Forum Discussion
Bob_10976
Nimbostratus
Mar 27, 2008Can't use Remote Desktop to Web Servers
Just to let you know I did't set this up, I pretty much inherited everything and on top of that I'm a bit new to BigIP.
I cannot use remote desktop, (RDP) to connect to my webservers behind the F5 load balancer, running 9.3.0, when we use our VPN client. I can use RDP from web server to web server.
The web servers have the Bigip set as thier default gateway and all web services are working just fine. If i'm leaving any important details out please let me know.
Thanks in advance,
Bob
- dennypayne
Employee
BIG-IP is a default deny box, so if it isn't configured to pass specific traffic, it won't. So there needs to be either a NAT that directly maps an external address to each internal webserver that you want to connect to, or a forwarding virtual server that allows the BIG-IP to route traffic to its internal network. - Bob_10976
Nimbostratus
Denny, - The_Bhattman
Nimbostratus
The wilcard 0.0.0.0 port 0 Virtual Forwarding IP is one part of it. - dennypayne
Employee
If you apply the fwd vip to all VLAN's, then anybody coming in to the front side of BIG-IP can get forwarded to the internal network, and any server on the inside can also initiate connections outbound to any destination. If you don't want to allow outbound connections then you could only enable the forwarder on the external VLAN. It basically depends on what your definition of "safe" is as to how granular you want to be about that. :-) - The_Bhattman
Nimbostratus
Well said. Also, if you want to verify whether traffic is actually going back and forth then I suggest you use "tcpdump -ni host on the cmd line on the F5. - Deb_Allen_18Historic F5 AccountIf you don't want to allow outbound connections then you could only enable the forwarder on the external VLAN.
- Deb_Allen_18Historic F5 Account(edited last post to actually make sense...)
Recent Discussions
Related Content
DevCentral Quicklinks
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com
Discover DevCentral Connects