Notices
Computer & Technology Related Post here for help and discussion of computing and related technology. Internet, TVs, phones, consoles, computers, tablets and any other gadgets.

can remote desktop into Win2k server but not Win2k3 server

Thread Tools
 
Search this Thread
 
Old 17 October 2007, 02:13 AM
  #1  
spectrum48k
Scooby Regular
Thread Starter
 
spectrum48k's Avatar
 
Join Date: Feb 2006
Posts: 2,519
Likes: 0
Received 0 Likes on 0 Posts
Default can remote desktop into Win2k server but not Win2k3 server

I VPN into the work's LAN from my home office...

I can remote desktop to the domain controller (win2k server)
Problem is, I CANNOT remote desktop to the stand-alone server (Win2k3)

To complicate things, I can remote desktop into the DC, and from there remote desktop into the stand-alone server!

Can someone explain what I need to do to the stand-alone server to allow me to remote desktop straight into it ?

Things I've checked:
1) Remote Desktop users group - it contains the administrator, which is the account I'm trying to log in with via remote desktop.
2) I notice there's no terminal server
3) I notice the stand-alone can't connect to a licencing server
4) There's no routing and remote access setup
Old 17 October 2007, 11:47 AM
  #2  
ChrisB
Moderator
 
ChrisB's Avatar
 
Join Date: Dec 1998
Location: Staffs
Posts: 23,573
Likes: 0
Received 0 Likes on 0 Posts
Default

Can you ping the stand alone server?

If so, have you enabled Remote Desktop? Right Click My Computer, System Properties tab, "Enable RD on this computer"?

Might be different on yours though, I don't have any non-domain W2K3 boxes about.
Old 17 October 2007, 01:08 PM
  #3  
mike1210
Scooby Regular
 
mike1210's Avatar
 
Join Date: Apr 2004
Location: Cardiff
Posts: 1,928
Likes: 0
Received 0 Likes on 0 Posts
Default

only other thing i can think of. Can port 3389 TCP be accessed via Hyper Terminal (run netstat -an) to see if its connected. Is the server on a seperate VLAN with ACL's blocking it?
Old 17 October 2007, 04:07 PM
  #4  
spectrum48k
Scooby Regular
Thread Starter
 
spectrum48k's Avatar
 
Join Date: Feb 2006
Posts: 2,519
Likes: 0
Received 0 Likes on 0 Posts
Default

Originally Posted by mike1210
only other thing i can think of. Can port 3389 TCP be accessed via Hyper Terminal (run netstat -an) to see if its connected. Is the server on a seperate VLAN with ACL's blocking it?
server is on same LAN

netstat -an reports port 3389 CAN be accessed
Old 17 October 2007, 04:09 PM
  #5  
spectrum48k
Scooby Regular
Thread Starter
 
spectrum48k's Avatar
 
Join Date: Feb 2006
Posts: 2,519
Likes: 0
Received 0 Likes on 0 Posts
Default

Originally Posted by ChrisB
Can you ping the stand alone server?
yes

Originally Posted by ChrisB
If so, have you enabled Remote Desktop? Right Click My Computer, System Properties tab, "Enable RD on this computer"?
already enabled - I mentioned above I could remote desktop into this stand-alone server, from the DC

I'm sure a user got deleted accidentally from the terminal services snap-in somewhere?
Old 17 October 2007, 08:58 PM
  #6  
ChrisB
Moderator
 
ChrisB's Avatar
 
Join Date: Dec 1998
Location: Staffs
Posts: 23,573
Likes: 0
Received 0 Likes on 0 Posts
Default

Sorry, missed that bit.

Just to clarify, you can ping the stand-alone remotely through the VPN?

Being able to RDP to the DC, then to stand-alone would suggest it's a routing issue but if you can ping it, it can't be. Hmmm!
Old 18 October 2007, 12:30 AM
  #7  
judgejules
Scooby Regular
 
judgejules's Avatar
 
Join Date: Nov 2000
Posts: 1,227
Likes: 0
Received 0 Likes on 0 Posts
Default

If you telnet x.x.x.x 3389 from a cmd prompt do you get a blank screen or does it hang they say connection failed?

Do you have a cutom IP security policy on the 2k3 box that stops RDC from any IPs othat than your 2k server?
Old 18 October 2007, 12:37 AM
  #8  
spectrum48k
Scooby Regular
Thread Starter
 
spectrum48k's Avatar
 
Join Date: Feb 2006
Posts: 2,519
Likes: 0
Received 0 Likes on 0 Posts
Default

Originally Posted by judgejules
If you telnet x.x.x.x 3389 from a cmd prompt do you get a blank screen or does it hang they say connection failed?
"could not telnet to ..... connection failed"

Originally Posted by judgejules
Do you have a cutom IP security policy on the 2k3 box that stops RDC from any IPs othat than your 2k server?
no

I'm sure "dialuser" got deleted by mistake in one of the terminal services snap-ins. Can anyone confirm if thIs user installed automatically in Win2k3 ?
Old 18 October 2007, 12:38 AM
  #9  
spectrum48k
Scooby Regular
Thread Starter
 
spectrum48k's Avatar
 
Join Date: Feb 2006
Posts: 2,519
Likes: 0
Received 0 Likes on 0 Posts
Default

Originally Posted by ChrisB
Sorry, missed that bit.

Just to clarify, you can ping the stand-alone remotely through the VPN?
yes, definitely.

Originally Posted by ChrisB
Being able to RDP to the DC, then to stand-alone would suggest it's a routing issue but if you can ping it, it can't be. Hmmm!
Old 18 October 2007, 01:16 AM
  #10  
judgejules
Scooby Regular
 
judgejules's Avatar
 
Join Date: Nov 2000
Posts: 1,227
Likes: 0
Received 0 Likes on 0 Posts
Default

Originally Posted by spectrum48k
"could not telnet to ..... connection failed"



no

I'm sure "dialuser" got deleted by mistake in one of the terminal services snap-ins. Can anyone confirm if thIs user installed automatically in Win2k3 ?
Dialuser will have nothing to do with it if you cant even open a telnet port to the waiting RDC port, there is a problem with the networking. Are you able to RDC to the 2k3 box from another machine (other than the 2k box) inside the building? Do you have any other ports open on the 2k3 box that you can test with telnet, like http / ftp ?
Old 18 October 2007, 01:19 AM
  #11  
judgejules
Scooby Regular
 
judgejules's Avatar
 
Join Date: Nov 2000
Posts: 1,227
Likes: 0
Received 0 Likes on 0 Posts
Default

As you can RDC to the 2k machine, its not a problem with the vpn/firewall/router (unless there is a specific rule regarding the 2k3 machine). You've checked that? If you have checked, then its something on the box itself.

In Start->Administrative Tools->Local Security Policy do you have a Traffic Filter entry in the right pane, and is it policy assigned to Yes/No?
Old 18 October 2007, 01:49 AM
  #12  
spectrum48k
Scooby Regular
Thread Starter
 
spectrum48k's Avatar
 
Join Date: Feb 2006
Posts: 2,519
Likes: 0
Received 0 Likes on 0 Posts
Default

Originally Posted by judgejules
As you can RDC to the 2k machine, its not a problem with the vpn/firewall/router (unless there is a specific rule regarding the 2k3 machine). You've checked that? If you have checked, then its something on the box itself.

In Start->Administrative Tools->Local Security Policy do you have a Traffic Filter entry in the right pane, and is it policy assigned to Yes/No?
i'LL CHECK.

I'm pretty sure its a wrong settings on the stand-alone server (win2k3)

Question: Which users by default are in the Remote Desktop Users group ?
Old 18 October 2007, 01:51 AM
  #13  
judgejules
Scooby Regular
 
judgejules's Avatar
 
Join Date: Nov 2000
Posts: 1,227
Likes: 0
Received 0 Likes on 0 Posts
Default

Originally Posted by spectrum48k
i'LL CHECK.

I'm pretty sure its a wrong settings on the stand-alone server (win2k3)

Question: Which users by default are in the Remote Desktop Users group ?
None, from memory administrator is granted rights through policies somewhere.
Old 20 October 2007, 05:34 PM
  #14  
spectrum48k
Scooby Regular
Thread Starter
 
spectrum48k's Avatar
 
Join Date: Feb 2006
Posts: 2,519
Likes: 0
Received 0 Likes on 0 Posts
Default

Problem Solved

After messing around with plenty of things, including updating the SonicWall GlobalVPN client to v4x, I finally got things working when I disabled Windows Firewall/ICS service in the Win2k3 stand-alone server.

I also, deleted and then re-inserted the administrator in the remote desktop users group.

BINGO!! ;-)

Thanks for everyone's comments. You're a great bunch.
Related Topics
Thread
Thread Starter
Forum
Replies
Last Post
KAS35RSTI
Subaru
27
04 November 2021 07:12 PM
Mattybr5@MB Developments
Full Cars Breaking For Spares
38
17 July 2016 10:43 PM
Mattybr5@MB Developments
Full Cars Breaking For Spares
28
28 December 2015 11:07 PM
Mattybr5@MB Developments
Full Cars Breaking For Spares
12
18 November 2015 07:03 AM
Nick_Cat
Computer & Technology Related
2
26 September 2015 08:00 AM



Quick Reply: can remote desktop into Win2k server but not Win2k3 server



All times are GMT +1. The time now is 08:30 AM.