On a Windows Server 2008 R2 virtual server with RDWeb that's open externally (port 3389), a client is able to login to the RDWeb page but unable to connect when opening the remote application.
I've not found any common events that show up in Event Viewer, but the Security logs show that the user logs on and back off a couple of times in a row. The typical events if I were to attempt a login from the client computer were ordered as:
An account was successfully logged on. Subject: Security ID: NULL SID Account Name: - Account Domain: - Logon ID: 0x0 Logon Type: 3 New Logon: Security ID: MYDOMAIN\MYUSERNAME Account Name: MYUSERNAME Account Domain: MYDOMAIN Logon ID: 0x6bcec6fd Logon GUID: {00000000-0000-0000-0000-000000000000} Process Information: Process ID: 0x0 Process Name: - Network Information: Workstation Name: CLIENTHOSTNAME Source Network Address: CLIENTIP Source Port: CLIENTPORT Detailed Authentication Information: Logon Process: NtLmSsp Authentication Package: NTLM Transited Services: - Package Name (NTLM only): NTLM V2 Key Length: 128
An account was logged off. Subject: Security ID: MYDOMAIN\MYUSERNAME Account Name: MYUSERNAME Account Domain: MYDOMAIN Logon ID: 0x6bcec6fd Logon Type: 3
A logon was attempted using explicit credentials. Subject: Security ID: NETWORK SERVICE Account Name: TS-HOSTNAME$ Account Domain: MYDOMAIN Logon ID: 0x3e4 Logon GUID: {00000000-0000-0000-0000-000000000000} Account Whose Credentials Were Used: Account Name: MYUSERNAME Account Domain: MYDOMAIN Logon GUID: {db9597b1-8344-293c-7b99-fff6762c912f} Target Server: Target Server Name: localhost Additional Information: localhost Process Information: Process ID: 0x26f0 Process Name: C:\Windows\System32\inetsrv\w3wp.exe Network Information: Network Address: - Port: -
An account was successfully logged on. Subject: Security ID: NETWORK SERVICE Account Name: TS-HOSTNAME$ Account Domain: MYDOMAIN Logon ID: 0x3e4 Logon Type: 3 New Logon: Security ID: MYDOMAIN\MYUSERNAME Account Name: MYUSERNAME Account Domain: MYDOMAIN Logon ID: 0x6bced09d Logon GUID: {db9597b1-8344-293c-7b99-fff6762c912f} Process Information: Process ID: 0x26f0 Process Name: C:\Windows\System32\inetsrv\w3wp.exe Network Information: Workstation Name: TS-HOSTNAME Source Network Address: - Source Port: - Detailed Authentication Information: Logon Process: Authz Authentication Package: Kerberos Transited Services: - Package Name (NTLM only): - Key Length: 0
An account was logged off. Subject: Security ID: MYDOMAIN\MYUSERNAME Account Name: MYUSERNAME Account Domain: MYDOMAIN Logon ID: 0x6bced09d Logon Type: 3
I'm not sure if these events help, but any ideas on this would be greatly appreciated. We had a similar issue two weeks ago where every user that tried to connect would time out with similar security events, and the workaround for that was to just try 3+ times and it would eventually let you connect. We never really fixed it, but it just kind of went away and this is the closest thing I've heard since.
Thank you