RDS 2012 - unable to connect to SH via webgateway

Dear all,
we have setup a RDS 2012 system following this article;
rds8-standard-3-node-remoteapp-deployment-on-windows-server-2012
It all went ok as far is I could see but Im running into the following problem.
If I use MSTSC to connect through the gateway directly things work, I get the desired SH desktop without a problem. (eg connect to SH001.domain.local using the web url for the gateway/webserver).
If I go to the external website and try to setup a connection it goes into somekind of loop. It first gives me a security warning stating it wants to connect to the connection broker, then I get a certificate error from the connection broker, which is correct
in this case, I choose to ignore the certificate warning and continue anyway. RDP then continues; Securing external connection, checking bandwith, starting the external connection. And there it hangs, it doesnt go any further and tries to connect for ever.
The external adres of the gateway is xxx.xxxx.nl and internally it xxx.xxxx.local not sure if this could be related. I noticed an article with a powershell script that would change the .local into .nl
Strange thing it worked before. I even went as far as  trashing all 3 machines, removing the roles and removing them from the domain to run the install again on fresh machines with new DNS names. Still no luck.
Not sure on how to troubleshoot this any further. Eventlogs on the GW and CB show nothing special, no errors. One thing that I do notice is a recurring WMI 5605 ID - The root\cimv2\RDMS namespace is marked with the requiresEncryption flag. Access to this
namespace might be denied if the script or application does not have the appropriate authentication level. Change the authentication level to Pkt_Privacy and run the script or application again.
Thanks for any thoughts on this.
Best regards,
Louis

HI,
Can you confirm everything works internally and your problems occur when trying to access resources externally.
Firstly check the certificates and ensure you have configured self signed or trusted.
Try turning of certificate authentication for testing only - this will answer your authentication level question.
Have a look at the following post:
http://ryanmangansitblog.com/2013/03/10/configuring-rds-2012-certificates-and-sso/
It does sound like you are experencing issues with the Internal and external nameing of the gateway. There are a few ways round this. TP has written a script which will assist with the change.
http://gallery.technet.microsoft.com/Change-published-FQDN-for-2a029b80/file/103829/2/Set-RDPublishedName.ps1 If you have questions
around the use of this, reply in this post.
Ryan Mangan | Ryanmangansitblog.wordpress.com | Help keep the forums tidy, if this has helped please mark it as an answer

Similar Messages

  • Unable to connect to internet via the proxy - Proxy set up OEM 12c

    Windows server 2008 64 bit
    OEM 12.1
    I have to get agent software for Windows server 2003, and as far as I know the only way is through self update in OEM, is this the only way?
    But when I input my Oracle support credentials I get an error :
    Unable to complete network operation against My Oracle Support. Please check network connectivity to Oracle Support Site.
    Proxy settings in EOM are set for https, but not sure about the realm, I input our damain address "company.corp"
    test successful :
    https://updates.oracle.com was tested successfully using the Proxy.
    Go to set oracle support credentials error :
    Unable to complete network operation against My Oracle Support. Please check network connectivity to Oracle Support Site.
    In the emoms.log file :
    2012-07-22 18:28:50,753 [EMUI_18_28_49_/console/admin/rep/proxy/server] ERROR core.patch logp.251 - [EM-01942] Unable to connect to internet via the proxy. Http Proxy - company:80. Destination URL - https://server:proxy/emd/main/. Protocol - https. Error Message - Cannot establish proxy connection: 502 Proxy Error ( The specified Secure Sockets Layer (SSL) port is not allowed. Forefront TMG is not configured to allow SSL requests from this port. Most Web browsers use port 443 for SSL requests.  ).
    java.io.IOException: Cannot establish proxy connection: 502 Proxy Error ( The specified Secure Sockets Layer (SSL) port is not allowed. Forefront TMG is not configured to allow SSL requests from this port. Most Web browsers use port 443 for SSL requests.  )

    Please check the following section in
    http://docs.oracle.com/cd/E24628_01/install.121/e24089/firewalls.htm#EMADV626
    Enabling Oracle Management Service to Access My Oracle Support
    Unless online access to the Internet is strictly forbidden in your environment, Oracle Management Service should be enabled to access My Oracle Support. This access is necessary to enable updates and patches to be downloaded, for example.
    At minimum, the following URLs should be made available through the firewall:
    aru-akam.oracle.com
    ccr.oracle.com
    login.oracle.com
    support.oracle.com
    updates.oracle.com
    About the dontProxyfor Property
    When you configure the Oracle Management Service or a Management Agent to use a proxy server, it is important to understand the purpose of the dontProxyFor property, which identifies specific URL domains for which the proxy will not be used.
    For example, suppose the following were true:
    You have installed the Oracle Management Service and several Management Agents on hosts that are inside the company firewall. These hosts are in the internal .example.com and .example.us.com domains.
    You have installed several additional Management Agents on hosts that are outside the firewall. These hosts are installed in the .example.uk domain.
    You have configured Enterprise Manager to automatically check for critical software patches on My Oracle Support.
    In this scenario, you want the Oracle Management Service to connect directly to the Management Agents inside the firewall without using the proxy server. On the other hand, you want the Oracle Management Service to use the proxy server to contact the Management Agents outside the firewall, as well as the My Oracle Support site, which resides at the following URL:
    http://support.oracle.com
    The following properties will prevent the Oracle Management Service from using the proxy server for connections to the Management Agents inside the firewall. Connections to My Oracle Support and to Management Agents outside the firewall will be routed through the proxy server:
    proxyHost=proxy42.example.com
    proxyHost=80
    dontProxyFor=.example.com, .example.us.com
    PS: Cygwin has nothing to do with My Oracle Support connection. Cygwin is ONLY required for agent deployment using agent push from OMS.

  • HT4623 After ios update on my ipad mini i am unable to connect to internet via cellular connection

    i Have update ios 7.0.2 on my ipad mini. But after update of ios 7.0.2 i am unable to connect to internet via cellulau connection. Cellular connection appears on my screen but i get error as "Could not activate cellular data network you are not subscribed to a cellular data service". Cellular connection was working prior to ios 7.0.2 update. Please help.

    GOT MINE FIXED -
    THE 7.0.3 update reported my iPhone as LOST or STOLEN  to Verizon.
    They suspended my iPhone service immediately (as I would expect them to) and THAT is why I couldn't get on.
    Called Verizon wireless - they restored me in 30 seconds - EVERYTHING WORKS AGAIN.
    They said "we've been doing this ALL MORNING."
    Hope this works for others, too!
    You blow bright orange chunks, Microsoft, er, I mean, Apple.

  • Unable to connect to Internet via Airport Express - 'cannot contact server'

    I'm unable to connect to the internet via my Airport Express. I'm using OS 10.3.9, and had the same setup with no problems at a previous address, but with a different modem from the same ISP.
    My AE is connected - the light is green - and my mac is connected to the network in Internet Connect. But when I open Safari I get an 'unable to contact server' message.
    I've tried rebooting everything (modem, AE, Mac), and leaving modem/AE off for several minutes. Also reset the AE, but to no avail.
    The connection works fine via Ethernet cable.
    Any ideas?

    Thanks, I checked out that advice doc (106798), but could not connect to the address (http://17.149.160.49) which is given to test if it's a DNS issue. My ISP says I shouldn't need DNS settings.
    The service is PPPoE, and I went into Airport Admin Utility to check if the Airport was configured for this. Under Configure/Internet, I found it was set to 'Ethernet', so changed it to PPPoE. Then when I restarted I got connection status in the bar (and good Airport signal), but status flipped between 'looking for PPPoE host' and 'negotiating PPPoE host', sometimes sticking on one or the other each time I tried rebooting all gear.
    Any other ideas?

  • SCVMM 2012: Unable to connect to the VMM management server localhost:8100

    Hi everyone
    I have difficulties connecting with the Admin UI to the SCVMM server running on the same machine. This is the error message I see:
    Unable to connect to the VMM management server localhost. The Virtual Machine Manager service on that server did not respond.
    Verify that Virtual Machine Manager has been installed on the server and that the Virtual Machine Manager service is running.
    Then try to connect again. If the problem persists, restart the Virtual Machine Manager service.
    ID: 1602
    I checked that the service is running and checked with the Resource Monitor that vmmservice.exe is really listening on port 8100. The Resource Monitor also shows some traffic between itself, the service and the DC. But all traffic dies down after a few seconds,
    then nothing happens for a minute, then I get the above error message. The only SCVMM related entry in the eventlog is this (was logged when I manually tried restarting the service):
    Failed to stop service. System.NullReferenceException: Object reference not set to an instance of an object.
    at Microsoft.VirtualManager.Engine.VirtualManagerService.OnStop()
    at System.ServiceProcess.ServiceBase.DeferredStop()
    But I guess that entry is of no help. Other important things that might be relevant:
    This installation worked fine three months ago. Since then only the automatic updates were installed.
    DPM (the 2012 CTP for Win8) is installed on the same server.
    After it didn't work I installed SQL Server 2008 R2 SP1 (offered by Microsoft Update)
    SCVMM is part of a small test installation (~10 VMs or so), no valuable data, so there's no risk when messing around
    Control panel shows the version number 3.1.1042.0 for "Microsoft System Center 2012 Virtual Machine Manager".
    Is there anything else I could try? How can SCVMM stop to work, all by itself? Leaves a sour taste...
    Cheers,
    Simon

    When such odd behaviour occur, it is a good tip to start a VMM trace to see where things are actually going wrong. And suck files is interestin for MS support once the obvious things for errors, are eliminated out of the picture.
    VMM has dependencies such as SQL, permissions and service accounts. All of these variables does
    also have dependencies that should be verified. Verify that the account for the service does is not locked/expired pwd, that the SQL is up and running - and actually is working. There is a lot of logs to check in order to determine the root cause of
    this behaviour.
    -kn
    Kristian (Virtualization and some coffee: http://kristiannese.blogspot.com )

  • Unable to Connect error 948 via SQL

    System Center 2012 DPM trying to connect to a SQL instance on a different server using Windows Authentication. Getting the unable to connect error "Unable to cnnect to xxx.domain.com (ID: 948) Verify that the DPM service is running on this computer",
    I figured out that if you add the user to "sysadmin" in SQL management it works for that user.  My question is, is this the best practices method of solving this problem?  Will this need to be done for every windows user
    that tries to access the DPM, or is there a more proper way?
    Thanks

    can anyone help?

  • Unable to connect to essbase via EAS & unable to create Planning Applicatio

    we have 2 servers in our environment
    Linux - Essbase Server
    Windows - Planning, Reporting, EAS, Essbase client, workspace etc
    when im trying to connect to essbase via EAS, i could not open the page.
    Im also unable to create the Planning application.
    We have installed essbase server on Linux Server and Essbase client and EAS on windows server and have configured these to a oracle 10g server.
    Please give me your suggestions.
    Thanks in Advance
    Rao

    Hi Rao,
    Could you please post the error message?
    Have you checked all previleges that you are using for login through EAS?
    Check with also defaut username admin once.
    Regards
    Venkat G

  • Nokia 3230 unable to connect to internet via USB c...

    when i use CA-53 cable to connect to internet using nokia pc suite7.0.8.2 (one touch access) an error message pops up "unable to connect to the speified device make sure the modem is configured properly" but i can easily connect to internet via bluetooth   other functions like file manager , contacts , messages and back up can be accessed by using the CA-53 cable

    I called a vw dealership (in South Australia) today because I have an iphone5 and a Tiguan and experienced the same thing (after i had purchased the lightening/30pin adapter).
    I was advised that the media interface software is not compatible with iphone5.  VW will eventually update the software according to ol'mate at the dealership, but it will be at an expense to the consumer allegedly.
    I know that there is a iphone/vw media cable one can purchase from VW however, I believe this to only work with iphone4 or older?
    Maybe try an older generation ipod to use for the car if all ur music is in itunes?
    if anyone can correct me, I'd be more than happy to know... going to try my older generation ipad and see if there is any truth to the tale.... eventually.  Until then i'll stream via bluetooth :-)
    Sheree

  • RDS 2012 R2 - open connection in windowed mode?

    We built a new RDS 2012 R2 environment and are publishing a full desktop for use with remote users. The issue we are having is we would like the users to be able to open the connection in a windowed mode. Right now when the users logs onto the RD web access
    server and clicks the collection icon the connection opens full screen across all the monitors the user  has. I see no way to configure this option. Is is possible to have the connection open in a windows VS full screen across every monitor?

    Hi Brock,
    Firstly sorry for delay response.
    You can set RDP setting for RDS Desktopheight & DesktopWidth. Refer this article for more information.
    In addition, you can use mstsc option for editing existing RDC(.rdp) configuration file. Also you can use
    mstsc /span for multiple monitor. Please check below articles for more details.
    1.  Mstsc
    2.  Using Multiple Monitors in Remote Desktop Session
    Hope it helps!
    Thanks,
    Dharmesh

  • Unable to connect to databases via SQLPlus or SQLDeveloper

    Hi,
    Current Setup: Linux Enterprise 5.8 64 bit/ Oracle 11g/ SQL Developer 3.1
    I recently created a new Linux VM from scratch and installed Oracle 11g on it. Was able to successfully create databases via DBCA, how ever am not able to connect to these databases.
    You'll find this very interesting. I recently discovered different scenarios, where it works and does not works.
    Below scenarios are executed in sequence. After Scenario C, I can successfully create connections via SQLPlus and SQLDeveloper
    Scenario A :
    STEP 1) Start Linux Box
    STEP 2) Try to extablish connection via SQLPlus and SQLDeveloper
    SQLPlus Error: ERROR: ORA-12541: TNS:no listener
    SQLDeveloper Error: Network Adaptor could not establish the resource
    Scenario B :
    STEP 1)Run: lsnrctl start
    ==========
    OUTPUT START
    ==========
    [admin@localhost ~]$ lsnrctl start
    LSNRCTL for Linux: Version 11.2.0.1.0 - Production on 10-AUG-2012 23:53:53
    Copyright (c) 1991, 2009, Oracle. All rights reserved.
    Starting /home/admin/app/admin/product/11.2.0/dbhome_1/bin/tnslsnr: please wait...
    TNSLSNR for Linux: Version 11.2.0.1.0 - ProductionSystem parameter file is /home/admin/app/admin/product/11.2.0/dbhome_1/network/admin/listener.oraLog messages written to /home/admin/app/admin/diag/tnslsnr/localhost/listener/alert/log.xmlListening on:
    (DESCRIPTION=(ADDRESS=(PROTOCOL=ipc)(KEY=EXTPROC1521)))Listening on:
    (DESCRIPTION=(ADDRESS=(PROTOCOL=tcp)(HOST=localhost.localdomain)(PORT=1521)))
    Connecting to (DESCRIPTION=(ADDRESS=(PROTOCOL=IPC)(KEY=EXTPROC1521)))STATUS of the LISTENER------------------------
    Alias LISTENERVersion TNSLSNR for Linux: Version 11.2.0.1.0 - ProductionStart Date 10-AUG-2012 23:53:56Uptime 0 days 0 hr. 0 min. 2 secTrace Level offSecurity ON: Local OS AuthenticationSNMP OFFListener Parameter File /home/admin/app/admin/product/11.2.0/dbhome_1/network/admin/listener.oraListener
    Log File /home/admin/app/admin/diag/tnslsnr/localhost/listener/alert/log.xmlListening Endpoints Summary...
    (DESCRIPTION=(ADDRESS=(PROTOCOL=ipc)(KEY=EXTPROC1521))) (DESCRIPTION=(ADDRESS=(PROTOCOL=tcp)(HOST=localhost.localdomain)(PORT=1521)))The listener supports no servicesThe command completed successfully[admin@localhost ~]$
    =========
    OUTPUT END
    =========
    STEP 2) Try to extablish connection via SQLPlus and SQLDeveloper
    SQLPlus Error: ORA-12514: TNS:listener does not currently know of service requested in connect descriptor
    SQLDeveloper Error: TNS: listner does not currently know of SID given in connect descriptor
    Scenario C :
    STEP 1) Open DBCA > Configure all database one by one database > Go to till STEP 3 of DBCA configuration wizard
    STEP 2) Close DBCA
    STEP 3)Run: lsnrctl status
    ==========
    OUTPUT START
    ==========
    [admin@localhost ~]$ lsnrctl status
    LSNRCTL for Linux: Version 11.2.0.1.0 - Production on 11-AUG-2012 12:04:11
    Copyright (c) 1991, 2009, Oracle. All rights reserved.
    Connecting to (DESCRIPTION=(ADDRESS=(PROTOCOL=IPC)(KEY=EXTPROC1521)))
    STATUS of the LISTENER
    Alias LISTENER
    Version TNSLSNR for Linux: Version 11.2.0.1.0 - Production
    Start Date 11-AUG-2012 11:48:51
    Uptime 0 days 0 hr. 15 min. 19 sec
    Trace Level off
    Security ON: Local OS Authentication
    SNMP OFF
    Listener Parameter File /home/admin/app/admin/product/11.2.0/dbhome_1/network/admin/listener.ora
    Listener Log File /home/admin/app/admin/diag/tnslsnr/localhost/listener/alert/log.xml
    Listening Endpoints Summary...
    (DESCRIPTION=(ADDRESS=(PROTOCOL=ipc)(KEY=EXTPROC1521)))
    (DESCRIPTION=(ADDRESS=(PROTOCOL=tcp)(HOST=localhost.localdomain)(PORT=1521)))
    Services Summary...
    Service "agent" has 1 instance(s).
    Instance "agent", status READY, has 1 handler(s) for this service...
    Service "agentXDB" has 1 instance(s).
    Instance "agent", status READY, has 1 handler(s) for this service...
    Service "orcl.localdomain" has 1 instance(s).
    Instance "orcl", status READY, has 1 handler(s) for this service...
    Service "orclXDB.localdomain" has 1 instance(s).
    Instance "orcl", status READY, has 1 handler(s) for this service...
    Service "productionXDB" has 1 instance(s).
    Instance "production", status READY, has 1 handler(s) for this service...
    Service "production_core" has 1 instance(s).
    Instance "production", status READY, has 1 handler(s) for this service...
    Service "publishing" has 1 instance(s).
    Instance "publishing", status READY, has 1 handler(s) for this service...
    Service "publishingXDB" has 1 instance(s).
    Instance "publishing", status READY, has 1 handler(s) for this service...
    Service "switchinga" has 1 instance(s).
    Instance "switchinga", status READY, has 1 handler(s) for this service...
    Service "switchingaXDB" has 1 instance(s).
    Instance "switchinga", status READY, has 1 handler(s) for this service...
    Service "switchingb" has 1 instance(s).
    Instance "switchingb", status READY, has 1 handler(s) for this service...
    Service "switchingbXDB" has 1 instance(s).
    Instance "switchingb", status READY, has 1 handler(s) for this service...
    The command completed successfully
    [admin@localhost ~]$
    ==========
    OUTPUT END
    ==========
    What can I do to connect to databases and not start dbca and configure each database on system start?
    Any help would be highly appreciated.
    Cheers,
    Sandeep
    Edited by: Sandeep.R on Aug 11, 2012 12:06 PM

    You need a service to auto start/stop instances. Pls See
    Re: Oracle instance is going to idle when i restart/start the machineRgds,
    Ahmer

  • Unable to connect to mail via iCloud from iPhone or macbook air

    error message from iPhone when trying to access mail "The connection to the server failed" any solutions?

    For now....wait.
    From the Apple Support Page, http://www.apple.com/support/icloud/systemstatus/ 
    iCloud: Mail & Notes - Users Affected: <1%
    01/08/2012 09:43 PST
    Users may be unable to access Mail. Service is expected to be restored by 8pm PST today. All messages will be delivered at that time.

  • Unable to connect to SRW224P via web base and serial port on the front until reboot switch

    Just installed new SRW224P switch 4 days ago and we lose connectivy to the SRW224P manage switch. Try to Web in to device and also direct serial port unable to get connected, reboot and it works for a little bit but then we loose connectivity again. Also the computers connected to the switch loose their IP address and sometimes unable to get a DHCP address assigned back from are server.
    Any suggestions?
    (Edited for guideline compliance.Thanks!)Message Edited by JOHNDOE_06 on 05-14-2007 09:20 AM

    I ended up doing a replacement with linksys, the new one has been in place for 2 weeks and it seems to be running ok.

  • Unable to connect to internet via wifi

    I have had this problem ever since I received my preordered Dinc.  I can successfully connect to the internet via wifi anywhere but at my place of employment (very frustrating).  The Dinc sees and connects to the wifi but when I open the browser the following pop up window appears:
    “Security warning
    There are problems with the security certificate for this site.
    This certificate is not from a trusted authority”
    I then have a choice to continue, view certificate, or cancel.  When I view the certificate it states the organization, The Go Daddy Group Inc, unit, Go Daddy Class 2 Certification Authority and validity:
    VZ tech support stated that they never heard of it and recommended that I call HTC. 
    HTC said that this is a common problem and that Go Daddy uses a variable wild card for their SSL.  The conversation ended when they said that there is nothing that can be done.
    I finally contacted Go Daddy who said that they need the account number without that there is nothing that they can do.
    Laptops, Iphones, and other cell phones can get on the internet.
    My questions to this board are:
    Has anyone else had this issue?
    Does anyone know of a fix?
    Who is responsible for the fix VZ or HTC?
    Do you think that when (ever) the OTA update to Froyo will fix this?
    Thanks to all

    I'd talk to your IT dept at work.

  • Nokia PC software unable to connect to E5 via Blue...

    Hi.  I have a Nokia E5 with fully up to date software on it.  I have succesfully paired it with my HP Pavilion dv6 laptop running Windows 7 Home Premium, again, fully up to date.
    I can connect via the usb cable and transfer/backup data from my phone.  Ok, so far so good.  I tried to do this via Bluetooth.  I have the phone paired with the laptop, I can see it if I go into Bluetooth connections and devices and the phone is there with a tick by it.  Bluetooth is turned on at the phone I have checked.  I can explore the phone from the Windows Bluetooth page on the laptop.  I try to connect via the Nokia PC Suite but the option to connect via Bluetooth is not available?  The text is there but no link, it is greyed out.
    So, any ideas why?  Is this a Nokia PC suite problem or a Windows one?
    Thank you.

    Just to add to this.  When I go to the connection page (with the picture of the phone and cable etc in the background) I have tried to click on what should be a link 'Use bluetooth instead' with the bluetooth symbol right next to it.  Trouble is the link does not..... link.  It remains grey and no amount of clicking on it does anything.
    I have checked in the Windows bluetooth software and the device is 'paired', or it says it is and as stated before, I can transfer files with the Windows Explorer software.
    One other thing I have noticed, my contacts got mixed up (address fields in the wrong order) when I synced using USB.  Could the software be flawed?  I have tried the repair route by the way.

  • Unable to connect to internet via Airport (wirelessly)

    I have 2 Macbooks at my house. One can connect to a password protected wireless connection just fine, the other is unable to. I have Mac OS X 10.5.8 and 10.4.(something) on the other.
    When I enter in the WEP code and try to connect to the server, it says that I am unable to. I am 100% positive that the password is correct.
    I have tried deleting my preferred networks and my keychain passwords for networks and nothing has worked.
    Thanks you

    The computer was allowed to connect before, and has until about a day ago.
    I'm not sure what kind of password it is, but I cannot change any of the settings just to put that out there.
    I have tried both the Airport icon, and through internet connect. no luck either way.
    Not sure about what the router is in, but it should be accessible since it was before and other computers and iPhones can connect to it just fine.

Maybe you are looking for