Microsoft Remote Desktop over L2TP/IPSec VPN to Tiger Server not working

I need to use Microsoft Remote Desktop over an L2TP VPN connection to a Mac OS X Server (10.4.2). the VPN connection itself is working fine, I can use AFP, SSH, LPT and any other thing I've tested. The only thing that doesn't work is MS-RDC. (Version 1.0.3 (040913))

The exact Error message I get from MS-RDC Client is:

The client computer could not connect to the remote computer
Either remote connections are not enabled, the computer is too busy to accept new connections, or network problems are preventing your connection. Try connecting again later or contact your administrator.

I really like the clear and focused error message with a lot of possibilities...

Remote connections are enabled on the remote computer and that machine is definitely not too busy to accept new connections. Connecting at a later time doesn't help either which leaves me with the "network problems" and contacting my administrator. I am quite confident that I do not have problems with the network as I can use any other service over that VPN connection. My administrator, which I am myself, didn't have a solution for me yet. 🙂

Afaik MS-RDC only uses TCP port 3389, just like AFP uses TCP port 548. The difference is, that AFP works just fine, whereas RDC keeps telling me about not beeing able to connect. When physically connected to the network there RDC works just fine. I am connected over 3Mbit DSL, so bandwidth shouldn't be a problem.

The "example" connection in RDC is listed as IP 192.168.255.255 which would be the broadcast address of a private IP range. This is a little annoying though a broadcast IP doesn't exist on this VPN connection. (At least not according to ifconfig ppp0) RDC doesn't seem wanting to connect to the braodcast or DSN, or mDNS or anything else but the remote computer's IP. Still leaves me confused.

I've seen quite a lot of info over the net of people using RDC over VPN connections, and my personal guess is, that I am not the first and only one to try this.

The system.log and console.log on the client (my PowerBook) stay empty. As far as I can tell, access is not restricted by either firewall.

Regards MacLemon

PowerBook G4 Mac OS X (10.4.3)

Posted on Dec 5, 2005 8:21 AM

Reply
6 replies

Dec 18, 2005 8:54 PM in response to Peter Scordamaglia

I VPN in over L2TP and connect to our XP machine with Remote Desktop Connection. You need to open port 3389 on your server. I did that for only our internal IP addresses. This is a bit more secure. Since when you VPN in you have an internal IP address, this will work just fine. Now I can VPN in and connect to the XP machine over the VPN. Hope this helps. I got the same message you did until I found that port.

Dec 20, 2005 2:25 AM in response to Leif Carlsson

I've found out what the problem was.

The windows PC did inherit some firewall rules from it's PDC that neither me nor the windows admin knew about. It was the hint to portscan the Windows machine locally and over the VPN that brought me there. (A little embarrassing that I didn't find that out by myself.)
Our Windows sysadmin wasn't able to change the firewall rules (sic), but I could adapt the IP range served to VPN clients to match the range allowed by Windows.

No we're happily using MS-RDC over L2TP for remote control. Both, Microsofts official client as well as rdesktop work just fine.

If like me, you don't want to use the Microsoft client, there is an opensource X11 Client available that compiles from source without a hitch on Mac OS X (Tiger). A fink package "rdesktop" is available as well if you don't want to do it manually.

See http://www.rdesktop.org for more information.


Regards MacLemon

PowerBook G4 Mac OS X (10.4.3)

This thread has been closed by the system or the community team. You may vote for any posts you find helpful, or search the Community for additional answers.

Microsoft Remote Desktop over L2TP/IPSec VPN to Tiger Server not working

Welcome to Apple Support Community
A forum where Apple customers help each other with their products. Get started with your Apple Account.