Quantcast
Channel: Remote Desktop Services (Terminal Services) forum
Viewing all articles
Browse latest Browse all 1106

Remote Desktop - No connection but shows logon/logoff

$
0
0

On a Windows Server 2008 R2 virtual server with RDWeb that's open externally (port 3389), a client is able to login to the RDWeb page but unable to connect when opening the remote application. 

I've not found any common events that show up in Event Viewer, but the Security logs show that the user logs on and back off a couple of times in a row. The typical events if I were to attempt a login from the client computer were ordered as:

An account was successfully logged on.

Subject:
	Security ID:		NULL SID
	Account Name:		-
	Account Domain:		-
	Logon ID:		0x0

Logon Type:			3

New Logon:
	Security ID:		MYDOMAIN\MYUSERNAME
	Account Name:		MYUSERNAME
	Account Domain:		MYDOMAIN
	Logon ID:		0x6bcec6fd
	Logon GUID:		{00000000-0000-0000-0000-000000000000}

Process Information:
	Process ID:		0x0
	Process Name:		-

Network Information:
	Workstation Name:	CLIENTHOSTNAME
	Source Network Address:	CLIENTIP
	Source Port:		CLIENTPORT

Detailed Authentication Information:
	Logon Process:		NtLmSsp 
	Authentication Package:	NTLM
	Transited Services:	-
	Package Name (NTLM only):	NTLM V2
	Key Length:		128
An account was logged off.

Subject:
	Security ID:		MYDOMAIN\MYUSERNAME
	Account Name:		MYUSERNAME
	Account Domain:		MYDOMAIN
	Logon ID:		0x6bcec6fd

Logon Type:			3
A logon was attempted using explicit credentials.

Subject:
	Security ID:		NETWORK SERVICE
	Account Name:		TS-HOSTNAME$
	Account Domain:		MYDOMAIN
	Logon ID:		0x3e4
	Logon GUID:		{00000000-0000-0000-0000-000000000000}

Account Whose Credentials Were Used:
	Account Name:		MYUSERNAME
	Account Domain:		MYDOMAIN
	Logon GUID:		{db9597b1-8344-293c-7b99-fff6762c912f}

Target Server:
	Target Server Name:	localhost
	Additional Information:	localhost

Process Information:
	Process ID:		0x26f0
	Process Name:		C:\Windows\System32\inetsrv\w3wp.exe

Network Information:
	Network Address:	-
	Port:			-
An account was successfully logged on.

Subject:
	Security ID:		NETWORK SERVICE
	Account Name:		TS-HOSTNAME$
	Account Domain:		MYDOMAIN
	Logon ID:		0x3e4

Logon Type:			3

New Logon:
	Security ID:		MYDOMAIN\MYUSERNAME
	Account Name:		MYUSERNAME
	Account Domain:		MYDOMAIN
	Logon ID:		0x6bced09d
	Logon GUID:		{db9597b1-8344-293c-7b99-fff6762c912f}

Process Information:
	Process ID:		0x26f0
	Process Name:		C:\Windows\System32\inetsrv\w3wp.exe

Network Information:
	Workstation Name:	TS-HOSTNAME
	Source Network Address:	-
	Source Port:		-

Detailed Authentication Information:
	Logon Process:		Authz   
	Authentication Package:	Kerberos
	Transited Services:	-
	Package Name (NTLM only):	-
	Key Length:		0
An account was logged off.

Subject:
	Security ID:		MYDOMAIN\MYUSERNAME
	Account Name:		MYUSERNAME
	Account Domain:		MYDOMAIN
	Logon ID:		0x6bced09d

Logon Type:			3

I'm not sure if these events help, but any ideas on this would be greatly appreciated. We had a similar issue two weeks ago where every user that tried to connect would time out with similar security events, and the workaround for that was to just try 3+ times and it would eventually let you connect. We never really fixed it, but it just kind of went away and this is the closest thing I've heard since.

Thank you



Viewing all articles
Browse latest Browse all 1106

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>