Hi,
I've an e200 fortinet running version 5.6.2.
In my net there are several windows 2016 servers witch programmers access them via rdp, previously, they open an ssl-vpn connection. In some cases, everythings work fine, but some programers have troubles to open RDP "your credentias didn't work" but they are correct. When I check the event viewer for rdp , there is no register for the fail connection.
To bypass the issue I opened RDP to the wan, so the programers connects directly using the public ip address (is dangerous, I'm aware).
I guess that there is a mismatch between the rdp client and the vpn.
Any help w'll be appreciate.
Tnx
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
My advice is to use IPsec VPN, using the same FortiVPN client. No problems whatsoever.
On my ipsec-vpn with FGT-111C and FWF-60E, noticed vncviewer got unresponsive once in a while (e.g., no tcp reply from wireshark).
Adding the following setting to each of the FGTs fixed the issue:
config system session-ttl config port edit 5900 set protocol 6 set timeout never set start-port 5900 set end-port 5900 next end end
This is due to FGTs maintain security & protocol states for each session (user logged-on, policy id, app id, etc.). For the vncviewer over ipsec-vpn, there are 2 sessions maintained: vpn session in UDP, then tunnelled vncviewer session in TCP. If desktop has screensaver, the vncviewer traffic would become inactive and session may expire and deleted in the FGT. This result to future tcp traffic disrupted. Can see session info in 'diag sys session list'.
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1714 | |
1093 | |
752 | |
447 | |
232 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.