FortiGate
FortiGate Next Generation Firewall utilizes purpose-built security processors and threat intelligence security services from FortiGuard labs to deliver top-rated protection and high performance, including encrypted traffic.
KumarV
Staff
Staff
Article Id 274078
Description

This article describes how to allow RDP from a PC to a Windows Domain Controller using a non-Admin user

 

Topology: 

The below topology diagram is used, where both the Domain controller and PC are behind the two different FortiGates, and FG1 and FG2 are connected with point-to-point connection:

 

PNG1.PNG

 

In the Scenario below, it is located on the PC side and is trying to take the RDP to the Domain Controller using the User named User1 which is a non-Admin User.

 

PNG3.PNG

 

It is ended up with an error mentioned in the screenshot below:

 

PNG2.PNG

Scope FortiGate.
Solution

The basic sniffer depicts that the reset packets are sent by the Domain controller. 10.10.2.2 is sending rst + ack, which basically means that 10.10.10.2 sent the reset first.

 

PNG4.PNG

 

  1. On Domain Controller, make sure that User1 must be part of the policy 'Allow log on through remote Desktop Services'. This setting needs to be done for both Admin and non-Admin users.

 

png5.PNG

 

  1. For Non-Admin access for RDP, add User1 under the Remote Desktop Users under This PC-> Properties-> Remote Settings -> Select Users -> Add -> User1.

                                                                                                                                       PNG6.PNG

 

PNG7.PNG                                                                                                                     

After adding User1, it would be possible to do the RDP from non-admin users:

 

PNG8.PNG

 

Contributors