none
RD farm: с клиента windows 10 подключается по RDP, а с win 7 не подключается RRS feed

  • Вопрос

  • Добрый день!

    развернута терминальная ферма

    msk-ts-cb2.domain.local                   сервер, с ролью RD Connection Broker
    msk-ts-gw.domain.local                    сервер, RD Gateway. Public DNS tsgw.domain.ru
    msk-ts-sh02.domain.local                 RD Session Host
    MSK-TS-HA1.domain.LOCAL              DNS round robin name

    создана коллекция сессий для полноценного RDP подключения.

    С удаленного офиса (выделенный канал) с компьютера где установлена windows 10 подключение происходит и пускает по RDP на сервер msk-ts-sh02. А вот с компьютера где установлена windows 7 не подключается, после ввода логина и пароля висит на "инициализация удаленного подключения"

    вот логи, с двух подключений, win 10 и win 7

    Сессия, которая устанавливается с windows 10
    
    Это с роли RD Connection Broker
    
    
    Log Name:      Microsoft-Windows-TerminalServices-RemoteConnectionManager/Operational
    Source:        Microsoft-Windows-TerminalServices-RemoteConnectionManager
    Date:          08.08.2018 10:00:01
    Event ID:      261
    Task Category: None
    Level:         Сведения
    Keywords:      
    User:          NETWORK SERVICE
    Computer:      msk-ts-cb2.domain.local
    Description:
    Прослушиватель RDP-Tcp получил соединение
    
    
    
    Log Name:      Microsoft-Windows-TerminalServices-RemoteConnectionManager/Operational
    Source:        Microsoft-Windows-TerminalServices-RemoteConnectionManager
    Date:          08.08.2018 10:00:02
    Event ID:      1149
    Task Category: None
    Level:         Сведения
    Keywords:      
    User:          NETWORK SERVICE
    Computer:      msk-ts-cb2.domain.local
    Description:
    Службы удаленных рабочих столов: Успешная проверка подлинности пользователя:
    
    Пользователь: s_borovikov
    Домен: domain
    Адрес источника сети: 10.17.48.63
    
    
    
    Log Name:      Microsoft-Windows-TerminalServices-SessionBroker-Client/Operational
    Source:        Microsoft-Windows-TerminalServices-SessionBroker-Client
    Date:          08.08.2018 10:00:02
    Event ID:      1301
    Task Category: Клиент посредника подключений к удаленному рабочему столу обрабатывает запрос пользователя
    Level:         Подробно
    Keywords:      
    User:          NETWORK SERVICE
    Computer:      msk-ts-cb2.domain.local
    Description:
    Клиент посредника подключений к удаленному рабочему столу получил запрос на перенаправление. 
    Пользователь: domain\s_borovikov 
    Версия RDP-клиента: 5
    
    
    
    Log Name:      Microsoft-Windows-TerminalServices-SessionBroker/Operational
    Source:        Microsoft-Windows-TerminalServices-SessionBroker
    Date:          08.08.2018 10:00:02
    Event ID:      800
    Task Category: RD Connection Broker processes connection request
    Level:         Подробно
    Keywords:      
    User:          NETWORK SERVICE
    Computer:      msk-ts-cb2.domain.local
    Description:
    RD Connection Broker received connection request for user domain\s_borovikov. 
    Hints in the RDP file (TSV URL) = tsv://MS Terminal Services Plugin.1.domain_Office_Works 
    Initial Application = NULL 
    Call came from Redirector Server = msk-ts-cb2.domain.local 
    Redirector is configured as Virtual machine redirector
    
    
    
    Log Name:      Microsoft-Windows-TerminalServices-SessionBroker-Client/Operational
    Source:        Microsoft-Windows-TerminalServices-SessionBroker-Client
    Date:          08.08.2018 10:00:02
    Event ID:      1307
    Task Category: Клиент посредника подключений к удаленному рабочему столу обрабатывает запрос пользователя
    Level:         Подробно
    Keywords:      
    User:          NETWORK SERVICE
    Computer:      msk-ts-cb2.domain.local
    Description:
    Клиент посредника подключений к удаленному рабочему столу успешно перенаправил пользователя domain\s_borovikov на конечную точку msk-ts-sh02.domain.local. 
    IP-адрес конечной точки: 10.17.48.62
    
    
    
    Log Name:      Microsoft-Windows-TerminalServices-SessionBroker/Operational
    Source:        Microsoft-Windows-TerminalServices-SessionBroker
    Date:          08.08.2018 10:00:02
    Event ID:      801
    Task Category: RD Connection Broker processes connection request
    Level:         Подробно
    Keywords:      
    User:          NETWORK SERVICE
    Computer:      msk-ts-cb2.domain.local
    Description:
    RD Connection Broker successfully processed the connection request for user domain\s_borovikov. Redirection info: 
    Target Name = MSK-TS-SH02 
    Target IP Address = 10.17.48.62 
    Target Netbios = MSK-TS-SH02 
    Target FQDN = msk-ts-sh02.domain.local 
    Disconnected Session Found = 0x0
    
    
    
    
    Это логи с роли RD Gateway
    
    Log Name:      Microsoft-Windows-TerminalServices-Gateway/Operational
    Source:        Microsoft-Windows-TerminalServices-Gateway
    Date:          08.08.2018 10:00:01
    Event ID:      300
    Task Category: (5)
    Level:         Information
    Keywords:      Audit Success,(16777216)
    User:          NETWORK SERVICE
    Computer:      msk-ts-gw.domain.local
    Description:
    The user "domain\s_borovikov", on client computer "172.17.64.5", met resource authorization policy requirements and was therefore authorized to connect to resource "MSK-TS-HA1.domain.LOCAL".
    
    
    Log Name:      Microsoft-Windows-TerminalServices-Gateway/Operational
    Source:        Microsoft-Windows-TerminalServices-Gateway
    Date:          08.08.2018 10:00:01
    Event ID:      302
    Task Category: (3)
    Level:         Information
    Keywords:      (16777216)
    User:          NETWORK SERVICE
    Computer:      msk-ts-gw.domain.local
    Description:
    The user "domain\s_borovikov", on client computer "172.17.64.5", connected to resource "MSK-TS-HA1.domain.LOCAL". Connection protocol used: "HTTP".
    
    
    Log Name:      Microsoft-Windows-TerminalServices-Gateway/Operational
    Source:        Microsoft-Windows-TerminalServices-Gateway
    Date:          08.08.2018 10:00:02
    Event ID:      303
    Task Category: (3)
    Level:         Information
    Keywords:      (16777216)
    User:          NETWORK SERVICE
    Computer:      msk-ts-gw.domain.local
    Description:
    The user "domain\s_borovikov", on client computer "172.17.64.5", disconnected from the following network resource: "MSK-TS-HA1.domain.LOCAL". Before the user disconnected, the client transferred 6535 bytes and received 11975 bytes. The client session duration was 1 seconds. Connection protocol used: "HTTP".
    
    
    Log Name:      Microsoft-Windows-TerminalServices-Gateway/Operational
    Source:        Microsoft-Windows-TerminalServices-Gateway
    Date:          08.08.2018 10:00:14
    Event ID:      300
    Task Category: (5)
    Level:         Information
    Keywords:      Audit Success,(16777216)
    User:          NETWORK SERVICE
    Computer:      msk-ts-gw.domain.local
    Description:
    The user "domain\s_borovikov", on client computer "172.17.64.5", met resource authorization policy requirements and was therefore authorized to connect to resource "10.17.48.62".
    
    
    Log Name:      Microsoft-Windows-TerminalServices-Gateway/Operational
    Source:        Microsoft-Windows-TerminalServices-Gateway
    Date:          08.08.2018 10:00:14
    Event ID:      302
    Task Category: (3)
    Level:         Information
    Keywords:      (16777216)
    User:          NETWORK SERVICE
    Computer:      msk-ts-gw.domain.local
    Description:
    The user "domain\s_borovikov", on client computer "172.17.64.5", connected to resource "10.17.48.62". Connection protocol used: "HTTP".
    
    
    
    Log Name:      Microsoft-Windows-TerminalServices-Gateway/Operational
    Source:        Microsoft-Windows-TerminalServices-Gateway
    Date:          08.08.2018 10:00:51
    Event ID:      303
    Task Category: (3)
    Level:         Information
    Keywords:      (16777216)
    User:          NETWORK SERVICE
    Computer:      msk-ts-gw.domain.local
    Description:
    The user "domain\s_borovikov", on client computer "172.17.64.5", disconnected from the following network resource: "10.17.48.62". Before the user disconnected, the client transferred 390542 bytes and received 434221 bytes. The client session duration was 36 seconds. Connection protocol used: "HTTP".
    
    
    Это с роли RDSH
    
    
    Log Name:      Microsoft-Windows-TerminalServices-RemoteConnectionManager/Operational
    Source:        Microsoft-Windows-TerminalServices-RemoteConnectionManager
    Date:          08.08.2018 10:00:14
    Event ID:      261
    Task Category: None
    Level:         Сведения
    Keywords:      
    User:          NETWORK SERVICE
    Computer:      msk-ts-sh02.domain.local
    Description:
    Прослушиватель RDP-Tcp получил соединение
    
    
    
    Log Name:      Microsoft-Windows-TerminalServices-RemoteConnectionManager/Operational
    Source:        Microsoft-Windows-TerminalServices-RemoteConnectionManager
    Date:          08.08.2018 10:00:20
    Event ID:      1149
    Task Category: None
    Level:         Сведения
    Keywords:      
    User:          NETWORK SERVICE
    Computer:      msk-ts-sh02.domain.local
    Description:
    Службы удаленных рабочих столов: Успешная проверка подлинности пользователя:
    
    Пользователь: s_borovikov
    Домен: domain
    Адрес источника сети: 10.17.48.63
    
    
    Log Name:      Microsoft-Windows-TerminalServices-LocalSessionManager/Operational
    Source:        Microsoft-Windows-TerminalServices-LocalSessionManager
    Date:          08.08.2018 10:00:22
    Event ID:      41
    Task Category: None
    Level:         Сведения
    Keywords:      
    User:          SYSTEM
    Computer:      msk-ts-sh02.domain.local
    Description:
    Начать разрешение спора для сеанса:
    
    Пользователь: domain\s_borovikov
    Код сеанса: 127
    
    
    
    Log Name:      Microsoft-Windows-TerminalServices-LocalSessionManager/Operational
    Source:        Microsoft-Windows-TerminalServices-LocalSessionManager
    Date:          08.08.2018 10:00:22
    Event ID:      42
    Task Category: None
    Level:         Сведения
    Keywords:      
    User:          SYSTEM
    Computer:      msk-ts-sh02.domain.local
    Description:
    Завершить разрешение спора для сеанса:
    
    Пользователь: domain\s_borovikov
    Код сеанса: 127
    
    
    Log Name:      Microsoft-Windows-TerminalServices-LocalSessionManager/Operational
    Source:        Microsoft-Windows-TerminalServices-LocalSessionManager
    Date:          08.08.2018 10:00:36
    Event ID:      21
    Task Category: None
    Level:         Сведения
    Keywords:      
    User:          SYSTEM
    Computer:      msk-ts-sh02.domain.local
    Description:
    Службы удаленных рабочих столов: Успешный вход в систему:
    
    /Пользователь: domain\s_borovikov
    Код сеанса: 127
    Адрес сети источника: 10.17.48.63
    
    
    Log Name:      Microsoft-Windows-TerminalServices-RemoteConnectionManager/Admin
    Source:        Microsoft-Windows-TerminalServices-RemoteConnectionManager
    Date:          08.08.2018 10:00:36
    Event ID:      20482
    Task Category: None
    Level:         Сведения
    Keywords:      
    User:          NETWORK SERVICE
    Computer:      msk-ts-sh02.domain.local
    Description:
    Справедливое распределение ресурсов сети для служб удаленных рабочих столов включено для учетной записи пользователя domain\s_borovikov с весом 1.
    
    
    Log Name:      Microsoft-Windows-TerminalServices-LocalSessionManager/Operational
    Source:        Microsoft-Windows-TerminalServices-LocalSessionManager
    Date:          08.08.2018 10:00:36
    Event ID:      22
    Task Category: None
    Level:         Сведения
    Keywords:      
    User:          SYSTEM
    Computer:      msk-ts-sh02.domain.local
    Description:
    Службы удаленных рабочих столов: Получено уведомление о запуске оболочки:
    
    Пользователь: domain\s_borovikov
    Код сеанса: 127
    Адрес сети источника: 10.17.48.63
    
    
    Log Name:      Microsoft-Windows-TerminalServices-LocalSessionManager/Operational
    Source:        Microsoft-Windows-TerminalServices-LocalSessionManager
    Date:          08.08.2018 10:00:51
    Event ID:      40
    Task Category: None
    Level:         Сведения
    Keywords:      
    User:          SYSTEM
    Computer:      msk-ts-sh02.domain.local
    Description:
    Сенас 127 был отключен, код причины 0
    
    
    
    Log Name:      Microsoft-Windows-TerminalServices-LocalSessionManager/Operational
    Source:        Microsoft-Windows-TerminalServices-LocalSessionManager
    Date:          08.08.2018 10:00:51
    Event ID:      24
    Task Category: None
    Level:         Сведения
    Keywords:      
    User:          SYSTEM
    Computer:      msk-ts-sh02.domain.local
    Description:
    Службы удаленных рабочих столов: Сеанс был отключен:
    
    Пользователь: domain\s_borovikov
    Код сеанса: 127
    Адрес сети источника: 10.17.48.63
    
    
    
    
    
    Логи сессии, которая не устанавливается c windows 7
    
    
    RD Connection Broker
    
    
    Log Name:      Microsoft-Windows-TerminalServices-RemoteConnectionManager/Operational
    Source:        Microsoft-Windows-TerminalServices-RemoteConnectionManager
    Date:          08.08.2018 10:38:36
    Event ID:      261
    Task Category: None
    Level:         Сведения
    Keywords:      
    User:          NETWORK SERVICE
    Computer:      msk-ts-cb2.domain.local
    Description:
    Прослушиватель RDP-Tcp получил соединение
    
    
    Log Name:      Microsoft-Windows-TerminalServices-RemoteConnectionManager/Operational
    Source:        Microsoft-Windows-TerminalServices-RemoteConnectionManager
    Date:          08.08.2018 10:38:37
    Event ID:      1149
    Task Category: None
    Level:         Сведения
    Keywords:      
    User:          NETWORK SERVICE
    Computer:      msk-ts-cb2.domain.local
    Description:
    Службы удаленных рабочих столов: Успешная проверка подлинности пользователя:
    
    Пользователь: s_borovikov
    Домен: domain
    Адрес источника сети: 10.17.48.63
    
    
    Log Name:      Microsoft-Windows-TerminalServices-SessionBroker-Client/Operational
    Source:        Microsoft-Windows-TerminalServices-SessionBroker-Client
    Date:          08.08.2018 10:38:37
    Event ID:      1301
    Task Category: Клиент посредника подключений к удаленному рабочему столу обрабатывает запрос пользователя
    Level:         Подробно
    Keywords:      
    User:          NETWORK SERVICE
    Computer:      msk-ts-cb2.domain.local
    Description:
    Клиент посредника подключений к удаленному рабочему столу получил запрос на перенаправление. 
    Пользователь: domain\s_borovikov 
    Версия RDP-клиента: 5
    
    
    Log Name:      Microsoft-Windows-TerminalServices-SessionBroker/Operational
    Source:        Microsoft-Windows-TerminalServices-SessionBroker
    Date:          08.08.2018 10:38:37
    Event ID:      800
    Task Category: RD Connection Broker processes connection request
    Level:         Подробно
    Keywords:      
    User:          NETWORK SERVICE
    Computer:      msk-ts-cb2.domain.local
    Description:
    RD Connection Broker received connection request for user domain\s_borovikov. 
    Hints in the RDP file (TSV URL) = tsv://MS Terminal Services Plugin.1.domain_Office_Works 
    Initial Application = NULL 
    Call came from Redirector Server = msk-ts-cb2.domain.local 
    Redirector is configured as Virtual machine redirector
    
    
    Log Name:      Microsoft-Windows-TerminalServices-SessionBroker-Client/Operational
    Source:        Microsoft-Windows-TerminalServices-SessionBroker-Client
    Date:          08.08.2018 10:38:38
    Event ID:      1307
    Task Category: Клиент посредника подключений к удаленному рабочему столу обрабатывает запрос пользователя
    Level:         Подробно
    Keywords:      
    User:          NETWORK SERVICE
    Computer:      msk-ts-cb2.domain.local
    Description:
    Клиент посредника подключений к удаленному рабочему столу успешно перенаправил пользователя domain\s_borovikov на конечную точку msk-ts-sh02.domain.local. 
    IP-адрес конечной точки: 10.17.48.62
    
    
    Log Name:      Microsoft-Windows-TerminalServices-SessionBroker/Operational
    Source:        Microsoft-Windows-TerminalServices-SessionBroker
    Date:          08.08.2018 10:38:38
    Event ID:      801
    Task Category: RD Connection Broker processes connection request
    Level:         Подробно
    Keywords:      
    User:          NETWORK SERVICE
    Computer:      msk-ts-cb2.domain.local
    Description:
    RD Connection Broker successfully processed the connection request for user domain\s_borovikov. Redirection info: 
    Target Name = MSK-TS-SH02 
    Target IP Address = 10.17.48.62 
    Target Netbios = MSK-TS-SH02 
    Target FQDN = msk-ts-sh02.domain.local 
    Disconnected Session Found = 0x1
    
    
    RD Gateway
    
    Log Name:      Microsoft-Windows-TerminalServices-Gateway/Operational
    Source:        Microsoft-Windows-TerminalServices-Gateway
    Date:          08.08.2018 10:38:22
    Event ID:      312
    Task Category: (3)
    Level:         Information
    Keywords:      
    User:          NETWORK SERVICE
    Computer:      msk-ts-gw.domain.local
    Description:
    The user "s_borovikov@domain", on client computer "172.17.64.5:55079", has initiated an outbound connection. This connection may not be authenticated yet.
    
    
    Log Name:      Microsoft-Windows-TerminalServices-Gateway/Operational
    Source:        Microsoft-Windows-TerminalServices-Gateway
    Date:          08.08.2018 10:38:22
    Event ID:      313
    Task Category: (3)
    Level:         Information
    Keywords:      
    User:          NETWORK SERVICE
    Computer:      msk-ts-gw.domain.local
    Description:
    The user "s_borovikov@domain", on client computer "172.17.64.5:55080", has initiated an inbound connection. This connection may not be authenticated yet.
    
    
    Log Name:      Microsoft-Windows-TerminalServices-Gateway/Operational
    Source:        Microsoft-Windows-TerminalServices-Gateway
    Date:          08.08.2018 10:38:22
    Event ID:      200
    Task Category: (2)
    Level:         Information
    Keywords:      Audit Success,(16777216)
    User:          NETWORK SERVICE
    Computer:      msk-ts-gw.domain.local
    Description:
    The user "domain\s_borovikov", on client computer "172.17.64.5", met connection authorization policy requirements and was therefore authorized to access the RD Gateway server. The authentication method used was: "NTLM" and connection protocol used: "HTTP".
    
    
    Log Name:      Microsoft-Windows-TerminalServices-Gateway/Operational
    Source:        Microsoft-Windows-TerminalServices-Gateway
    Date:          08.08.2018 10:38:22
    Event ID:      300
    Task Category: (5)
    Level:         Information
    Keywords:      Audit Success,(16777216)
    User:          NETWORK SERVICE
    Computer:      msk-ts-gw.domain.local
    Description:
    The user "domain\s_borovikov", on client computer "172.17.64.5", met resource authorization policy requirements and was therefore authorized to connect to resource "MSK-TS-HA1.domain.LOCAL".
    
    
    Log Name:      Microsoft-Windows-TerminalServices-Gateway/Operational
    Source:        Microsoft-Windows-TerminalServices-Gateway
    Date:          08.08.2018 10:38:22
    Event ID:      300
    Task Category: (5)
    Level:         Information
    Keywords:      Audit Success,(16777216)
    User:          NETWORK SERVICE
    Computer:      msk-ts-gw.domain.local
    Description:
    The user "domain\s_borovikov", on client computer "172.17.64.5", met resource authorization policy requirements and was therefore authorized to connect to resource "MSK-TS-HA1.domain.LOCAL".
    
    
    Log Name:      Microsoft-Windows-TerminalServices-Gateway/Operational
    Source:        Microsoft-Windows-TerminalServices-Gateway
    Date:          08.08.2018 10:38:22
    Event ID:      302
    Task Category: (3)
    Level:         Information
    Keywords:      (16777216)
    User:          NETWORK SERVICE
    Computer:      msk-ts-gw.domain.local
    Description:
    The user "domain\s_borovikov", on client computer "172.17.64.5", connected to resource "MSK-TS-HA1.domain.LOCAL". Connection protocol used: "HTTP".
    
    
    Log Name:      Microsoft-Windows-TerminalServices-Gateway/Operational
    Source:        Microsoft-Windows-TerminalServices-Gateway
    Date:          08.08.2018 10:38:35
    Event ID:      303
    Task Category: (3)
    Level:         Information
    Keywords:      (16777216)
    User:          NETWORK SERVICE
    Computer:      msk-ts-gw.domain.local
    Description:
    The user "domain\s_borovikov", on client computer "172.17.64.5", disconnected from the following network resource: "MSK-TS-HA1.domain.LOCAL". Before the user disconnected, the client transferred 2088 bytes and received 3194 bytes. The client session duration was 12 seconds. Connection protocol used: "HTTP".
    Event Xml:
    
    
    Log Name:      Microsoft-Windows-TerminalServices-Gateway/Operational
    Source:        Microsoft-Windows-TerminalServices-Gateway
    Date:          08.08.2018 10:38:37
    Event ID:      300
    Task Category: (5)
    Level:         Information
    Keywords:      Audit Success,(16777216)
    User:          NETWORK SERVICE
    Computer:      msk-ts-gw.domain.local
    Description:
    The user "domain\s_borovikov", on client computer "172.17.64.5", met resource authorization policy requirements and was therefore authorized to connect to resource "MSK-TS-HA1.domain.LOCAL".
    
    
    Log Name:      Microsoft-Windows-TerminalServices-Gateway/Operational
    Source:        Microsoft-Windows-TerminalServices-Gateway
    Date:          08.08.2018 10:38:37
    Event ID:      302
    Task Category: (3)
    Level:         Information
    Keywords:      (16777216)
    User:          NETWORK SERVICE
    Computer:      msk-ts-gw.domain.local
    Description:
    The user "domain\s_borovikov", on client computer "172.17.64.5", connected to resource "MSK-TS-HA1.domain.LOCAL". Connection protocol used: "HTTP".
    
    
    Log Name:      Microsoft-Windows-TerminalServices-Gateway/Operational
    Source:        Microsoft-Windows-TerminalServices-Gateway
    Date:          08.08.2018 10:38:38
    Event ID:      303
    Task Category: (3)
    Level:         Information
    Keywords:      (16777216)
    User:          NETWORK SERVICE
    Computer:      msk-ts-gw.domain.local
    Description:
    The user "domain\s_borovikov", on client computer "172.17.64.5", disconnected from the following network resource: "MSK-TS-HA1.domain.LOCAL". Before the user disconnected, the client transferred 5702 bytes and received 11564 bytes. The client session duration was 1 seconds. Connection protocol used: "HTTP".
    
    
    
    На сервер сессий RDSH так и не произошло перенаправление, логов на нем нет
    

    9 августа 2018 г. 12:31

Все ответы