richard101 Posted June 14, 2007 Report Share Posted June 14, 2007 H Allremote assistance is driving me insane !! it definatelly used to work (from my work xp, to my home server).I type mstsc to start it, enter an ip-address that I have confirmed is current, then login info, then after a few mins - error.I use mstsc regularly in my job to different places ok (so I know my work xp machine is fine), and I can connect to my home-router using a URL to port 443 (so I know I can connect)In the past I did change the registry of my home server to use port 81 (- I think). But have definatelly changed it back now to 3389.oh, also, I have a 'service' on my netgear broadband router/firewall/modem called 'work' that forwards any incoming tcp connections on port 3389 to the static ip-address of my windows-2003 web-server.any ideas please?richard101 Quote Link to comment Share on other sites More sharing options...
mcb2001 Posted June 14, 2007 Report Share Posted June 14, 2007 Port 3389 is used for remote desktop connections - and posibly also remote assistance, since its the same protocol.and therefore all data going in on your router, is sent to your windows 2003 server, instead of the computer in question.So my suggestion is that you use another port, and let 3389 either be forwarded to the computer you need to remote assist, or that you just leave it closed (and posibly enables UPnP) Quote Link to comment Share on other sites More sharing options...
richard101 Posted June 14, 2007 Author Report Share Posted June 14, 2007 Hi, thanks for that. Not sure I explained very well.I want to remote from my work XP desktop to my Home Server. My Home server - is - the computer in question. (NB: there are two other machines on my home LAN). Quote Link to comment Share on other sites More sharing options...
ithonicfury Posted June 14, 2007 Report Share Posted June 14, 2007 Can you remote into the server when youre on your local network? Is there a firewall installed on the server? If so, check to make sure remote desktop is exempted, maybe try with the firewall off.On the server try going to www.canyouseeme.org and put in 3389 for the port number, does it say its ok?Check your registry setting again to make sure the port is right. Make sure the terminal services service is running on the server in services.msc Quote Link to comment Share on other sites More sharing options...
richard101 Posted June 14, 2007 Author Report Share Posted June 14, 2007 Yes, I could remote using internal ip-address.Firewall - haven't checked lately, will stop temp and update tomorrowFrom XP http://canyouseeme.org sais for 3389.Will try from server, and update tomaorrowWill check terminal server service.many thanks Quote Link to comment Share on other sites More sharing options...
mcb2001 Posted June 15, 2007 Report Share Posted June 15, 2007 Well, i would check these things:Is there a firewall, and is it open for 3389is there a static IP on the computer (so you can forward directly to it)is the router port 3389 forwarded to itis NAT even enabled on your router?have you enabled UPnP, and in that case, have you tried opening remote access to another computer on the network, who then would be blocking port 3389have you opened for remote access locally on the server (system settings)have you checked windows's own firewall, and positivly disabled it, if your using a better?are you sure you use the right IP address when accessing from outside (some DSL service providers gives a dynamic IP)have you rebooted (NOT RESET) your router, and made sure the DHCP server in it, CANT hand out the IP address you chose for your server?Hope this might help you Quote Link to comment Share on other sites More sharing options...
richard101 Posted June 18, 2007 Author Report Share Posted June 18, 2007 Hi, ok here's the current state ... - I have turned off the Windows firewall on my Home-Server. - On my Home-Router I have a static route for my Home-server (x.x.x.x) - I can use MSTSC to connect from another home-machine to x.x.x.x. - I can remotelly connect to my home-router, and have confirmed there is a service to forward incoming traffic on port-3389 to ip x.x.x.x - I have confirmed my external ip-address at dyndns by browsing to http\\:<expernal-ip-addr> and seeing my web-page. - I have successfully testing port 3389 from home via canyouseeme. - I am unable to test port 3389 from my work as is times-out.Things that have changed since it definately worked (Feb 2007)... - I've changed my ISP (pipex to sky) - and I have changed officeThings that haven't changed ...My Home-serverMy DYNDNS account and settings Quote Link to comment Share on other sites More sharing options...
Scarecrow Man Posted June 18, 2007 Report Share Posted June 18, 2007 You need to forward that port (or any others remote assistance requires) on your router, before it will allow traffic on those ports to pass through to any computers. This is why it works internal, but not external. http://portforward.com/english/routers/por...routerindex.htm Quote Link to comment Share on other sites More sharing options...
richard101 Posted June 18, 2007 Author Report Share Posted June 18, 2007 quoting from my last "... and have confirmed there is a service to forward incoming traffic on port-3389 to ip x.x.x.x ..." Quote Link to comment Share on other sites More sharing options...
Scarecrow Man Posted June 18, 2007 Report Share Posted June 18, 2007 I have read your post, and see you are using a service http://canyouseeme.org/. This does not mean the forwarding is set up, because all http traffic is done via port 80, so it is possible the router is forwarding this traffic on port 80, even though it reports otherwise. Please check your router settings.EDIT: I have just tested this service while monitoring ports, and no traffic was sent via 3389 even though that was the one I tested. Quote Link to comment Share on other sites More sharing options...
ithonicfury Posted June 18, 2007 Report Share Posted June 18, 2007 Maybe check that you have the port forward set to tcp and not udp. Try from another location or try connecting to another rdp server elsewhere on the internet if available (your works firewall may be blocking outgoing traffic on 3389.)Maybe try setting up an ssh server on your network and use an ssh tunnel to connect to it, or use a VPN like Hamachi to connect (might want to disable file and print sharing on the hamachi interface though, especially on the work one cause of performance and security issues.) Quote Link to comment Share on other sites More sharing options...
mcb2001 Posted June 18, 2007 Report Share Posted June 18, 2007 You need BOTH udp and tcp on port 3389.And another thing, is it only at your office you cant connect, because then it might be the firewall there! Quote Link to comment Share on other sites More sharing options...
richard101 Posted June 19, 2007 Author Report Share Posted June 19, 2007 Hi, thanks, still failing with UDP/TCP setting in port-forwarding config.QUESTION - do I need port 3389 open at both ends? (ie: testing 3389 with 'canyouseeme.org' passes from my house, but failes from my work). Quote Link to comment Share on other sites More sharing options...
mcb2001 Posted June 19, 2007 Report Share Posted June 19, 2007 as i remember it, you only need it at home, since it can be pasive from the outside...At least i know for a fact, that i can connect pasively from my work (university with rather anoying firewall) to my home server, using both remote desktop, ftp and web...BUT with that said, you might actually have a "bad" firewall, blocking the request, cause its a known security issue, that you can remote access the computer.meaning that the office firewall just blocks out all attempts to logon to your home server.So what i would do is:Setup up the connection, and the second you press "connect" via remote desktop, go to "start menu" > "run" > "cmd" and type in "netstat -b -n" to see which port you are using for the remote desktop on your office computer, and then ask your IT department to open that port in the firewall... Quote Link to comment Share on other sites More sharing options...
richard101 Posted June 19, 2007 Author Report Share Posted June 19, 2007 Hi again* please ignore my last (forgot what I had open) *ok, every entry (in netstat) for my home server uses 3389 and has status on syn_sent until it times out. Quote Link to comment Share on other sites More sharing options...
mcb2001 Posted June 19, 2007 Report Share Posted June 19, 2007 syn_sent aint a good status in this case.It either means that your router is rejecting the request, or that the firewall on your office network, aint forwarding it to your router.But what you also needed to look at in the "netstat -b -n" is which internal port that are being used, because if its below 10k (good standard pointer to be sure) its definatly locked at the firewall by default, and not a port usable for normal "passive mode". Quote Link to comment Share on other sites More sharing options...
mcb2001 Posted June 19, 2007 Report Share Posted June 19, 2007 Thanks (very interesting command). I used mstsc and captured the list as requested.I repeated this a number of times looking for mstsc.exe and got ...x.x.x.x:3389 establishedx.x.x.x:3389 establishedx.x.x.x:3389 syn_sentx.x.x.x:3389 establishedx.x.x.x:3389 syn_sentx.x.x.x:3389 establishedx.x.x.x:3389 establishedx.x.x.x:3389 = my home serverx.x.x.x= dunno (but looks like its on same subnet as my work pc).IDEA !this x~ ip, can it be using up same resource? (IE: can xp only have one ts session at a time?)And just a single word of advise - hide your IP, since this is an open invitation to anyone without a legitimate reason, to try and take over your computer.Original post deleted as requested - BorisYou already told which sort of OS your running, which ports you got open, and then its actually just a mather of time before someone gets dumb ideas...As an example, i can already tell you that both IP's listed are from the UK...But anyways, hope my post right above this might help a bit finding the reason for the remote desktop problems... Quote Link to comment Share on other sites More sharing options...
richard101 Posted June 20, 2007 Author Report Share Posted June 20, 2007 Morning All (btw: my isp seems to change my ip almost every day)here's some output ...C:\WINDOWS>netstat -b -nActive Connections Proto Local Address Foreign Address State PID TCP [my work ip]:1871 [my home server]:3389 SYN_SENT 1472 [mstsc.exe]...... I hope this is meaningful.Oh, also, after trying mstsc to connect - for the above test, I looked on my home-router log (I have everything set to 'always log'), and there were only two entries today 1) HTTP match at 09:30 (where I browsed my home-page this morning) and 2) administrator remote-login (me reading this log now).So ... I guess ... the request isnt getting to my home-router. right? Quote Link to comment Share on other sites More sharing options...
mcb2001 Posted June 20, 2007 Report Share Posted June 20, 2007 Morning All (btw: my isp seems to change my ip almost every day)So ... I guess ... the request isnt getting to my home-router. right?First thing - get a static IP, almost every ISP offeres it, might cost you a couple of euro, but defenitly worth it...Second thing, the router don't log f.x. ping requests, so the router can't be ruled fully out!But with that said, yes, its the office computer network thats the problem... Do you have an IT department, who can help you setup the right access?Or is this a small network? - and in that case, have you tried disabling your firewall(s), then connecting first to your webserver, then use the same IP and connect to the remote desktop? Quote Link to comment Share on other sites More sharing options...
richard101 Posted June 21, 2007 Author Report Share Posted June 21, 2007 Thanks all: job-done: had quiet chat w network-guy, who said 3389 is blocked (and reason I can mstsc to other sites, is, there within the firewall) doah! Quote Link to comment Share on other sites More sharing options...
Recommended Posts
Join the conversation
You can post now and register later. If you have an account, sign in now to post with your account.