Posts

Showing posts from February, 2011

External RDWeb Access generates two RDP sessions in RDS Farm and other problems

i'm having problem logins rdwa/rdg setup internal farm. using san cert , farm named cert, digitally signed remoteapp mstsc.exe using farm name cert arguments topoint ot rds farm name , use public mode, domain name same inside outside, using nla, rdp client 7.0 , web sso. internally, no issues. externally, no issues following exceptions. using rd web access rd gateway, user accounts attempting log onto rds farm internet have 2 sessions different rds farm servers. upon logout, 1 remain in disconnected state (until ide/disconnected timeout threshold reached: 30 minutes company policy). happens every time. intermittent issues happen during second logon prompt comes when published mstsc.exe remoteapp used (full desktop desired policy): #1 during second logon , monitoring remote desktop connection manager,  see rds farm user accoutn session #1 active in remote desktop connection manager farm, logon prompt , attempt logon. if successful, when see 2 rdp sessions on 2 sepa...

Server 2012 R2 Hyper-V and Drivers

hello all,  question regarding drivers on our dell systems deploying use in msft 2012 r2 environment.  of systems showing requiring nic driver updates dell.  i'm little leery of replacing msft drivers dell drivers want hear on recommendations.  i'm concerned msft may not have tested drivers and/or hyper-v has been tested extensively using msft drivers versus vendor nic drivers. hi, are concern windows update drivers tested or not? these updates typically available on windows update. contain security fixes, , time time contain reliability rollup packages. these updates thoroughly tested , microsoft highly recommends update computer these releases. in fact, automatically downloaded machine if have windows update turned on. in cases, update releases available standalone downloads download center. more information: windows hotfixes , updates - how work? http://blogs.msdn.com/b/ntdebugging/archive/2008/10/21/windows-hotfixes-and-updates-how-do-...

Windows 2003 DC migration to cloud vendor (Hosted Service)

dear all, is there way/solution migrate windows 2003 dc cloud? currently, have on premise infrastructure installed in office.  dc 2003, dhcp, dns, ad, exchange 2007, file server, dbase server. we plannning subscribe , migrate a cloud vendor iaas. thanks advise. regards, oscar hello, just see additional dc same domain , install/move other servers hosting environment different site. way can move everything, online, hoster. for exchange move server exchange forum better place , database server use forum vendor. best regards meinolf weber disclaimer: posting provided "as is" no warranties or guarantees , , confers no rights. Windows Server  >  Windows Server General Forum

RemoteFX not possible

  our customer require centralize gpu processing. remotefx ordinary usages not close near native performance.   there gpu passthrough feature latest hyper-v in server 2012 r2 ?   or later expected ?   microsoft have disk passthrough, nic passthrough sr-iov still importantly missing display adapter passthrough. shahid roofi hi, thanks question. i’m not sure if gpu passthrough feature included in coming windows server 2012 r2. however, submit customer wish in our internal portal. thanks feedback.  best regards jeremy wu Windows Server  >  Remote Desktop Services (Terminal Services)

Error ID 56 Error in Protocol Stream from Unknown IP

the error message is: the terminal server security layer detected error in protocol stream , has disconnected client. client ip: 94.242.239.162. no way ip should logging in.  hacker?  if so, should see how far got? the security log show failed login 2 seconds before (failed network login.  tried login admin.) thanks in advance don hi, is server able accessed internet? it seems 94.242.239.162 tried access server through rdp. protect server, may try limite access internet configuring firewall. best regards, steven lee please remember mark replies answers if , unmark them if provide no help. if have feedback technet support, contact tnmff@microsoft.com. Windows Server  >  Remote Desktop Services (Terminal Services) ...

2003 native mode to 2008?

Image
i running in 2003 native mode 10 domain controllers.  want add 2008 r2 domain controller.  there such thing 2008 mixed mode?  if so, of 2008 functionality 1 2008 r2 server or of domain controllers need @ 2008 r2?  thanks hi, you can install windows server 2008 r2 in windows server 2003 native mode. since have many windows server 2003 domain controllers, domain , forest functional level cannot upgrade windows server 2008 r2. for new features windows server 2008 r2 domain , forest functional level provide, please refer following microsoft technet article: understanding active directory domain services (ad ds) functional levels http://technet.microsoft.com/en-us/library/understanding-active-directory-functional-levels(v=ws.10).aspx to upgrade or install windows server 2008 r2 in windows server 2003 environment, need run adprep.exe. more information, please refer following microsoft technet article: upgrade domain controllers: microsoft support quick star...

\users\administrator loses its contents

(i have installed system center endpoint protection msdn , found no viruses) going on??? on 3 of servers now, 2 virtual , 1 physical, loose desktop contents (turns black), , folder contents go this:  directory of c:\users\administrator 03/11/2015  11:10    <dir>          . 03/11/2015  11:10    <dir>          .. 02/09/2015  12:54 pm    <dir>          contacts 03/12/2015  01:43 pm    <dir>          desktop 02/09/2015  12:54 pm    <dir>          documents 02/09/2015  12:54 pm    <dir>          downloads 02/09/2015  12:54 pm    <dir>          favorites 02/09/2015  12:54 pm    <dir>          links 02...

TS Roles on one machines

hi,   is ok install :   terminal service ts web access ts remoteapp ts gateway on 1 machine ??   is there security issue ? disadvantages ? _____________________________ tarek majdalani computer engineer, ciw, mcsa: security 2000/2003, ts: windows vista mvp -- isa firewalls website : http://www.elmajdal.net/isaserver hi!   yes - can install mentioned roles on 1 box. there should no problems/disadvantages  nor security issues.   thanks, geanina   Windows Server  >  Remote Desktop Services (Terminal Services)

Remote Desktop Gateway Support One Time Passwords?

we considering setting remote desktop gateway server users can remote control office desktop pcs home without needing vpn. the plan secure pass-through internet desktop pc.  there not terminal services login or web apps hosted on server.  we have not decided if rdweb available.  it users use rdp client such microsoft mstsc.exe remote desktop client in windows or similar app ios, android or osx rather use browser reach pc. i noticed rdp clients, mobile apps , web browsers have option remember credentials can log in without typing credentials next time connect.  this security threat if pc stolen , not encrypted.  is there way provide access, prevent users reusing saved passwords connect remote desktop gateway without using smart cards? i had idea of having kind of 1 time password system authenticate through rd gateway saved passwords useless.  what remote desktop gateway support can this? hi, posting in windows server forum. consider t...

HELP!!! How to do a WMI SUPERCLASS reference using POWERSHELL

hi friends, i'm developing wmi subclass , reference superclass subclass. i know mof code is: class mysubclass : __superclass how can same using powershell? my ps code is: $newclass = new-object system.management.managementclass ("root\mysubclass", "root\mysubclass\__superclass", $null); $newclass['__class'] = "mysubclass" $newclass.properties.add('name', [system.management.cimtype]::string, $false) $newclass.properties['name'].qualifiers.add('key', $true) thanks tavares [system.management.managementclass]::new(<namespace crete in>, < fullpath new class>,<options>) add ":superclass" new class name set class derive from. $myderivedclass = [system.management.managementclass]::new('root\cimv2', 'root\cimv2\myderivedclass:win32_environment', $null) $myderivedclass.__class = 'myderivedclass' # add properties , methods $myderivedclass.put() ...

installing interactive service

i have application bundles tomcat. instead of using tomcat startup.bat want install interactive service. using service.bat install service. not make interactive. how can programatically. command line options enable interactive mode? hi rempran, thank posting in windows server forums, you can use set command , syntax : set [ variable =[ string ]] variable specifies environment-variable name. string specifies series of characters assign variable. ============================================================================ another example using echo eg: <tt>echo off</tt> <tt>cls</tt> <tt>rem yesno.bat</tt> <tt>rem delete file named yn</tt> <tt>if exist yn del yn</tt> <tt>rem prompt user</tt> <tt>echo if want yes branch,</tt> <tt>echo press key followed by</tt> <tt>echo ctrl-z , enter. if you</tt> <tt>echo want no branch, press</tt> <tt>echo ctrl-z , e...

WAIK 3.0 Where?!

i see many 'hits' waik 3.0 end getting kb3aik iso. when installs, program files says version 2.0. and when microsoft presents "download", doesn't version number in file name. i looking 3.0 can use dism update image patches , drivers. if knows...thank you. hi, i suppose looking this: windows assessment , deployment kit (adk) windows® 8 http://www.microsoft.com/en-in/download/details.aspx?id=30652 hope helps. Windows Server  >  Setup Deployment

Edit Group Policy

i have pc has power settings pushed out default domain policy in ad environment. of course on local machine "some settings managed system adminstrator". the machine temporarily no longer in contact domain controller (it's been physically moved , not on same network now) can't updated gpo settings. i believe if edit local group policy won't make difference because of group policy processing , precedence. since it's temporary away ad network, still want use settings of ad user. is there somewhere in registry stored can edit power plan manually until can sync domain? (i need prevent sleeping while plugged in - it's set 1 hour) thanks! allen crist i found site: http://gpsearch.azurewebsites.net/#7916 i able add policy to hkey_local_machine\software\policies\microsoft\power using specs found on site. looks solved issue. i'll report if didn't. thanks! allen crist ...

Domain Controller replication General question

hello, i have 2 dc, other 1 replica main dc , read disabled, problem move 5 roles main secondary + global catalog, secondary server after move become main dc (master) ?? after step can take old main dc , clone new dc server ?? regards, ayesh. all dcs same (except rodc). in that, dcs hold fsmo. each dc in domain can global catalog server , fsmo roles can transferred between them. devaraj g | technical solution architect Windows Server  >  Directory Services

TwoFactor Authentication: VMM VM Console Access

hi everyone, i'm setting 2 factor authentication rdp connections hyper-v virtual machines requiring smart card. there way enforce 2 factor authentication when connecting via rdp not when accessing the virtual machine console using vmm? is this possible?   hi, for rds, there 3 ways add second layer of authentication: 1. pre-shared user certificate 2. pre-shared token 3. otp you can refer thread: 2 factor authentication or otp windows remote desktop services http://social.technet.microsoft.com/forums/windowsserver/en-us/e2219953-cabf-47da-8954-fa3107b61b1a/2-factor-authentication-or-otp-for-windows-remote-desktop-services hope helps. best regards jeremy wu Windows Server  >  Remote Desktop Services (Terminal Services) ...

Problems enabling 3D acceleration using DDA

hello, we have windows 10 pro x64 gen2 vm on hyper-v server 2016 graphics card assigned vm using dda. have managed working successfully, card installed latest whql signed drivers , we've run number of 3d tests , confirmed 4 5 times increase in framerate on saw when ran same vm using remotefx (for additional clarification, we're not using remotefx longer, used baseline performance comparison using same hardware in different configuration). however, when testing number of features such gpu accelerated browser features, media playback , testing tools we've found direct3d seems broken. taking @ dxdiag can see directdraw acceleration , texture acceleration both 'not available'. attempting inspect graphics configuration leads problems, can't access 'display adapter properties' rdp session. using hyper-v management console , direct connecting vm allows access , edit display properties of 'microsoft hyper-v video' adapter. can disable in devi...

Terminal Services User Access

i have setup ws08 ts gateway/rras/active directory, every thing works fine , users part of administrative group can log in not in group can not log in terminal services. know administrators not need go through ts, possible setting in ts mis-configured. users message saying not authorized log in ts , need added remote desktop group.... have created , added group network , ts gateway policies grant access specific group. so  not know why nobody can connect, in rd client 6 when browse computer domain/workgroup not contain terminal servers.     hi,   from error you're getting, sounds you've got gateway setup properly, may not have terminal server setup needed.  can confirm (domain?) users in each terminal server's 'remote desktop users' group?  ts configurations use domain user groups , add each terminal server user groups.    if haven't looked already, there's gateway info site: http://technet2.microsoft.com/windowsserver2008/en/library/9da3742f...

Best way to replicate a directory share to a new Windows 2012 serv, keeping all permissions and timestamps the same?

we have legacy windows 2008 r2 server, single network share on it, acting primary file share.   inside network share dozen different folders (with subfolders) different permissions applied them @ folder , file level.    i want migrate/copy entire directory structure new windows 2012 standard server, keeping timestamps, permissions, etc. on old directory structure.  both servers part of same single windows 2008 r2 domain. what best practice method achieving this?  using xcopy?   if so, syntax want use command make sure don't lose permissions or change data , timestamps during migration? hi  recommend use  robocopy accomplish it. technet guide robocopy command: http://technet.microsoft.com/en-us/library/cc733145(v=ws.10).aspx microsoft robocopy gui  tool .  tool link:  http://www.myitforum.com/articles/15/view.asp?id=9433 note: test in test environment, before applying production servers regards, ravikuma...

Replication

 i have problem rodc not want replicate. here small example of lay out. i have main ad server ,  rodc's. when run repadmin /replicate on rodc1 replicates when run on rodc2 , rodc3 tells me rpc server unavailable. found solution - thought might work 1 website led more problems. on rodc2 stopped , started netlogon services ran ipconfig /flushdns , started netlogon services again , led database error. atleast know how fix that.  on rodc3 have not done because don't want same happen. can please me out on rpc error   when run repadmin /replicate on rodc1 replicates when run on rodc2 , rodc3 tells me rpc server unavailable. >>>rpc server unavailable ad replication error 1722. article below explains symptoms, causes , how resolve.   active directory replication error 1722: rpc server unavailable https://technet.microsoft.com/en-us/library/replication-error-1722-the-rpc-server-is-unavailable(v=ws.10).aspx best regards, jay   ...

Outlook 2003 unable to view pictures

hello, i need question answered please. an email has been sent 2 people. email contains picture has been pasted in it. 1 person can view picture , other person can not. how can person view picture. cheers   hello,   thank reply.   according description, afraid cause closely related outlook 2003.   to issue resolved in timely manner, suggest discussing issue in our office newsgroup.   office newsgroup: http://www.microsoft.com/office/community/en-us/default.mspx?dg=microsoft.public.outlook.general&lang=en&cr=us   i hope issue can resolved soon.   tim quan - msft   Windows Server  >  Windows Server General Forum

GPO for Application Deployment

i'm stumped problem hope can give me suggestions. put i've got msi need deploy. i've got server (windows 2008) in usa , in uk (windows 2003). so, software package put same location on both servers, shares set up, etc. 2 gpo's created depending deploying software depending on ou machine in. fine far. fired test xp box, put usa ou , sure enough application deploys windows 2008 server , good. rebuilt test xp box, fired up, put in uk ou , application tries deploy uk fails error: "failed apply changes software installation settings.  software changes not applied.  previous log entry details should exist.  error : installation source product not available.  verify source exists , can access it. " ok, test fire command prompt , launch under nt auth\system - sure enough anonymous access blocked on 2003 box change local policy allow anonymous connections , xp box connects still doesn't have permission run msi. running via nt auth\system account er...

Once more for posterity DNS-DHCP insteractions on the same server.

Image
first of apologize since question has been asked many times cant seem fit of answers current issues. first of all done in virtual environment ie. closed loop. i have windows 2008 r2 server have installed both dns , dhcp servers on. server has address 10.10.10.10 static address. gw set 10.10.10.1 , dns set 10.10.10.10, subnet 255.255.255.0. not domain controller domains not used. the dhcp server installed on server serving out scope 10.10.10.20-10.10.10.240 presenting dns , gw + subnet values mentioned above. dhcp flawless! serves out ip's no end sorts of clients old windows machines , linux machines. no problem! installed dns server also: called domain blah.local created forward , reverse zones wizard. made sure dhcp server set update records. manually made (a) record server name blah-dhcpdns.local pointing 10.10.10.10 , created ptr record itself. now...  none of dhcp'd clients getting hostnames recorded.   can see leases names in dhcp address leases...

languages input

hey! i added on terminal server new language , need users able change input language while using apps. when changed under profile in session host  the option of different input method different app able change the language when opening remote office app, need change clients , having them logon session host in not option. couldn't figure how change default settings user profiles while logging rds farm i saw thread  http://social.technet.microsoft.com/forums/windowsserver/en-us/9b198ee1-7da1-46e8-b5e5-9f09aa7eac40/keyboard-layout?forum=winservergp  and wondering if true server 2012? (i don't editing default profile users wanted @ least right? ) thanks, shlomi hi eventually  i found option copy l anguage settings default profile from advanced setting of region in control panel it solved problem, posted here in case else problem Windows Server ...

List users with default password

is possible list users default password? we have policy allows create users default password (e.g. "pass123") , users not obligated change it. windows server 2008 r2, password are not stored in reversible encryption. idea: encrypt "pass123" , compare encrypted password of user. $password = 'pass123' add-type -assemblyname system.directoryservices.accountmanagement $ds = new-object system.directoryservices.accountmanagement.principalcontext("domain") get-aduser -filter * | foreach { new-object psobject -prop @{ name = $_.name sam = $_.samaccountname default = $ds.validatecredentials($_.samaccountname, $password) } } Windows Server  >  Windows PowerShell

Calendar permission cleanup

alright i'm still kinda new powershell game i've been working on creating user termination script , add calendar cleanup potion it. thinking below work. major issue amount of time takes process (especially when doing bulk user cleanup). function calusercleanup{ $calusers = get-mailboxfolderpermission user@company.com:\calendar | select user foreach($user in $calusers){get-aduser -filter * -properties *| displayname -like $user.'user' | select userprincipalname} } $access = calusercleanup foreach ($user in $access){ remove-mailboxfolderpermission -identity user@company.com:\calendar -user $user.userprincipalname -accessrights fullaccess -inheritancetype -confirm:$false -erroraction silentlycontinue -warningaction silentlycontinue} any tips or can provide appreciated. get-mailboxfolderpermission user@company.com:\calendar | {$_.user.displayname -ne 'default' -and $_.user.displayname -ne 'anonymous'} | foreach { ...

嗨,你好

如果诊断出为刚才您提到的问题,该采用什么样的方式进行解决呢?谢谢了先 hi, please understand forum geared answer questions regarding product of english version. regarding products of other languages, local support can better resource troubleshooting. suggest post in appropriate newsgroup ensure issue can resolved in timely manner. for convenience, i’ve included link of newsgroup home page: http://www.microsoft.com/communities/newsgroups/en-us/default.aspx?guid=1080912a-26c5-7040-afdd-2224a4feb3ea in addition, can contact microsoft customer support service instant assistance. obtain phone numbers specific technology request, please click following link , select location under contact information: http://www.microsoft.com/worldwide/ thanks. Windows Server  >  Directory Services ...

URGENT---->ASSISTANCE ABOUT GROUP POLICIES..

help me plz... building active directory architecture office ((((*** using windows server 2008 r2 ***))))and ve around 30 computers. have 3 subnets each having 10 computers. ve created 3 usernames 3 subnets , want users of subnet 1 should unable access shared folders of computers of subnet 2 & 3. if m member of subnet 1 n try access computer of subnet 2 or 3 network places should give error "access denied " or something. so if assist me group policies need set serve purpose. plz me need d soln asap... thanks all am 27.11.2011 10:16, schrieb cheetu: plz me need d soln asap... read answers, can not helped, if not this. if asap on weekend, buy consulting. mark mark heitbrink - mvp windows server - group policy homepage:       www.gruppenrichtlinien.de - deutsch gpo tool:       www.reg2xml.com - registry export file converter networktraytool www.gruppenrichtlinien.de/tools/networktraytool.htm ...

client traffic between parent and child domain

what expected traffic (and why generated) between hosts parent child domain (and vice versa)?  i understand these ports hit between domain controllers (https://technet.microsoft.com/en-us/library/dd772723(ws.10).aspx) seeing traffic on ports 389/626/500 between parent domain clients , child dcs.  why clients talking way , expected? hi, thanks post. >why clients talking way , expected? active directory communication takes place using several ports. these ports required both client computers , domain controllers. example, when client computer tries find domain controller sends dns query on port 53 find name of domain controller in domain. udp port 389 ldap handle normal queries client computers domain controllers. tcp port 636  directory, replication, user , computer authentication, group policy, trusts please check articles more details. http://blogs.msmvps.com/acefekay/2011/11/01/active-directory-firewall-ports-let-s-try-to-make-this-simple/ https...

macro to spell check entire document

i'm ocr-ing doc , there lot of spelling errors.  need macro replace words first option spell check proposes.  need macro separates superscripts words space, since word superscript count misspelled word , it's not.   i need macro ignore words capitalized.   also, wrong with <cite> answers . microsoft .com</cite> that website not working.  wanted post question there didn't work, have use website. this should it: sub spelling2() dim wd as range dim oldtxt as string dim newtxt as string dim sugg as spellingsuggestions dim addspace as string application.screenupdating = false for each wd in activedocument.words oldtxt = wd.text if not application.checkspelling(word:=oldtxt, ignoreuppercase:= true ) then set sugg = application.getspellingsuggestions(oldtxt) if sugg. count <> 0 then newtxt = application.getspellingsuggestions(oldtxt).item(1) if right(o...

Windows Server R2 RAID-5 Synchronization (Long Resync time)

hello!  i setup dell pe410t server has 6 (2x500gb 4x2tb) drives using windows server 2008 r2 sp1. unfortunately card came sas card instead of perc card. unaware of difference tween 2 , dell rep never pointed out.. surprise surprise. sas wont raid5. work around configured hardware mirroring system drives , decided use windows software raid5 4x2tb drives. due client demands had roll-out server before initial sync completed. find sync keeps having rebuild after each reboot. it's brand new there no disk failure problems. is there way speed process? seeing performance hit. machine quad-core xeon , overhead @ 25% on disks @ moment. noticed it's taking an exorbitant amount of time sync.. days 25%. normal? rob holmes something wrong happens during reboots. in other words - system not think shut down correctly , resync every time. fix before finding out what's broken resync time (you're right - it's much). start seeing what's inside event log. system ...

Windows 2008 auto restart

i've got windows server 2008 r2 file server . this problem signature , me please   problem signature: problem event name: bluescreen os version: 6.0.6002.2.2.0.272.7 locale id: 2057 additional information problem: bccode: d1 bcp1: 008a0038 bcp2: 00000002 bcp3: 00000000 bcp4: 8e6bb031 os version: 6_0_6002 service pack: 2_0 product: 272_2 files describe problem: c:\windows\minidump\mini030411-01.dmp c:\users\administrator\appdata\local\temp\1\wer-102782241-0.sysdata.xml c:\users\administrator\appdata\local\temp\1\wer9980.tmp.version.txt     hi,   please understand troubleshoot auto-restarting issues, need perform debugging. however, in forum, not provide debugging support. if perform debugging, please contact microsoft customer support service (css).   to obtain phone numbers specific technology request, please refer website listed below: http://support.microsoft.com/default.aspx?scid=fh;en-us...

[DNS] Starts then stops.

good morning/afternoon, when installing active directory, in dns configuration phase, it couldn't contact rpc. rpc fine though. noticed when dns server starts, stops few seconds after, no error shown in event viewer. log name: dns server source: microsoft-windows-dns-server-service date: 1/21/2013 8:09:47 pm event id: 3 task category: none level: information keywords: classic user: n/a computer: _______________ description: dns server has shut down. event xml: <event xmlns="http://schemas.microsoft.com/win/2004/08/events/event"> <system> <provider name="microsoft-windows-dns-server-service" guid="{71a551f5-c893-4849-886b-b5ec8502641e}" eventsourcename="dns" /> <eventid qualifiers="16384">3</eventid> <version>0</version> <level>4</level> <task>0</task> <opcod...

HOWTO Addd/Modify DVD/CD/Disks to a Virtual Machine and get a VM's IP Address.

howto addd/modify dvd/cd/disks virtual machine , vm's ip address. i posted these questions in c#/.net forum also. please direct me correct forum. i'm coding c#/.net , wmi. want list of dvd/cd/disk devices hyper-v server has, , add/remove/modify them given virtual machine (vm). i want able vm's ip address(es) if has any. in task, vm may not running, , thus, not ip addresses, , may running have no network, or may have multiple networks. there many scripting examples floating around. taylor brown did bit of around time of hte origional release: http://blogs.msdn.com/taylorb/ he has quite few wmi examples. in regards ip address, must query vm os itself, scvmm, or use kvp integration components.  can query dns. the host not configure ip address, has no record of ip address of vm - scvmm queries , adds scvmm database, hyper-v not. brian ehlert (hopefully have found useful) Windows Server ...

Viewing VMs in Server Core

if load/install virtual machines, windows 7 or windows server on windows server2008 r2 core , use scvmm manage vms, can open , view vms on server core machine. hi,   windows server 2008 r2 core installation doesn’t include console view hyper-v virtual machines. need manage vms remote computer hyper-v manager or scvmm installed.     best regards, vincent hu   Windows Server  >  Server Core

Connecting to RDS Collection with Palo Alto FW issue

we have small 2012 r2 remote desktop services environment set has been working perfectly.  recently needed add additional server collection accommodate additional load.  this worked fine of people had connecting except 1 location.  that location reason cannot connect published application session when gateway sends them second server.  we have worked client , seems issue palo alto networks firewall.  when connect outside of firewall can connect either server in collection fine.  however when behind firewall unable connect second server.   it seems clear me issue on end working other clients, client has worked directly palo alto networks , claim cannot figure out why not working.   is there missing? hi, please ensure ports required rds open. rds 2012: ports used during deployment? https://social.technet.microsoft.com/wiki/contents/articles/16164.rds-2012-which-ports-are-used-during-deployment.aspx as third party firewall should ...