SOLVED

2019 RDWebClient, RDS Published Apps - missing something, just not sure where

%3CLINGO-SUB%20id%3D%22lingo-sub-1279014%22%20slang%3D%22en-US%22%3E2019%20RDWebClient%2C%20RDS%20Published%20Apps%20-%20missing%20something%2C%20just%20not%20sure%20where%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1279014%22%20slang%3D%22en-US%22%3E%3CP%20class%3D%22_1qeIAgB0cPwnLhDF9XSiJM%22%3EUniversity%20setting%2C%20VMWare%20%26amp%3B%20Microsoft%3C%2FP%3E%3CP%20class%3D%22_1qeIAgB0cPwnLhDF9XSiJM%22%20data-unlink%3D%22true%22%3EInternal%20domain%3CSPAN%3E%26nbsp%3B%3C%2FSPAN%3Elocal.name.edu%26nbsp%3B%3CSPAN%3E%26nbsp%3B%3C%2FSPAN%3Eexternal%20domain%3CSPAN%3E%26nbsp%3B%3C%2FSPAN%3Ename.edu%26nbsp%3B%3C%2FP%3E%3CP%20class%3D%22_1qeIAgB0cPwnLhDF9XSiJM%22%20data-unlink%3D%22true%22%3ESetup%202019%20server%3CSPAN%3E%26nbsp%3B%3C%2FSPAN%3Evapps-01.local.name.edu%26nbsp%3B%3CSPAN%3E%26nbsp%3B%3C%2FSPAN%3Eoutside%20name%3CSPAN%3E%26nbsp%3B%3C%2FSPAN%3Evapps.name.edu%26nbsp%3B%3CSPAN%3E%26nbsp%3B%3C%2FSPAN%3Egoing%20through%20Barracuda%20load%20balancer%20as%20a%20proxy.%20using%20a%20wildcard%20cert%20*.name.edu%20(vapps-01.local.name.edu%26nbsp%3B%3CSPAN%3E%26nbsp%3B%3C%2FSPAN%3Eas%20SAN)%20and%20applied%20down%20the%20line.%20Thumbprints%20checked%20and%20verified.%3C%2FP%3E%3CP%20class%3D%22_1qeIAgB0cPwnLhDF9XSiJM%22%20data-unlink%3D%22true%22%3Efrom%20browser%2C%20can%20open%3CSPAN%3E%26nbsp%3B%3C%2FSPAN%3E%3CA%20href%3D%22https%3A%2F%2Fvapps.name.edu%26nbsp%3B%22%20target%3D%22_blank%22%20rel%3D%22nofollow%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%22%3Ehttps%3A%2F%2Fvapps.name.edu%26nbsp%3B%3C%2FA%3E%3CSPAN%3E%26nbsp%3B%3C%2FSPAN%3Ethat%20is%20redirected%20to%3CSPAN%3E%26nbsp%3B%3C%2FSPAN%3E%3CA%20href%3D%22https%3A%2F%2Fvapps.name.edu%2Frdweb%2Fwebclient%26nbsp%3B%22%20target%3D%22_blank%22%20rel%3D%22nofollow%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%22%3Ehttps%3A%2F%2Fvapps.name.edu%2Frdweb%2Fwebclient%26nbsp%3B%3C%2FA%3E%3CSPAN%3E%26nbsp%3B%3C%2FSPAN%3Eand%20connects%20to%3CSPAN%3E%26nbsp%3B%3C%2FSPAN%3Evapp-01.local.name.edu%2Frdweb%2Fwebclient%26nbsp%3B%3CSPAN%3E%26nbsp%3B%3C%2FSPAN%3Eand%20comes%20up%20with%20login%20credentials.%20Can%20login%20using%20local%5Cname%20and%20password.%3C%2FP%3E%3CP%20class%3D%22_1qeIAgB0cPwnLhDF9XSiJM%22%3EBrings%20up%20console%20with%20applications%20and%20when%20application%20is%20selected%2C%20%22opening%20remote%20port%22%2C%20%22Configuring%20remote%20port%22%20and%20dies%20there.%20%22Oops%2C%20we%20couldn't%20connect%20to%20%22app%22%20The%20connection%20to%20the%20remote%20PC%20was%20lost%2C%20This%20might%20be%20because%20of%20a%20network%20connection%20problem.%20If%20this%20keeps%20happening%2C%20ask%20your%20admin%20or%20tech%20support%20for%20help.%22%3CBR%20%2F%3EWell%2C%20**bleep**.%20That's%20me.%3CBR%20%2F%3EAs%20far%20as%20I%20can%20tell%2C%20the%20app%20is%20opening%20an%20RDP%20connection%20on%20port%203392%2C%20which%20is%20open%20in%20firewall%20and%20has%20SSL%20cert%20attached%20to%20it%20but%20the%20connection%20is%20failing.%3C%2FP%3E%3CP%20class%3D%22_1qeIAgB0cPwnLhDF9XSiJM%22%3EI%20am%20hoping%20someone%20out%20there%20has%20had%20this%20happen%20to%20them%20and%20they%20know%20what%20check%20box%20I%20missed%20or%20link%20I%20need%20to%20change.%26nbsp%3B%3C%2FP%3E%3CP%20class%3D%22_1qeIAgB0cPwnLhDF9XSiJM%22%3EWireshark%20makes%20it%20appear%20as%203389%20is%20dropping%20session%20with%20a%20RST%2C%20ACK%20Maybe%20that%20is%20issue.%20Could%20be%20DNS%2C%20Could%20be%20needing%20a%20gateway...%20Hopefully%20someone%20has%20experience%20with%202019%20now%3F%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1307950%22%20slang%3D%22en-US%22%3ERe%3A%202019%20RDWebClient%2C%20RDS%20Published%20Apps%20-%20missing%20something%2C%20just%20not%20sure%20where%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1307950%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F608140%22%20target%3D%22_blank%22%3E%40McGentrix%3C%2FA%3E%26nbsp%3Bhi%20-%20for%20VMware%20deployments%20it%20might%20be%20best%20to%20loop%20in%20VMware%20-%20or%20use%20their%20support%20platforms.%20Thanks.%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1310023%22%20slang%3D%22en-US%22%3ERe%3A%202019%20RDWebClient%2C%20RDS%20Published%20Apps%20-%20missing%20something%2C%20just%20not%20sure%20where%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1310023%22%20slang%3D%22en-US%22%3E%3CP%3EFor%20some%20reason%2C%26nbsp%3B%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F139744%22%20target%3D%22_blank%22%3E%40Eva%20Seydl%3C%2FA%3E%26nbsp%3Bmarked%20this%20as%20the%20best%20answer%3F%20This%20is%20no%20answer%20so%20for%20it%20to%20be%20marked%20best%20answer%20is%20no%20good.%20What%20would%20VMWare%20have%20to%20do%20with%20this%20at%20all%3F%20It%20obviously%20either%20a%20certificate%20issue%20or%20a%20permission%20issue%20with%20Microsoft%20and%20there%20is%20no%20documentation%20or%20guidance%20to%20move%20on.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EWhile%20I%20appreciate%20Pieter's%20effort%2C%20pushing%20this%20off%20as%20a%20VMWare%20issue%20is%20really%20just%20passing%20the%20buck.%20I'm%20not%20looking%20for%20buck%20passing%2C%20but%20help%20or%20answers.%20Problem%20has%20not%20been%20resolved%20or%20answered.%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1310269%22%20slang%3D%22en-US%22%3ERe%3A%202019%20RDWebClient%2C%20RDS%20Published%20Apps%20-%20missing%20something%2C%20just%20not%20sure%20where%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1310269%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F608140%22%20target%3D%22_blank%22%3E%40McGentrix%3C%2FA%3E%26nbsp%3Bit's%20pretty%20difficult%20to%20troubleshoot%20this%20over%20forum%20posts%20especially%20when%20additional%203rd%20party%20components%20(VMware%2FBarracuda%20appliances)%20are%20included%20for%20which%20we%20don't%20own%20the%20code%20nor%20experience.%20Would%20it%20be%20possible%20to%20test%20without%20any%20of%20that%20involved%20using%20a%20basic%20infrastructure%20before%20adding%20proxies%3F%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3ESide%20note%3A%20WVD%20doesn't%20use%203389%20but%20443%20only.%20The%20VM%20creates%20an%20outbound%20443%2FTCP%20connection%20into%20our%20management%20plane%20and%20ties%20the%20connection%20coming%20from%20the%20client.%26nbsp%3B%3C%2FP%3E%0A%3CP%3EThanks%2C%3C%2FP%3E%0A%3CP%3EPieter%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1310382%22%20slang%3D%22en-US%22%3ERe%3A%202019%20RDWebClient%2C%20RDS%20Published%20Apps%20-%20missing%20something%2C%20just%20not%20sure%20where%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1310382%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F608140%22%20target%3D%22_blank%22%3E%40McGentrix%3C%2FA%3E%26nbsp%3B%3A%20Please%20contact%20as%20suggested%20VMWare%20to%20confirm%20this%20is%20not%20a%20bug%20within%20the%20management%20plane.%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EThank%20you!%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1310539%22%20slang%3D%22en-US%22%3ERe%3A%202019%20RDWebClient%2C%20RDS%20Published%20Apps%20-%20missing%20something%2C%20just%20not%20sure%20where%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1310539%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F63584%22%20target%3D%22_blank%22%3E%40Pieter%20Wigleven%20(WINDOWS)%3C%2FA%3E%26nbsp%3BThe%20issue%20is%20repeatable%20inside%20the%20DMZ%20going%20to%20local%20address%20which%20rules%20out%20the%20load%20balancers%20and%20any%20connectivity%20issues.%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1310550%22%20slang%3D%22en-US%22%3ERe%3A%202019%20RDWebClient%2C%20RDS%20Published%20Apps%20-%20missing%20something%2C%20just%20not%20sure%20where%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1310550%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F608140%22%20target%3D%22_blank%22%3E%40McGentrix%3C%2FA%3E%26nbsp%3BIf%20this%20is%20not%20using%20VMware%20you%20can%20could%20use%20PowerShell%20to%20see%20diagnose%20issues%3A%26nbsp%3B%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Fvirtual-desktop%2Fdiagnostics-role-service%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%22%3Ehttps%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Fvirtual-desktop%2Fdiagnostics-role-service%3C%2FA%3E%26nbsp%3B%3CBR%20%2F%3EWe%20see%20this%20error%20a%20lot%20when%20there's%20a%20UPN%20mismatch%20between%20AAD%20and%20AD.%26nbsp%3B%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EIf%20it%20is%20VMware%2C%20we%20are%20unable%20to%20help%20you.%20Apart%20from%20the%20OS%2C%20the%20code%20used%20here%20is%20not%20in%20our%20control.%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1310696%22%20slang%3D%22en-US%22%3ERe%3A%202019%20RDWebClient%2C%20RDS%20Published%20Apps%20-%20missing%20something%2C%20just%20not%20sure%20where%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1310696%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F63584%22%20target%3D%22_blank%22%3E%40Pieter%20Wigleven%20(WINDOWS)%3C%2FA%3E%26nbsp%3BI%20am%20questioning%20now%20if%20you%20even%20read%20the%20problem%20I%20am%20having.%20Go%20back%2C%20read%20the%20OP%20and%20tell%20me%20how%20the%20help%20you%20are%20providing%20is%20helping.%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1311758%22%20slang%3D%22en-US%22%3ERe%3A%202019%20RDWebClient%2C%20RDS%20Published%20Apps%20-%20missing%20something%2C%20just%20not%20sure%20where%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1311758%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F608140%22%20target%3D%22_blank%22%3E%40McGentrix%3C%2FA%3E%26nbsp%3Byour%20opening%20statement%20is%20%22%3CSPAN%3EUniversity%20setting%2C%20VMWare%20%26amp%3B%20Microsoft%22%20so%2C%20are%20you%20using%20VMWare%3F%20You%20have%20also%20posted%20this%20question%20in%20the%20Windows%20Virtual%20Desktop%20community%3A%20are%20you%20using%20WVD%3F%20Is%20it%20VMWare%20integration%20with%20WVD%3B%20or%20neither%3F%3C%2FSPAN%3E%3C%2FP%3E%0A%3CP%3E%3CSPAN%3ETo%20effectively%20troubleshoot%20your%20connectivity%20issue%20the%20best%20approach%20is%20to%20first%20remove%20all%20of%20the%20non-Microsoft%20components%20from%20the%20network%20path%20then%20re-test.%20Your%20description%20also%20suggests%20that%20you%20don't%26nbsp%3Bhave%20an%20RD%20Gateway.%20Do%20you%20have%20all%20of%20the%20components%20required%20for%20a%20fully%20functioning%20RDS%20environment%26nbsp%3B%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fwindows-server%2Fremote%2Fremote-desktop-services%2Fdesktop-hosting-logical-architecture%23standard-rds-deployment-architectures%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%22%3Ehttps%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fwindows-server%2Fremote%2Fremote-desktop-services%2Fdesktop-hosting-logical-architecture%23standard-rds-deployment-architectures%3C%2FA%3E%3C%2FSPAN%3E%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1312572%22%20slang%3D%22en-US%22%3ERe%3A%202019%20RDWebClient%2C%20RDS%20Published%20Apps%20-%20missing%20something%2C%20just%20not%20sure%20where%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1312572%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F204420%22%20target%3D%22_blank%22%3E%40Danny%20Newport%3C%2FA%3E%26nbsp%3B%20%22%3CSPAN%3EYou%20have%20also%20posted%20this%20question%20in%20the%20Windows%20Virtual%20Desktop%20community%3A%22%20Well%20that%20explains%20it...%20When%20I%20started%20this%2C%20I%20was%20in%26nbsp%3B%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fwindows-server-for-it-pro%2Fbd-p%2FWindowsServer%22%20target%3D%22_blank%22%3Ehttps%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fwindows-server-for-it-pro%2Fbd-p%2FWindowsServer%3C%2FA%3E%3C%2FSPAN%3E%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%3CSPAN%3EWe%20don't%20even%20use%20WVD%20so%20this%20should%20not%20be%20in%20this%20community.%26nbsp%3B%3C%2FSPAN%3E%3C%2FP%3E%3C%2FLINGO-BODY%3E
Highlighted
Occasional Contributor

University setting, VMWare & Microsoft

Internal domain local.name.edu  external domain name.edu 

Setup 2019 server vapps-01.local.name.edu  outside name vapps.name.edu  going through Barracuda load balancer as a proxy. using a wildcard cert *.name.edu (vapps-01.local.name.edu  as SAN) and applied down the line. Thumbprints checked and verified.

from browser, can open https://vapps.name.edu  that is redirected to https://vapps.name.edu/rdweb/webclient  and connects to vapp-01.local.name.edu/rdweb/webclient  and comes up with login credentials. Can login using local\name and password.

Brings up console with applications and when application is selected, "opening remote port", "Configuring remote port" and dies there. "Oops, we couldn't connect to "app" The connection to the remote PC was lost, This might be because of a network connection problem. If this keeps happening, ask your admin or tech support for help."
Well, **bleep**. That's me.
As far as I can tell, the app is opening an RDP connection on port 3392, which is open in firewall and has SSL cert attached to it but the connection is failing.

I am hoping someone out there has had this happen to them and they know what check box I missed or link I need to change. 

Wireshark makes it appear as 3389 is dropping session with a RST, ACK Maybe that is issue. Could be DNS, Could be needing a gateway... Hopefully someone has experience with 2019 now?

9 Replies
Highlighted
Best Response confirmed by Eva Seydl (Microsoft)
Solution

@McGentrix hi - for VMware deployments it might be best to loop in VMware - or use their support platforms. Thanks.

Highlighted

For some reason, @Eva Seydl marked this as the best answer? This is no answer so for it to be marked best answer is no good. What would VMWare have to do with this at all? It obviously either a certificate issue or a permission issue with Microsoft and there is no documentation or guidance to move on.

 

While I appreciate Pieter's effort, pushing this off as a VMWare issue is really just passing the buck. I'm not looking for buck passing, but help or answers. Problem has not been resolved or answered.

Highlighted

@McGentrix it's pretty difficult to troubleshoot this over forum posts especially when additional 3rd party components (VMware/Barracuda appliances) are included for which we don't own the code nor experience. Would it be possible to test without any of that involved using a basic infrastructure before adding proxies?

 

Side note: WVD doesn't use 3389 but 443 only. The VM creates an outbound 443/TCP connection into our management plane and ties the connection coming from the client. 

Thanks,

Pieter

Highlighted

@McGentrix : Please contact as suggested VMWare to confirm this is not a bug within the management plane.

 

Thank you!

@Pieter Wigleven (WINDOWS) The issue is repeatable inside the DMZ going to local address which rules out the load balancers and any connectivity issues.

Highlighted

@McGentrix If this is not using VMware you can could use PowerShell to see diagnose issues: https://docs.microsoft.com/en-us/azure/virtual-desktop/diagnostics-role-service 
We see this error a lot when there's a UPN mismatch between AAD and AD. 

 

If it is VMware, we are unable to help you. Apart from the OS, the code used here is not in our control.

 

 

Highlighted

@Pieter Wigleven (WINDOWS) I am questioning now if you even read the problem I am having. Go back, read the OP and tell me how the help you are providing is helping. 

Highlighted

@McGentrix your opening statement is "University setting, VMWare & Microsoft" so, are you using VMWare? You have also posted this question in the Windows Virtual Desktop community: are you using WVD? Is it VMWare integration with WVD; or neither?

To effectively troubleshoot your connectivity issue the best approach is to first remove all of the non-Microsoft components from the network path then re-test. Your description also suggests that you don't have an RD Gateway. Do you have all of the components required for a fully functioning RDS environment https://docs.microsoft.com/en-us/windows-server/remote/remote-desktop-services/desktop-hosting-logic...

Highlighted

@Danny Newport  "You have also posted this question in the Windows Virtual Desktop community:" Well that explains it... When I started this, I was in https://techcommunity.microsoft.com/t5/windows-server-for-it-pro/bd-p/WindowsServer

 

We don't even use WVD so this should not be in this community.