RD Gateway problem when in Open extarnal

RD Gateway problem when in Open extarnal

avatar

We have problems connection to servers with RDP external through a Microsoft RD Gateway we log on to with a password from the user vault.

If I choose to Connect to an RDP session from RDM (Open external)

 I gett:
Remote Desktop Connection 
Your computer can't connect to the remote computer because a security package error 
occurred in the transpot layer. Retry the connection or contact your network administrator 
for assistance. 
Hide details 
Error code: Dx3DDD017 
Extended error code: OXO 
Press Ctrl+C to copy.

If I choose to use embedded, it works.

If I rename the Password entry in my user vault, then I am asked for a username and password by windows then it works connection external.

The most of our users use embedded, but those who use it external this a problem for some of them, to make this even better
they can have days that it works, not everybody at the same time.
I think this started after upgrading to 2021.2.x
Windows 10 and windows 11
Remote desktop manager Enterprise edition 2021.2.26
Datasource Azure SQL
forum image

All Comments (13)

avatar

Hello,
Could you try to toggle this setting?

forum image

Regards

David Hervieux

avatar

When I turn it off, I'm asked for credentials by the Microsoft RD gateway.
forum image

avatar

Hello,

Thank you for your swift reply!

If you save your credentials in your RDP entry directly, without using those from your User Vault, do you experience the same issue when the RDP connection is launched externally?

Best regards,

James Lafleur

avatar

Yes , I get the same problem when configuring the Usernam and password on the RDP entry directly.

avatar

Hello,

Thank you for your swift reply!

The next time this issue occurs, could you please ask your users to go under Help -> Profiler -> Debug Only and set the debug level to 1?
Once this is done, ask them to launch the connection again and provide us with the logs that will be created in the Profiler Window.

Once this is done, make sure to set your debug level back 0. These logs can be sent to me via private message.

Best regards,

James Lafleur

avatar

I do not get anything in the log when set the debug level to 1 and connect to a server open with parameters open(external).
Can it be a setting that I missed?

avatar

Hello,
I have added a new debug log and this will be in the next minor update. The problem with external RDP is that we can't set the credentials directly and we have to set it in the Windows Credential Vault.

Regards

David Hervieux

avatar

I do not think this is a username/password problem, I base this on that if I change the password in the password entry in my personal vault, I get this:
forum image
If I then type my username and password I get logged inn.
But when the username and password is correct in my personal vault I get:
forum image
And I have found that if you change:

HKEY_CURRENT_USER\Software\Microsoft\Terminal Server Client
Name: RDGClientTransport
From 1 to 0 You get logged inn,
but then you have the problem that you may have to tray 10 times to log on to a server, so that is not a god solution.

avatar

Hello,

While reading your reply, the workaround you have found was what I was about to suggest. This is explained in detail here: https://kb.devolutions.net/rdm_microsoft_rdp_remote_computer_error.html

Since this workaround does not seem to suit your needs, I would recommend trying the first solution mentioned in the above link instead. Let us know if that works for you.

Best regards,

James Lafleur

avatar

We have the Activate network level authentication checked and it does not work.

avatar

Hello,

Thank you for your swift reply!

Would you be interested in having a remote session? We could take a closer look at your current configuration and see what can be done. If you are interested, just let me know and I will open a support ticket on your behalf in order to schedule a session with you.

Best regards,

James Lafleur

avatar

Yes please do.

avatar

Hello,

Thank you! Your case number is 00002286 and you should receive a reply from me shortly.
Once this issue has been sorted, I will post the solution on this forum thread.

Best regards,

James Lafleur