republican-creole
Search:  

 
 
   All ForumsHot TopicsGallery






how-to block ads


 
Forums » The Site » Old Forums » Kerio - Tiny Support » [Kerio 4.x] Kerio/Sunbelt blocks RDP
Search Topic:
Uniqs:
301
Share Topic:
RSS topic:
toggle:
flat / full
normal / watch
Posting:
AuthorAll Replies


Teledata

@t-dialin.net

[Kerio 4.x] Kerio/Sunbelt blocks RDP

Hello,

i've got a Problem: I am trying to connect my PC from another computer with the RDP, which is included in Windows XP. Everytime i switch of the firewall, it works. I created a rule, but i am not sure if that is the right rule.

Please see the screenshots below:

»www.eriks-light-house.de/hc_001.jpg
»www.eriks-light-house.de/hc_002.jpg
»www.eriks-light-house.de/hc_003.jpg

For Help I would be very thankfull - If you need more information, don't hesitate to ask

Teledata

Mister_E

join:2004-04-02
Etobicoke, ON


edit:
August 22nd, @11:11PM

I believe your port rules are too strict - RDP expects communication to be directed to local port 3389, however, the outgoing port used for communication could be any. Picture above is from Kerio 2.15, but you should get the idea:

If you're connecting from a computer with Kerio installed (as in the pic above), you need to set the local end point port to be any and the remote end point to be 3389 (and ideally specified to the ip address you're connecting to).

If it's the computer you're trying to control remotely that has Kerio installed, the opposite would be true - e.g. connection is to local port 3389, but the remote port can be varied.


Teledata

@t-dialin.net

Hi,

thank you for your quick reply.

I changed the rule like in the screen below:

»www.eriks-light-house.de/hc_004.jpg

But it still don't work. It try to connect from another PC to my PC at home. My PC at home has the kerio/sunbelt firewall installed. As I said - if I shut down the firewall, it works.

Do you have any other idea?

Mister_E

join:2004-04-02
Etobicoke, ON


edit:
August 24th, @01:24AM

First, I would specify the protocol as TCP.

Then, for the local port, you need to specify 3389 - don't specify all ports as this will leave your system open!

For the remote options, the port number should be set to all (or blank - I don't remember what Kerio 4.x uses). If the IP you're connecting from doesn't change (e.g. a static internet IP) you can specify it for added security - otherwise, don't specify an IP or set an IP range that belongs to the IP block you connect from.

Finally, the application specified should be C:\WINDOWS\system32\svchost.exe (as it's svchost that's listening to requests on port 3389 and will manage the Terminal services connection - assuming you're running XP at home). If this doesn't work, you may have to change the application specified to 'Any' to allow communication on port 3389 to get where it needs to go.

Also, if you have a router in between the home PC you're connecting to, you may have configure it to port forward 3389 to the PC's internal IP address. (If your router supports a VPN connection/VPN server, you'll be better off using this to establish the connection - see below.)

BE WARNED though, opening port 3389 is a security risk - many port scanners check to see if this port is open and attack via it, etc. The best solution is to set up a VPN connection first, then run Remote Desktop over the VPN.
Forums » The Site » Old Forums » Kerio - Tiny Support


Wednesday, 19-Nov 09:59:45 Terms of Use | Privacy Policy | Hosting by www.nac.net - DSL,Hosting & Co-lo | feedback | contact
over 9 years online! © 1999-2008 dslreports.com.
page compression OFF
Most commented news this week
· [185] Obama FCC Selection Team Won't Make AT&T Happy
· [97] DSL's Not Dead Yet
· [66] Zone Alarm Pro Free Just For Today
· [49] Cable Grabbing 71% Of New Broadband Customers
· [44] Comcast Offers 'Bare Bones' 768kbps VoIP Double Play
· [44] Comcast DOCSIS 3.0 Hits Pacific Northwest In December
· [42] Comcast Buys San Fran Muni-Network
· [41] Spam Success: A 1 In 12.5 Million Shot
· [34] iPhone 3G Most Popular Phone
· [28] Sprint Offering Employee Buyouts
Most people now reading
· Wiring error - how serious? [Home Repair & Improvement]
· [rant] Apple can be really stupid. [All things Macintosh]
· Microsoft: Windows 7 ready for Christmas [Microsoft help]
· Oregon Woman Loses $400,000 to Nigerian E-Mail Scam [Security]
· Upgrading from Premiere to ExtremeHD [Verizon FIOS TV]
· CallWithUs: Is CallWithUs.com Down? [VOIP Tech Chat]
· Epic Fail with Hotkeys [World of Warcraft]
· DIR-655 New firmwares 1.21b04 and 1.21b05_nosecurespot [D-Link]
· [WotLK] Zygor's Leveling Guide Vs QuestHelper Addon [World of Warcraft]