DrayTek UK Users' Community Forum

Help, Advice and Solutions from DrayTek Users

Not enough Port Forwarding

  • paul ambrose
  • Topic Author
  • User
  • User
More
24 Mar 2020 19:54 #1 by paul ambrose
Not enough Port Forwarding was created by paul ambrose
Hi
I'm trying to set up 30 port forwards on a 2830, am i limited to 20 and if so is there a way round it?

Please Log in or Create an account to join the conversation.

  • hornbyp
  • User
  • User
More
25 Mar 2020 00:13 #2 by hornbyp
Replied by hornbyp on topic Re: Not enough Port Forwarding
If they are really just Port Forwards, i.e. you just want to specify the target host, but keep the same Port no., you can use "NAT >> Open Ports" instead of "NAT >> Port Redirection".

"Been there, got the T-Shirt", as the saying goes :)

Please Log in or Create an account to join the conversation.

  • paul ambrose
  • Topic Author
  • User
  • User
More
25 Mar 2020 08:24 #3 by paul ambrose
Replied by paul ambrose on topic Re: Not enough Port Forwarding
What i'm trying to achieve is to RDP into 25 Windows 10 pc's. so I have assigned a public port forward for each pc and need to forward it to 3389 and the ip of the pc.
Were using Duo for MFA to protect the RDP as much as possible.

Please Log in or Create an account to join the conversation.

  • paul ambrose
  • Topic Author
  • User
  • User
More
25 Mar 2020 08:28 #4 by paul ambrose
Replied by paul ambrose on topic Re: Not enough Port Forwarding
Just re reading your answer, if i kept the public and private ports all the same say 3389 could I use open ports to direct to individual ip's?
As i'm using MFA I feel reasonably happy about RDP security.

Many thanks for your help

Please Log in or Create an account to join the conversation.

  • hornbyp
  • User
  • User
More
25 Mar 2020 13:09 #5 by hornbyp
Replied by hornbyp on topic Re: Not enough Port Forwarding
ah ... I see.

To use "Open Ports", you'd have to reconfigure the individual target machines to listen on the same port number as you have assigned for the remote client to use. I suppose, you can mix and match schemes, i.e. just do this for the ones that won't fit into the "Port Redirection" list. Not the best solution from an administrative point-of-view, but should work.

I vaguely recall that Remote Desktop Gateway Server is the 'proper' answer to this - though it would take more setting up. (First link I found: https://turbofuture.com/computers/What-is-Remote-Desktop-Gateway-and-how-to-install )

To my mind, the easiest solution would be to configure "Remote Dial-in Users" and connect the remote clients by VPN; then they can RDP anywhere. The 2830 allows 32 accounts, before you have to start sharing them. It also claims to support 32 concurrent VPN connections.

You might also consider the "SSL Application" approach. To quote the manual: "It provides a secure and flexible solution for network resources, including VNC (Virtual Network Computer) / RDP (Remote Desktop Protocol)/SAMBA, to any remote user with access to Internet and a web browser)".

I remember trying it and getting it to work for a single RDP client, but I decided Remote Dial-in was more flexible. ISTR that it uses an Active-X control to implement the RDP client and this may well cause 2020's Web Browsers to have a minor melt-down...)

Please Log in or Create an account to join the conversation.