- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
Enhanced Security Measures in Place: To ensure a safer experience, we’ve implemented additional, temporary security measures for all users.
08-19-2021 06:58 AM
Good morning, thank you very much for your support.
I have the following problem.
I have a PA-220 equipment, connected to the Internet via a 200mb symmetrical Adsl link.
Scenario:
PanOS 10.0.6
Globalprotect clients 5.2.7 ( win 10 )
PA-220 ---NAT1:1---Router/modem-adsl---dynamic public IP---fqdn DynDNS.
I have configured global protect for rdp connections, using Ipsec.
The connection is established correctly, the problem is they very slow connections via RDP.
Apply QoS, leave only one policy for RDP with only the IPS security profile.
If I open a Dnat (for security not recommended) and if I do RDP via internet pointing to the Dyndns FQDN I don't have the slowness problems.
I added both UDP and TCP for policy permission RDP.
Please your support on how to remedy this.
Thank you, best regards.
08-24-2021 09:25 AM
Hello
Please describe "slowness", as this is a subjective word. What is slow to you? The painting of the screen, transferring files, mouse movement, etc?
What does your VPN configuration look like? Are you using the default Phase1and Phase2 VPN configurations? Have you disabled PFS from the Phase2. You are working with a PA220 (no hardware for decryption) on top of 10.x software (which can slow down the PA220) and VPN configurations that we do not know how strong the settings are.
Provide additional information, and we can continue from there.
Thanks.
08-24-2021 02:33 PM
There's actually a lot of topics on this forum around this problem if you search for it. Do you actually just experience "slowness" or does RDP actually freeze up while you are using it? Do you have a security profile applied to the rule allowed the traffic?
If you're running into freezing, we've found that setting the UseURCP DWORD up helps substantially with it. To do so as a test you can simply running the following on an Admin command prompt on the machine that you are remoting into:
REG ADD "HKLM\SOFTWARE\Microsoft\Terminal Server Client" /v UseURCP /t REG_DWORD /d 0 /f
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!