Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
scerazy
New Contributor III

HTML5 RDP Windows 10/Server 2016 Connection Terminated

I can fill credentials (username/password), but all I get is error that connection is terminated

 

Anybody any ideas?

 

Connection to Server 2012 R2/W7/W8.x works fine from web VPN

15 REPLIES 15
MattM
New Contributor

I had this issue when the Network Level Authentication settings didn't match between the server and the HTML5 RDP connection.  On Windows I set RDP security to "Allow connections from computers running any version of Remote Desktop (less secure)" and set the HTML5 RDP shortcut to use Standard RDP Encryption.

That allowed me to connect.

 

scerazy
New Contributor III

Network Level Authentication for Remote Desktop Services Connections is already turned OFF!

That is the first thing I did check!

 

The settings (wording used) you mentioned is for Windows Vista/7/2008

 

For Windows 8/8.1/2012/10/2016 it is (untick):

 

Allow remote connections only from computers running Remote Desktop with Network Level Authentication (recommended)

 

as per: http://www.lazywinadmin.com/2014/04/powershell-getset-network-level.html

 

While it works fine connecting to Server 2012 R2, it does NOT connect to Windows 10/Server 2016

 

Seb

 

 

abeggled

Connection to Windows 10/Server 2016 works for me with the following configuration:

 

Windows:

[ul]
  • NLA activated[/ul]

    Bookmark:

    [ul]
  • Host: xxx.xxx.xxx.xxx (only IP-Adress works for me)
  • Username: leave empty
  • Password: leave empty
  • Security: Allow the server to choose the type of security[/ul]

     

    Drawback: You loose SSO

     

  • scerazy
    New Contributor III

    Allow the server to choose the type of security was the culprit, thanks

     

    But it does NOT work from Bookmark, it DOES work only from Quickconnect

     

    If IP only works for you then you have issue with dns/default domain on FTG

     

    For me FQDN resolves & works fine

     

    Seb

     

    scerazy
    New Contributor III

    Works fine with Server 2016 as well

    bhwong
    New Contributor

    Under Security for RDP, you have to select Network Level Authentication and enter your username to be saved. I didn't tick the recommended NLA in Windows Server 2016 as well, but it will only connect when security is set to NLA.

    Cohmert
    New Contributor

    Hello, i have the same issue.

    I could solve it but i am not satisfied.

    The problem with connecting only affects win10 clients. I have serveral clients where the connection settings are set to:

    [ul]
  • Type:rdp
  • Host: hostename or IP - both works
  • Port: 3389
  • Username: mydomain\
  • Passwort: empty
  • Keyboardlayout: German
  • Security: Standard RDP encription[/ul]

    But somehow, on a few clients it just wont work. When the user tries to connect, the user will get displayed "connection closed" immediately.

     

    I tried to set it to NLA with the same result. All win10 clients have the NLA box unchecked in the remote connection settings.

     

    Then i found out, that when i use the QuickConnection button and set it all to RDP with NLA and leave the credentials empty, i could connect to the client. The NLA box ist still unchecked and should work without it

    (As long the user is allowed and member in the Remotedesktop user group on the client)

     

    [ul]
  • The i changed the Portal settings to NLA and left the user/password section empty. No success
  • The i changed the Portal settings to NLA and filled in the name of one of the allowed users without the mydomain\ part. Only the username. Password still empty. Works[/ul]

    The NLA boxes are unchecked on all clients. All clients on same Patchlevel and winver.

     

    Does anybody has a sugesstion why it is different on the clients and why some need the NLA, even if it is deactivated on the client.

     

     

     

     

  • thomasevig

    Cohmert wrote:

    Hello, i have the same issue.

    I could solve it but i am not satisfied.

    The problem with connecting only affects win10 clients. I have serveral clients where the connection settings are set to:

    [ul]
  • Type:rdp
  • Host: hostename or IP - both works
  • Port: 3389
  • Username: mydomain\
  • Passwort: empty
  • Keyboardlayout: German
  • Security: Standard RDP encription[/ul]

    But somehow, on a few clients it just wont work. When the user tries to connect, the user will get displayed "connection closed" immediately.

     

    I tried to set it to NLA with the same result. All win10 clients have the NLA box unchecked in the remote connection settings.

     

    Then i found out, that when i use the QuickConnection button and set it all to RDP with NLA and leave the credentials empty, i could connect to the client. The NLA box ist still unchecked and should work without it

    (As long the user is allowed and member in the Remotedesktop user group on the client)

     

    [ul]
  • The i changed the Portal settings to NLA and left the user/password section empty. No success
  • The i changed the Portal settings to NLA and filled in the name of one of the allowed users without the mydomain\ part. Only the username. Password still empty. Works[/ul]

    The NLA boxes are unchecked on all clients. All clients on same Patchlevel and winver.

     

    Does anybody has a sugesstion why it is different on the clients and why some need the NLA, even if it is deactivated on the client.

     

     

     

     

  • thank you so much!!!

    i've been searching for this for so long , my client couldn't work with

    ForticLient , therefore had to solve this somehow!!

     

     

    I'm very thankful

    rcslab
    New Contributor

    this method stills work with Windows 10 build 18363

     

    Cohmert wrote:

    Hello, i have the same issue.

    I could solve it but i am not satisfied.

    The problem with connecting only affects win10 clients. I have serveral clients where the connection settings are set to:

    [ul]
  • Type:rdp
  • Host: hostename or IP - both works
  • Port: 3389
  • Username: mydomain\
  • Passwort: empty
  • Keyboardlayout: German
  • Security: Standard RDP encription[/ul]

    But somehow, on a few clients it just wont work. When the user tries to connect, the user will get displayed "connection closed" immediately.

     

    I tried to set it to NLA with the same result. All win10 clients have the NLA box unchecked in the remote connection settings.

     

    Then i found out, that when i use the QuickConnection button and set it all to RDP with NLA and leave the credentials empty, i could connect to the client. The NLA box ist still unchecked and should work without it

    (As long the user is allowed and member in the Remotedesktop user group on the client)

     

    [ul]
  • The i changed the Portal settings to NLA and left the user/password section empty. No success
  • The i changed the Portal settings to NLA and filled in the name of one of the allowed users without the mydomain\ part. Only the username. Password still empty. Works[/ul]

    The NLA boxes are unchecked on all clients. All clients on same Patchlevel and winver.

     

    Does anybody has a sugesstion why it is different on the clients and why some need the NLA, even if it is deactivated on the client.

     

     

     

     

  • Announcements

    Select Forum Responses to become Knowledge Articles!

    Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

    Labels
    Top Kudoed Authors