TMG 2010 don´t permit RDP conections to external servers

Answered TMG 2010 don´t permit RDP conections to external servers

  • Wednesday, January 09, 2013 9:45 PM
     
     

    I have problems to enable terminal server connections (RDP protocol) I created a specific rule but still TMG server does not allow, the exact situation is that when I try to connect to the remote server, the server closes the connection TMG please them appreciate any help when tracking logs the error message that I get is: Unspecified error

All Replies

  • Thursday, January 10, 2013 5:17 AM
     
     Answered

    HI,

    create a Firewall policy rule which allows the RDP Protocol from INTERNAL To EXTERNAL for ALL USERS. The clients must be Secure NAT clients


    regards Marc Grote aka Jens Baier - www.it-training-grote.de - www.forefront-tmg.de - www.nt-faq.de

  • Thursday, January 10, 2013 2:41 PM
     
     

    HI, Marc

    thank you for response to me, i had created a rule that permit the RDP protocol from INTERNAL to EXTERNAL for ALL USERS, but how to make an SECURE NAT CLIENTS

  • Friday, January 11, 2013 7:33 AM
    Moderator
     
     

    Hi,

    Thank you for the post.

    Secure NAT client means its default gateway should point to TMG server. What is TMG live logging tell when internal client RDP to external client?

    Regards,


    Nick Gu - MSFT

  • Friday, January 11, 2013 3:12 PM
     
     

    Hi Nick,

    Thank you for you answer,  the gateway for my internal Network is my Switch Core and the default gateway for my switch Core is the TMG Server,  in my rule   "Terminal Service",  I´m  permit  all the RDP Protocols from Internal Network to EXternal Network and i adding the  external server that i need to connect using Terminal Services, for all Users, please help me

  • Thursday, January 17, 2013 7:03 AM
    Moderator
     
     Answered

    Hi,

    Thank you for the update.

    On TMG server, you should add internal subnet(subnet behind switch core) to the network definition for Internal. And then add a static route from the command line to point to switch core.

    Regards,


    Nick Gu - MSFT