This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Windows Server 2012 R2 Remote Desktop Gateway, Windows 10 Pro 1803 client and UTM 9.510-5 WAF

Good day,

I have been using Sophos UTM for a number of years now and know my way around the solution and its features reasonably well. I have several applications using the WAF feature including MS Exchange (Outlook Anywhere and ActiveSync), and until recently Remote Desktop Gateway (RDG) without any issues. Today I am struggling with RDG installed on Windows Server 2012 R2, and Windows 10 Pro 1803 clients trying to access the service via UTM 9.510-5 WAF.

Examining the WAF logs, I'm finding entries referencing URLs that are non-existent on the RDG server:

2018:09:10-14:26:30 #redacted# httpd[27345]: [url_hardening:error] [pid 27345:tid 3741174640] [client #redacted#:49501] No signature found, URI: https://#redacted#/KdcProxy 2018:09:10-14:26:30 #redacted# httpd[27345]: [url_hardening:error] [pid 27345:tid 3900636016] [client #redacted#:49497] No signature found, URI: https://#redacted#/remoteDesktopGateway/

Thing is, "/KdcProxy" and "/remoteDesktopGateway/" do not exist on the IIS site included in RDG, only "/Rpc" and "/RpcWithCert" are. Adding the URLs to the exceptions list is pointless as this simply results in 404 status codes being returned instead (because they don't exist).

Curiously, using an older Windows version seems to work fine, which leads me to suspect that something changed with the way Remote Desktop clients on Windows 10 communicate with the RDG via WAF; I don't run into any issues when accessing RDG on the internal network, only when accessing via WAF. I'm stumped and would appreciate any guidance from more experienced UTM admins.



This thread was automatically locked due to age.
Parents Reply Children
  • Hi Bob,

    da muss ich mal schauen, es ist so 2 Jahre (13.09.2017) her.
    Ich hatte da auch ein Ticket beim Dienstleister zu gehabt.

    Mein Dienstleister hat das mit Sophos geklärt, mit der UTM geht´s nicht. Bei der XG sei sowas nicht geplant.

    "Leider gibt es seitens Sophos zum aktuellen Zeitpunkt keine Möglichkeit dies nativ über die WAF umzusetzen."

    Ich hatte dann auch mal bei Andrea (Sophos) per mail angefragt, aber es gab wohl keine Rückmeldung von ihr.

    Hier gabs auch mal einen Beitrag  *no plan to implement new features in the upcoming Releases*

    community.sophos.com/.../server-2016-remote-web-workplace-and-remote-desktop-gateway-using-waf

    ABER es ist doch Aussagekräftig genug,

    das in der XG 17.5.3 keine Windows 2012 oder 2016 oder 2019 Remote Desktop in den Business app rules vorhanden ist...
    Naja, von den anderen 

    Windows 2012 und 2016 nutzen RDG , die Info von Louis-M ist mir auch neu (5.3.2019).

    Aber es wird auch zwischen Remote Web und Remote Gateway unterschieden...