cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
2991
Views
0
Helpful
7
Replies

RDP not working across IPSEC + GRE

ahmad82pkn
Level 3
Level 3

Hi,

i am having hard time connecting RDP to a machine.

Scenario is from Home user connect easy VPN (built on VPN concentrator) after VPN then can RDP company servers in Data Center "A"  fine.

Problem accurs when they need to access a 3rd party "B" server which is connected with our data center "A" via GRE tunnel over internet.

i tried MTU 1436 and 1460 and no MTU as well.

but it didnt work. attach is capture and diagram.

7 Replies 7

andrew.prince
Level 10
Level 10

check the routing from the remote 3rd party.

Sent from Cisco Technical Support iPad App

i can ping the server. so routing should be correct. Also attaching Good capture, when i can RDP same server with out VPN from LAN of office A.

Hello,

     Make sure that the connection to the server is fine. You may try using "telnet" with tcp/3389. If you got a black screen ,you may try to add "ip tcp adjust-mss 1300" on the interfaces for testing.

HTH,

Toshi

i tried chaning TCP adjust value to 1300 on GRE tunnel both side of rotuers, i can connect to 3rd party server via RDP from LAN in office A as before.

But i still cannot connect when i come via VPN. also when i am on vpn i cannot telnet port 3389

telnet 10.20.154.85 3389   (telnet works from office LAN though)

Connecting To 10.20.154.85...Could not open connection to the host, on port 3389

: Connect failed

Hello,

     When you're on VPN, you need to make sure that the routing is fine. If the routing is okay, you should telnet w/3389 without any problem. You might try to double-check w/ personal firewall on the server as well.

Toshi

Yes, when i am on VPN, routing is fine, i can telnet router and switch placed in 3rd office on same LAN 10.20.154.x.

only thing i cannot do is RDP to that server.

That server and my machine both has firewall off. and yes that is the issue telnet to 3389 doesnt work:(

Hi,

    When you're on VPN, you can ping the server. Right?

    When you're on VPN, you can connect the server with other protocol such as file sharing/tcp/445. Right?

    Is there any firewall in between?

Toshi