RDP Session, very unstable.. No changes on system or network


Recommended Posts

This is on my home network running Windows Server 2012. My firewall is a pFSense box configured to allow RDP.. I have had this setup for a couple of months with no RDP issues..Nothing has changed on my network or on the server. I use it just to remote in from work to manage things while I am away. I have done some goolging and found about 10000 different possible issues.. Didn't know if anyone here has ran into this.. Everything else on my network is working great.. No Bandwidth issues, good pings.. rebooted the server, modem, switch (managed) and pFsense.. Any ideas come off that might point me in the right direction?

Thanks!

Yes, I tried from my parents house last night and still same thing.. Sometimes it won't even let me login.. When it does, I have about a 1-2 minute window before it drops

Maybe I should use LogMeIn or Team Viewer.. Those are more secure anyway from what I read/been told.. I know there are exploits out there and a VPN + RDP is 1000x better.. maybe its a sign to change my ways at home..lol Suggestions on that?

Yes, I tried from my parents house last night and still same thing.. Sometimes it won't even let me login.. When it does, I have about a 1-2 minute window before it drops

Maybe I should use LogMeIn or Team Viewer.. Those are more secure anyway from what I read/been told.. I know there are exploits out there and a VPN + RDP is 1000x better.. maybe its a sign to change my ways at home..lol Suggestions on that?

RDP should be encrypted already, I wouldn't switch the way I do things because of a technical glitch. Any issues on the RDP Server machine in Event Viewer under System/Application that stand out? Windows Firewall turned off on that machine?

And is anything logged in the 2012 server for the drop?

I rdp to multiple boxes on my home network from work, but I do it over a vpn (openvpn) Problem I have with rdp open to the public net, unless you have it locked down to your work IP or other locations you might access it from in pfsense. Is its just a username password for protection. With my vpn, there is no way your guessing anything to get in - you have to have cert issued to by my CA, etc. And if for some reason I lost say my certs I store on my usb - then I could just revoke that cert and issue new ones.

Are you seeing any packet loss to your pfsense box? Can you get a running ping going, let it run for say 1000 or so pings - do you see drops? Increase the packet size of the pings to max.. Run the same test do you see any loss?

Move rdp to a different port. I had the standard 3389 set on my home network and it was getting constant attacks with attempted logins. This made it fragile to login remotely whereas on the lan it was fine.

The event viewer will show a load of failed authorisations if this is the case.

As of now, I can't even log in anymore..It ask me for my user/pass then drops. I will post logs and everything when I get home.. I can't ping the connection because I have that blocked. Thanks for everyone's help..

I was able to get in, and install Team Viewer.. I looked in the event log and there are a ton of,

TerminalServices-Printers

Driver Send To Microsoft OneNote 2010 Driver required for printer Send To OneNote 2010 is unknown. Contact the administrator to install the driver before you log in again.

Team Viewer is not crashing.. Hm...

Also getting a bunch of,

The Device Setup Manager service entered the running state.

The Device Setup Manager service entered the stopped state. Every two minutes..

Also getting these..

The Windows logon process has unexpectedly terminated.

For testing purposes only, bypass the router and directly connect the server to the internet. If you can RDP no problem, and over your internal LAN like you said with no problem, then it is your firewall hardware.

Instead of using any pre-programmed 'RDP' rules on the router, try forwarding an external port to internal port 3389. Then connect remotely using IPADDRESS:PORT. This will keep you safe from the RDP portscanner hack attempts and bypass the routers pre-programmed rules.

I was able to get in, and install Team Viewer.. I looked in the event log and there are a ton of,

TerminalServices-Printers

Driver Send To Microsoft OneNote 2010 Driver required for printer Send To OneNote 2010 is unknown. Contact the administrator to install the driver before you log in again.

Team Viewer is not crashing.. Hm...

Also getting a bunch of,

The Device Setup Manager service entered the running state.

The Device Setup Manager service entered the stopped state. Every two minutes..

Disable printer forwarding.

I was able to get in, and install Team Viewer.. I looked in the event log and there are a ton of,

TerminalServices-Printers

Driver Send To Microsoft OneNote 2010 Driver required for printer Send To OneNote 2010 is unknown. Contact the administrator to install the driver before you log in again.

Team Viewer is not crashing.. Hm...

Also getting a bunch of,

The Device Setup Manager service entered the running state.

The Device Setup Manager service entered the stopped state. Every two minutes..

Also getting these..

The Windows logon process has unexpectedly terminated.

Change your remote desktop connection to ignore printers under options | local resources.

it sounds like you have some troubleshooting to do on your server.

The Device Setup Manager service entered the running state.

The Device Setup Manager service entered the stopped state. Every two minutes..

Also getting these..

The Windows logon process has unexpectedly terminated.

^ if just a file server and other services that linux/bsd can do then sure pick your fav distro and run with it!

Just the other day I was looking to setup printing on my ipad I got for xmas, uses that stupid bonjour to find the printers. Well I had disabled most of the multicast on my windows box because just not having any need for it. And it was sending a bunch of noise that my gateway firewall was logging so just disabled it.

So since I have a linux VM running on my esxi host 24/7/365 anyway, just installed cups on it - connected it to the printer and there you go ipad can now see the printer being shared by cups ;) Took all of 10 minutes to setup vs having to turn mulicast back on my windows machine that would of generated a bunch of noise that isn't needed to be seen on my network.

linux can be a great solution for a bunch of stuff! Enjoy!

This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.
  • Posts

    • If someone chooses to continue using SB and therefore goes through the manual intervention in the thread, afterwards the BSOD problem is gone. Whether they then re-enable the task doesn't matter, they're done, though on such machines it might pay to keep it disabled in case the next update (if there is a next) causes the same problem. OTOH, if someone disables SB in the BIOS, the problem is also gone. Incidentally, I noticed that this task exists even on machines that don't support SB. It's just installed across the board...and runs. Doing what on such machines is a little hazy.
    • qBittorrent 5.2.2 by Razvan Serea The qBittorrent project aims to provide a Free Software alternative to µtorrent. qBittorrent is an advanced and multi-platform BitTorrent client with a nice user interface as well as a Web UI for remote control and an integrated search engine. qBittorrent aims to meet the needs of most users while using as little CPU and memory as possible. qBittorrent is a truly Open Source project, and as such, anyone can and should contribute to it. qBittorrent features: Polished µTorrent-like User Interface Well-integrated and extensible Search Engine Simultaneous search in most famous BitTorrent search sites Per-category-specific search requests (e.g. Books, Music, Movies) All Bittorrent extensions DHT, Peer Exchange, Full encryption, Magnet/BitComet URIs, ... Remote control through a Web user interface Nearly identical to the regular UI, all in Ajax Advanced control over trackers, peers and torrents Torrents queueing and prioritizing Torrent content selection and prioritizing UPnP / NAT-PMP port forwarding support Available in ~25 languages (Unicode support) Torrent creation tool Advanced RSS support with download filters (inc. regex) Bandwidth scheduler IP Filtering (eMule and PeerGuardian compatible) IPv6 compliant Available on most platforms: Linux, Mac OS X, Windows, OS/2, FreeBSD qBittorrent 5.2.2 changelog: FEATURE: Use D-Bus to show file in file managers (Chocobo1) #24340 BUGFIX: Fix friendlyUnitCompact precision calculation (vafada) #24323 BUGFIX: Remove all top-level folders (glassez) #24333 BUGFIX: Use proper API for checking exit status (Chocobo1) #24349 BUGFIX: Delete stale lockfile when hostname mismatch (TurboTheTurtle, glassez) #24363 BUGFIX: Fix wrong removal procedure of watched folder paths (Chocobo1) #24413 BUGFIX: Don't reannounce before interface changes are applied (glassez) #24447 BUGFIX: Use Latin script for Bosnian locale name (Andy Ye) #24342 WEBUI: Fix performance of global checkbox toggling (tehcneko) #24316 WEBUI: Fix Safari transfer list header misalignment (Piccirello) #24377 WEBUI: Fix error when submitting magnet before metadata loads (Piccirello) #24378 WEBUI: Use correct row id when updating Rss Downloader feed selection (Chocobo1) #24402 WEBUI: Use SameSite=Lax for session cookie to fix cross-site login (Piccirello) #24422 WEBUI: Bring back properties panel expand/collapse button (vafada) #24430 WEBAPI: Only use X-Forwarded-Host header when reverse proxy support is enabled (Chocobo1) #24457 RSSS: Fix "RSS Smart Episode Filter" RegEx (nathanon-akk, glassez) #24398 RSS: Fix previously matched episode format (glassez) #24452 WINDOWS: Fix Python fallback search path (TurboTheTurtle) #24325 WINDOWS: NSIS: Allow to install x64 binary on ARM64 (Chocobo1) #24358 Download: qBittorrent 5.2.2 | 41.1 MB (Open Source) Download: qBittorrent 64-bit installer (qt6) | 43.6 MB Links: qBittorrent Home page | Screenshot Get alerted to all of our Software updates on Twitter at @NeowinSoftware
    • Weechat. https://weechat.org/
    • they should stop making bad games that no one asked for
  • Recent Achievements

    • Veteran
      branfont went up a rank
      Veteran
    • Reacting Well
      Almohandis earned a badge
      Reacting Well
    • First Post
      Cosminus earned a badge
      First Post
    • One Year In
      ThatGuyOnline earned a badge
      One Year In
    • Week One Done
      Jeroen Wilms earned a badge
      Week One Done
  • Popular Contributors

    1. 1
      +primortal
      483
    2. 2
      +Edouard
      183
    3. 3
      PsYcHoKiLLa
      123
    4. 4
      Steven P.
      87
    5. 5
      neufuse
      72
  • Tell a friend

    Love Neowin? Tell a friend!