• Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login
Netgate Discussion Forum
  • Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login

RDP connection to Windows Server outside the network

Scheduled Pinned Locked Moved NAT
9 Posts 3 Posters 1.6k Views
Loading More Posts
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • G
    glennyboy
    last edited by May 21, 2015, 1:35 AM

    Good day.

    Cant connect to Windows server 2008 using RDP outside the network. I can connect to windows server thru LAN using RDP.

    But i can connect to windows 7 using RDP outside the network.

    I already setup port forwarding and uncheck "Block private networks" - "Block logon networks"

    Thank you.

    1 Reply Last reply Reply Quote 0
    • D
      doktornotor Banned
      last edited by May 21, 2015, 7:23 AM

      Works just fine. Without posting screenshots of your NAT/firewall rules, you can try a crystall ball. Also kindly disable the firewall on the W2008 server before any testing.

      1 Reply Last reply Reply Quote 0
      • D
        doktornotor Banned
        last edited by May 21, 2015, 7:41 AM

        1/ How on earth do you imagine me to figure out which one out of those does not work?
        2/ What's that advanced stuff all over the LAN?

        1 Reply Last reply Reply Quote 0
        • G
          glennyboy
          last edited by May 21, 2015, 8:13 AM

          sir doktornotor,

          all the MS RDP of terminal server and sql server (windows server) rules and nat does not work if try to access it outside the network. but if if the client is windows 7 i can access it outside the network.

          I can access it all the MS RDP inside the network.

          the advanced stuff is traffic shaper.

          thank you.

          1 Reply Last reply Reply Quote 0
          • D
            doktornotor Banned
            last edited by May 21, 2015, 8:41 AM May 21, 2015, 8:35 AM

            I definitely won't debug your SQL server mess. (Reading some MS docs would help there.)

            Regardless I cannot see any rule permitting outgoing traffic from LAN for any of those machines. Neither PayrollServer, nor TerminalServer, not even SQLServer alias has any outbound rules permitting traffic to go out from LAN. How exactly should that work goes beyond me. Not exactly surprised you can only work with those on LAN – since that traffic does not go through the firewall at all.

            On a generic note, having two zillions of nondescriptive aliases and duplicating rules on a per-machine basis/per-port basis certainly does NOT aid debugging. You are using aliases in places where it absolutely does NOT help (look at your LAN rules... is that one alias per IP or what?!), and avoid them in places where they'd extremely benefit the setup (like, the SQL server mess -- you did not notice that you can use aliases for ports, or... ???)

            1 Reply Last reply Reply Quote 0
            • G
              glennyboy
              last edited by May 21, 2015, 8:47 AM May 21, 2015, 8:44 AM

              sir doktornotor,

              thank you for the advice regarding port no for sql.  i will change the rules.

              i add rules under WAN

              Proto:              IPV4 / Any
              Source:            Lan Net
              Port:                Any
              Destination:    Any
              Port:              Any

              i tested it a while ago and i successfully connected to terminal server outside the network, but the rules that i add is it safe?

              thank you.

              1 Reply Last reply Reply Quote 0
              • D
                doktornotor Banned
                last edited by May 21, 2015, 8:49 AM

                A WAN rule does not apply at all for traffic coming from LAN. Will never get hit by anything legit. Kindly read the articles linked below:

                https://doc.pfsense.org/index.php/Firewall_Rule_Troubleshooting
                https://doc.pfsense.org/index.php/Port_Forward_Troubleshooting

                1 Reply Last reply Reply Quote 0
                • G
                  glennyboy
                  last edited by May 21, 2015, 8:51 AM

                  sir doktornotor, thank you for your help.

                  1 Reply Last reply Reply Quote 0
                  • F
                    firewalluser
                    last edited by Jun 4, 2015, 8:33 AM

                    Do you need to RDP to multiple lan windows boxes behind the fw?

                    If you do, then on pfsense have different ports open on pfsense with a portforward rule which goes to the LAN ip address and the RDP port

                    Then internet side use in the RDP client
                    IPaddress:Port1  where port1 portforwards to your server RDP port
                    IPaddress:Port2  where port2 portforwards to your sql box RDP port.

                    You can also change the default port the RDP server listens to on the window box, by tweaking the reg settings as well if you like accessing mutiple windows boxes from inside the lan at the same time.

                    Then provided you can RDP onto the windows box in question from inside the lan, the pfsense portwards should work ok.

                    If you want to hide the fact you have (multiple) port forwards setup for RDP on the internet, setup OpenVPN on another ip address range to get you inside the lan, then change your pfsense portwards from wan to openvpn. The less you expose wan side the better imo.

                    Both work well and gives you a way to have multiple RDP clients open at the same time to multiple window boxes on a lan. Of course having multiple RDP clients open at the same time is also easier if you have multiple monitors as well if you need to work on server(s) and workstation(s) at the same time for testing purposes without having to wait to log in each time or be alt-tabbing between multiple machines.

                    fwiw.

                    Capitalism, currently The World's best Entertainment Control System and YOU cant buy it! But you can buy this, or some of this or some of these

                    Asch Conformity, mainly the blind leading the blind.

                    1 Reply Last reply Reply Quote 0
                    • First post
                      Last post
                    Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.
                      This community forum collects and processes your personal information.
                      consent.not_received