My UTM 9 is allowing my end users access to RDS/HCSS Cloud Provider service. It's virtual desktop session that my end users use. Simliar to Citrix. The conversation occurs over tcp/443. I've noticed through exported logs (pcaps), that the conversation is also over udp/3391.
Peroidically, the firewall will drop the return traffic with a "60001" error code. But, only for the udp/3391 traffic. Example, if the provider address was 1.1.1.1 and my primary WAN ip is 2.2.2.2, the traffic flow would look something like this src: 1.1.1.1:3391 dst:2.2.2.2:56434.
The odd part is it's not consistent. I see two-way traffic within my pcaps between the WAN IP and the provider. For both tcp/443 and udp/3391. So, that tells me my DNATs/SNATs/MSQs and associated rules are all correct. When I do see the denies, it's precisely at the time when my end users complain about their RDP sessions freezing up.
Thoughts from the group?
Could this be something with SNORT/IPS on the firewall? Or something more on the provider side?
This thread was automatically locked due to age.