Remote Desktop 2012 R2 - Can't get RD Gateway with RD Web Access working through just 443

I have one server (2012 r2 fully updated) running all remote desktop roles (RD Web Access, RD Gateway, RD Licensing, RD Connection Broker, RD Session Host) and a separate domain controller.
I have RD Web Access published to cloud.mydomain.co.uk and accessing cloud.mydomain.co.uk/RDWeb works fine.
I want to setup the environment so only port 443 is open from the outside (thus the RD Gateway is installed) and the user can login through RDWeb and click on an app to launch it.
If I leave port 3389 open along with 443 and log on to RDWeb and click the remote app, this works fine.
If I close 3389 on the external firewall and only leave open 443, I can connect AND login to RDWeb but I cannot open the connection
This is expected:
http://i.imgur.com/9j2HRqm.png
Error:
http://i.imgur.com/2LH2c7T.png
Digging in the event viewer yielded: http://i.imgur.com/M9uHm0o.png
Which led me to test change the following setting in the resource access policy, as a test:
http://i.imgur.com/FlGObFr.png
This still didn't work but yielded a different error in event viewer:
http://i.imgur.com/LkaCfU4.png
Now I suspect I have misconfigured something somewhere in terms of the last event where it suggests it can't connect to resource "cloud.mydomain.co.uk" I would have expected this to be the internal FQDN of my session host. Or, I am hitting some sort
of odd problem because I have all the roles on the same box.
Any assistance greatly appreciated. I'm keen to find the root cause behind this as I need to document this solution so don't want to invalidate by messing around too much with settings.

Hi Gavin,
If you use RD Gateway then you only need to open TCP port 443 and UDP port 3391 and forward them to your RD Gateway server.  You may have RD Web Access (uses TCP port 443) and RDG running on the same server.
When an external client launches a RemoteApp they will connect to your RD Gateway via TCP port 443 and UDP port 3391, then the RDG will connect to your internal RDSH servers using TCP port 3389 and UDP port 3389 on behalf of the external client.  In
this way the RDG will act as a middleman between your external users and your internal RDSH servers.
In Server Manager - Remote Desktop Services - Overview - Tasks - Deployment Properties you need to specify the external FQDN of your RD Gateway server.  If you have RDWeb and RDG on the same server this would be the same FQDN that your users will use
for RDWeb.  For example, if your users use https://rds1.yourdomain.com/rdweb to connect to your RD Web Access site, then you would enter rds1.yourdomain.com for the RD Gateway name in deployment properties.
(Above one Quoted from this thread answered by TP).
In addition please see that you have properly configured RD Rap & RD Rap policy under RD Gateway manager and also properly configured certificates to match server name.
Hope it helps!
Thanks.
Dharmesh Solanki
Please remember to mark the replies as answers if they help and unmark them if they provide no help. If you have feedback for TechNet Support, contact [email protected]

Similar Messages

  • Remote Desktop update has caused me to no longer be able to access work using Citrix/CAG.  IT found my access to be intact on their end.  What can I do?

    How can I get access to my work after the Remote Desktop Update 3.8.2 blocked my access through Citrix/CAG?

    Can you start Firefox in [[Safe mode]] ?
    You can also do a clean reinstall and download a fresh Firefox copy from http://www.mozilla.com/firefox/all.html and save the file to the desktop.
    Uninstall your current Firefox version and remove the Firefox program folder before installing that copy of the Firefox installer.
    It is important to delete the Firefox program folder to remove all the files and make sure that there are no problems with files that were leftover after uninstalling.
    You can initially skip the step to create a new profile, that may not necessary for this issue.
    See http://kb.mozillazine.org/Standard_diagnostic_-_Firefox#Clean_reinstall

  • I had to buy a new computer and now can't get my CS3 with CS5 upgrade to work on windows 8.1. What can I do to get them to load and work?

    I can load CS3, but it won't let me register it and I can load CS5 upgrade, but when I open CS5 it shows fault and closes. What can I do to get these programs to work on my new computer?

    Registration has always been optional, so there is no point in trying. Those pages on the Adobe site are long gone. CS5 crashing is another matter, but without some crash logs and more detailed system information nobody can realyl know. This could be a mundane permissions issue on some files, could be a crash with the hardware acceleration stuff but just the same could be the activation system failing. Impossible to tell based on your limited information.
    Mylenium

  • HT201068 In the Ap Store "Updates" window, it says that "Remote Desktop Client Update" was installed today.  I never intentionally installed "Remote Desktop".  How did it get there, Where is it on my computer, and How can I remove it?  Thank You!

    In the Ap Store "Updates" window, it says that "Remote Desktop Client Update" was installed today.  I never intentionally installed "Remote Desktop".  How did it get there, Where is it on my computer, and How can I remove it?  Thank You!

    I don't know if you have been there, but a very suspicious icon!  (Like this one on a NSA satellite: http://b-i.forbesimg.com/kashmirhill/files/2013/12/Satellite-logo-for-spying.jpg)  Yikes!
    Are they after the French too?!?  I thought we were allies?!?  Wait a minute . . . I'm an American citizen with the Constitutional Right (which they vowed to uphold when they took their job!) of privacy!!!
    What do you think of all this?
    How did you find it in the OS?
    Do I just trash it with "Secure Empty"?

  • I have a text window open that displays every move I make on the desktop and I can't get rid of it. Help!

    My grandson was playing with my mouse and keyboard and did something so that now I have a text window open that displays every move I make on the desktop and I can't get rid of it. Help! The window continuously tells me where I am, etc.

    Go to System Preferences > Universal Access > Seeing Tab > Turn VoiceOver off.
    Or  CMD FN F5
    Captfred

  • When I click on Safari Icon it opens,but under the desktop picture.How can I get it on top of it?

    When I click on Safari Icon it opens,but under the Desktop picture.How can I get it on top,so I could see it?

    I would open a guest account and see if the problem persist in this new enviroment.
    Boot into Safe Boot Mode and see if the problem is present,  this turns off third party plug-in's and extentions.
    This will give us something to go on and recommend the next step.

  • Remote Desktop Connection Manager can't stop Reconnecting

    I use RDCM in different customer sites to connect to their Windows Server 2008/2008 R2 servers.  Typically the server on which RDCM is running on is Windows Server 2008 Standard SP2 (64-bit).  In some sites, when I disconnect from a server, instead
    of completely disconnecting, the session turns gray and a "Reconnecting" window pops up:
    Pressing the Cancel button simply grays out the button and I can never actually disconnect until I exit RDCM and restart it.  "Disconnect group" doesn't help either.  It seems like the problem occurs always in some sites and never in
    others.
    Is there a fix for this annoying problem?
    David Collacott

    Hi David,
    The RDS feature is also available on Server 2008 but just the name is different, on server 2008 it’s called Terminal Server. So you can able to find the option “Set time limit for disconnected sessions” or the
    session is active then you can choose the option “Set time limit for active Terminal Services sessions
    “under below mention path.
    User Configuration\Policies\Administrative Templates\Windows Components\Terminal Services\Terminal Server\Session Time Limits
    Please refer “Session Time Limits” for more guidance. In addition you can refer below article for Remote Desktop disconnection issue with server 2008.
    Remote Desktop disconnected or can’t connect to remote computer or Remote Desktop server (Terminal Server) that is running Windows Server 2008
    http://support.microsoft.com/kb/2477133
    Hope it helps!
    Thanks.

  • Hello - can anyone tell me why my iPad (4th Gen) screen will no longer rotate. I don't have a screen lock symbol next to the battery icon. I have the rotate icon on my desktop but still can't get the screen to rotate.

    Hello - can anyone tell me why my iPad (4th Gen) screen will no longer rotate. I don't have a screen lock symbol next to the battery icon. I have the rotate icon on my desktop but still can't get the screen to rotate.

    Double-click the Home button and swipe Task Bar to the right. Check the Rotation Lock on the far left of Task Bar.
    http://i1224.photobucket.com/albums/ee374/Diavonex/ba23c598623fe4fd062a40e349af2 18d.jpg

  • CAS and three primary hierarchy SCCM 2012 r2 can i get any runbook from microsoft for Step by step installation

    Hi All
    need CAS and three primary hierarchy SCCM 2012 r2 can i get any runbook from microsoft for Step by step installation
    need step by step installation guide with screenshots.

    There's a lots of installation guide but each guide is for a "standard" installation, your environment is unique and you should get help to be sure to implement SCCM to fulfill your needs.
    Installing SCCM without any experience will be tricky and maintain it will be even harder. This is not a simple product.
    http://sccmentor.wordpress.com/2014/01/08/sccm-2012-r2-step-by-step-installation-guide/
    http://www.windows-noob.com/forums/index.php?/topic/4045-system-center-2012-configuration-manager-step-by-step-guides/
    Benoit Lecours | Blog: System Center Dudes

  • Remote Desktop Virtualization Host failed to get redirection authentication information from the virtual machine

    Hello,
    When implementing a VDI solution, I'm getting an error on our virtualization host server.  The error is:
    Remote Desktop Virtualization Host failed to get redirection authentication information from the virtual machine [VDI-PC].
    Hresult 0x8000FFFF
    Event ID 8467, Severity: Warning, Source: Microsoft-Windows-TerminalServices\TSV\VmHostAgent
    This error happens every time a user or admin connects to a VDI desktop.  This is a fresh install of Remote Desktop Services on completely fresh servers.  This is in testing and we have not ever had it working before without the error.
    Topolgy: Server2012 R2, Windows 7
    Srv-RDCB1: Is the connection broker and Web Access server.  It is Virtualized thru Hyper=V.
    Srv-RDVH1: Is the virtualization host.  It is a physical server. It also has a separated hyper-v role (for RDS VDI deployment).
    Everything seems to be functional other than this error in the log, and I haven't found any information on what this could mean.
    Any help is greatly appreciated, thanks!

    Hello. I have this trouble too.
    All roles on one server.
    Deployment type - Quick start
    Deployment Scenario Virtual mashine-based desktop deplyment
    Reinstall all roles 2 times
    Warning TerminalServices-TSV-VmHostAgent
    8467 Orchestration
    Remote Desktop Virtualization Host failed to get redirection authentication information from the virtual machine [per-0] . 
    Hresult: 0x8000FFFF
    <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="Microsoft-Windows-TerminalServices-TSV-VmHostAgent" Guid="{92618A87-2F6A-4B75-9AE2-E77BE7EAF43C}"
    />
      <EventID>8467</EventID>
      <Version>0</Version>
      <Level>3</Level>
      <Task>22</Task>
      <Opcode>14</Opcode>
      <Keywords>0x4000000000000000</Keywords>
      <TimeCreated
    SystemTime="2014-11-11T13:24:45.579138000Z" />
      <EventRecordID>1655</EventRecordID>
      <Correlation
    ActivityID="{F4200EF7-FEDD-4CAD-9F5D-6219A5F30000}" />
      <Execution ProcessID="3164" ThreadID="13164" />
      <Channel>Microsoft-Windows-TerminalServices-TSV-VmHostAgent/Operational</Channel>
      <Computer>blade2.vzfei.local</Computer>
      <Security UserID="S-1-5-20" />
      </System>
    <UserData>
    <EventXML xmlns="Event_NS">
      <param1>per-0</param1>
      <param2>0x8000ffff</param2>
      </EventXML>
      </UserData>
     </Event>
    In RD Gateway Manager, right-click on the RD RAP and click Properties.  On Network Resources tab select
    “Allow users to connect to any network resource”.
    not work.

  • TS1410 By mistake I disconnected my iPod Classic when it said Do not disconnect. Now it doesn't appear in iTunes, but it does appear on my desktop. How can I get to reappear in iTunes (have tried resetting and rebooting).

    By mistake I disconnected my iPod (5th generation) when it said Do not disconnect. Now it doesn't appear in iTunes, but it does appear on my desktop. How can I get to reappear in iTunes? I have tried resetting and rebooting. And my iTunes is up to date on my macbook pro, mountain lion, OS X 10.8.
    Thank you!

    The iPod's filesystem may be corrupted.  This may seem like overkill, but it has been known to help many others in the same boat.  Try doing a low level reformat of the iPod's hard disk using the instructions in this article.
    http://www.methodshop.com/gadgets/ipodsupport/erase/
    B-rock

  • Can't get display options in FCP 6 to work?

    Hi
    Can't seem to get my canvas to play in Digital Cinema Desktop Preview - Full Screen, or RAW or Main or regular....firstly what are the differences in these and how can I get them to display...nothing happens when I select either of them.
    I've got a MAC PRO 3.0, using latest FCP 6.0.5, editing in a Apple Pro Res HQ seq, HDV footage, 23" apple and a DELL 24" display...can't get any of the VIEW options to work...solution?
    Thanks
    K

    You're right, thanks...now what is RAW and Main all about? I notice no difference between those and Full Screen...

  • Help! Can I sync my Palm Desktop with Outlook Web Access?? I'm using a T5 -- NOT wireless, but cable-synced

    I have spent the last 3+ weeks trying to get my Palm Desktop information to sync with an Outlook Web Access account.
    I have been able to sync my Palm Desktop info with Outlook 2007, and I have been able to acess an Outlook Web Access account through a microsoft exchange server.
    BUT, when I talk with tech support.... I get several conflicting answers.  One tech says it should be easily possible; one says I need to buy another monthly service; one says it is impossible and I should just buy a Blackberry.
    At this point.... I'm not sure I actually care what the answer is, but I would just like a definitive answer....
    I have a Palm Tungsten T5.
    I want to sync that Contact and Calendar information regularly with an Outlook Web Access account so that my colleagues can see and edit my schedule as needed.... then the info would sync BACK to my Palm so that I can have my current schedule with me.
    Can anyone shed some light on this please??
    Thank you!
    Emily Koenig
    Post relates to: Tungsten T5

    The short answer is no.
    The t-5 has the ability to connect to an exchange server but the version of versamail it has would only sync mail and calendar. You would have to have a wifi card to be able to do even that. To do what you would want you would need to upgrade the versamail client (I don't believe Palm has an upgrade for the T-5) and a wifi card.  
    Post relates to: None

  • How can I get my HP Officejet Pro 8100 to work. I had HP  on the phone for over two hours and thought it was fixed. Now it just will not print at all.

    How can I get my HP Officejet Pro 8100 to work.
    I'm using an  iMac (21.5-inch, Late 2013) running Yosemite. I spent hours on the phone with HP who did their best and thought they had solved the problem Now it has stopped printing completely. Just says 'idle' or' connecting to printer' but never does.

    Greetings paulr.paulr,
    Welcome to the Apple Support Communities!
    I understand that you are unable to print from your Mac running Yosemite on your HP Officejet Pro 8100. I know that printer issues can be very frustrating, but I believe the information in the attached article will be able to assist you. I would suggest reading over and systematically working your way through the suggested troubleshooting steps located in the following article. If any issues arise as you work your way through the steps, or if you work your way completely to the end and reset the printing system and the issue continues, please let me know. 
    OS X Yosemite: Printing troubleshooting
    Cheers,
    Joe

  • I can't get some song on my iphone they work off of the computer but they wont show up on my phone they are in the "on my iphone" section but they gray and have a gray dotted circle next to them i have tried every thing I just want them on my phone HELP!

    I can't get some song on my iphone they work off of the computer but they wont show up on my phone they are in the "on my iphone" section but they gray and have a gray dotted circle next to them i have tried every thing I just want them on my phone HELP!!!

    You have posted to the iTunes Match forum, which your question does not seem to be related to. Is your question concerning iTunes Match or syncing with iTunes via USB?

Maybe you are looking for

  • Where should I tell PE 12 to put its working copies on my Mac

    When I initially set up PE on my Mac, I set the following for the working directories: Capture Video : Same as Project Capture Audio : Same as Project Video Previews: Same as Project Audio Previews: Same as Project Media Cache: Custom Disc Encoding:

  • Why SQL2 took much more time than SQL1?

    I run these 2 SQLs sequencely. --- SQL1: It took 245 seconds. create table PORTAL_DAYLOG_100118_bak as select * from PORTAL_DAYLOG_100118; --- SQL2: It took 3105 seconds. create table PORTAL_DAYLOG_100121_bak as select * from PORTAL_DAYLOG_100121; It

  • Genuin Ipad or a fake one

    Hello , My name is  Dan Stan from Prague Czech Republic. I own an white colour  mini Ipad 16 gb,wifi only,that was sold in apple store  from Taiwan.It is an MD531TA\A, A1432 model,serial number F4*******196. The Ipad is still in warranty till august

  • Will I get an alert/notification on my iphone when i first log into icloud control panel on my PC

    Will I get an alert/notification on my iphone when i first log into icloud control panel on my PC

  • Make an embedded 5.1 QT

    I have a prores movie in FCP. I've mixed a 5.1 soundtrack in soundtrack pro and imported the discreet tracks back to FCP. Now I'd like to make a H.264 movie that will play from Plex (which I guess is the same as saying play from Quicktime?) as a movi