    192.168.3.3
    • Forward Type: Select the port, port range or port list that need to be forward from the WAN to the internal server    10000
    • Protected Servers: Select or create an existing host entry for the server     Server_IP (172.16.30.10)
    • Protected Zone: Select the Zone in which the host resides (LAN or DMZ)    LAN
    • Change Destination Port(s): Only check this if you wish to change ports like redirecting port 80 to port 9000   Not Applicable
    • Rewrite source address (Masquerading): Check    Enabled
    • Optional
    • Create Reflexive Rule: Check if the server will be initiating outgoing connections.

     

    I was going to use this KB ... https://community.sophos.com/kb/en-us/123070 but non http based template no longer listed

    So is the DNat Rule the closest to the non http based template

    Thanks

    Nigel

Children