cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1457
Views
0
Helpful
6
Replies

SSL Clientless\Remote Desktop Web Access

Eduard A.
Level 1
Level 1

Hi everyone, hope you are all safe. One server in our inside network is an RDS, this particular server works as expected long as the traffic is originating from the internal network and sites that are part of L2L. Now we wanted this server to be available outside, we included a bookmark of it in the clientless vpn, bookmark is working fine, but RDP to hosts are not. I am confused as to what needs to be done NAT or ACL(?) if so, what service am I going to open 3389 or 443?. Appreciate your help! 

6 Replies 6

Cristian Matei
VIP Alumni
VIP Alumni

Hi,

    

     There is no need to perform NAT, the ASA proxies all connections. Try looking in here for some troubleshooting guidelines, and ensure that the servers allow RDP connections from the IP address of the ASA.

HI,

 

Appreciate your reply. i have attached the rd web access interface that we have. i had bookmarked that one under https:// and it doesnt work. i also tried the link you tried, though i havnt got it to work also, if it work will i see the same page im seeing through https?

 

 

I notice that the article you link is for Microsoft Terminal Services, i thought at first this was different but when i checked microsoft documents its the same, they updated the name of MTS to RDS (remote desktop services). But still I am getting the errors. Just to make it clear, i can get to the ssl vpn homepage, and then there is a bookmark there for the RDS page, this rdp web page is a separate one (although i think its tied on the same outside interface public ip). Any thoughts? TIA! 

Hi,

 

   Have you uploaded the proper RDP plugin on the ASA?

 

Regards,

Cristian Matei.

I am continously googling now but can you link me to that plug in? We have one actually, just in case its not right.

By the way attached is page where we key in for rdp, from what i understand this is a page from Windows IIS Server. This is one work well when you are under the internal network. What are your thoughts? TIA!