EventID 4625 (NULL SID) when trying to establish RDP connection over port forwarding firewall


hi,

i created environment ipcop firewall. goal establish rdp connection terminal server (ip 192.168.70.12) on (green) side of firewall client on bad (red) side of firewall. make possible create port forwarding rule in firewall, forwards port 7012 port 3389.

now try build connection client terminal server mstsc , address 10.0.14.118:7012 (10.0.14.118 red ip address of firewall). when try this, following message:

"login failure: user account restriction. possible reasons blank passwords not allowed, logon hour restrictions, or policy restriction has been enforced".

in eventlog of terminal server following event:

an account failed log on.

subject:
 security id:  null sid
 account name:  -
 account domain:  -
 logon id:  0x0

logon type:   3

account logon failed:
 security id:  null sid
 account name:  dkoenig_adm
 account domain:  imagoverum

failure information:
 failure reason:  unknown user name or bad password.
 status:   0xc000006e
 sub status:  0xc000006e

process information:
 caller process id: 0x0
 caller process name: -

network information:
 workstation name: dkoenig-laptop
 source network address: -
 source port:  -

detailed authentication information:
 logon process:  ntlmssp
 authentication package: ntlm
 transited services: -
 package name (ntlm only): -
 key length:  0

what goes wrong here, can solve issue? rdp session works perfectly, when open connection client within green network , same credentials.

thanks in advance

regards
dave


hi,

i created environment ipcop firewall. goal establish rdp connection terminal server (ip 192.168.70.12) on (green) side of firewall client on bad (red) side of firewall. make possible create port forwarding rule in firewall, forwards port 7012 port 3389.

now try build connection client terminal server mstsc , address 10.0.14.118:7012 (10.0.14.118 red ip address of firewall). when try this, following message:

"login failure: user account restriction. possible reasons blank passwords not allowed, logon hour restrictions, or policy restriction has been enforced".

in eventlog of terminal server following event:

an account failed log on.

subject:
 security id:  null sid
 account name:  -
 account domain:  -
 logon id:  0x0

logon type:   3

account logon failed:
 security id:  null sid
 account name:  dkoenig_adm
 account domain:  imagoverum

failure information:
 failure reason:  unknown user name or bad password.
 status:   0xc000006e
 sub status:  0xc000006e

process information:
 caller process id: 0x0
 caller process name: -

network information:
 workstation name: dkoenig-laptop
 source network address: -
 source port:  -

detailed authentication information:
 logon process:  ntlmssp
 authentication package: ntlm
 transited services: -
 package name (ntlm only): -
 key length:  0

what goes wrong here, can solve issue? rdp session works perfectly, when open connection client within green network , same credentials.

thanks in advance

regards
dave



Windows Server  >  Remote Desktop Services (Terminal Services)



Comments

Popular posts from this blog

DCOM received error "2147746132" from...

DFSR RPC replication errors 5014 1726 with large files over VPN

ADFS 3.0 Event ID 4625 | An Error occurred During Logon | Status: 0xC000035B