RDP through L2L problems.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
10-26-2012 03:04 PM - edited 03-11-2019 05:14 PM
Having a strange issue with RDP to an XP machine through a L2L tunnel.
Tunnel is between an ASA5505 and ASA5510. Site A 5510, Site B 5505
I have a handful of Win7 and XP Dev machines running on ESXi 4.1 within Site A.
Site B to Site A
- I can RDP to all Server 2008 and W7 machines(physical and virtual).
- I can also RDP to a physical XP machine.
- I can ping the XP VMs by name and IP successfully.
- I cannot RDP to the 5 XP VMs running on the ESXi 4.1 host
Site A to Site B
- I can RDP from the XP VMs on the ESXi 4.1 host to any machine within Site B.
- Within Site A I can RDP to these XP VMs
AnyConnect
- I can AnyConnect into Site A and RDP to the XP VMs
I have tried to Telnet on 3389 to the XP VMs with no success.
Any ideas?
- Labels:
-
NGFW Firewalls
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
10-27-2012 11:42 AM
Hello,
Have you check the MTU on the regular RDP using the IPsec tunnel? Fragmentation are known issues when using RDP across IPsec
Mike
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
10-27-2012 12:29 PM
Hello Cybervex3,
This sounds like a fragmentation issue.
Can you do the following on Site A:
crypto ipsec df-bit clear-df outside
Then try to connect, if this does not work change the MTU size manually on the client to a value of 1300
Let us know the result,
Regards,
Senior Network Security and Core Specialist
CCIE #42930, 2xCCNP, JNCIP-SEC
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
10-27-2012 01:36 PM
Ran the command on Site A ASA
Set the MTU on the XP VM and the Machine I am trying to RDP from to 1300. No changes
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
10-27-2012 01:46 PM
Hello,
Please refer to the following documment :
We need to determine if this is a fragmentation issue, follow the Discover Fragmentation section
Julio
Senior Network Security and Core Specialist
CCIE #42930, 2xCCNP, JNCIP-SEC
