Downfall - "Droppin bombs since '04"

  • home
  • forums
  • gallery
  • calendar
  • handbook
  • tracker
Home › Forums › World of Warcraft General › Everything Else

Remote Desktop

karlizeth's picture

karlizeth — Wed, 08/27/2008 - 17:00

I was hoping I could get pointed to a tutorial for helping me set up the ability to do remote desktop on computers at other locations for my work. I have figured out how to do remote desktop on all the other computers physically located in the same building as me, and these computers are also part of the same workgroup. I now need to be able to connect to computers located off-site. Here's the details:

My computer:

  • Running Windows XP Pro
  • Part of a named Workgroup, not a Domain
  • Connected to a server at the same location which manages our internet access, some file storage, and a microsoft access database
  • Connection to the MS Access Database is through an SQL Server ODBC configuration, which I manage
  • IP Addresses are dynamic, assigned by DHCP

Off-site computers:

  • Running Windows XP Pro
  • Many computers have multiple users, all with one common user called "Admin."
  • Most staff members have limited accounts.
  • All these computers have an existing connection to our MS Access Database through a vpn connection
  • I believe each of the locations have their own router, but none of them are on a separate server
  • I believe the computers have dynamic IP addresses (or at least the majority of them do)
  • These computers may or may not also be on their own workgroup (none have domains)

The server at my location is the common thread; I also manage the users for the whole agency on this server. 
I'm running in to a few road blocks because the few tutorials I'm finding only tend to apply to what I've already got working (remote connection to named computers w/in the same Workgroup at the same location), or to computers with static IP addresses.  

I can't think of any more info to include at the moment but feel free to ask me stuff if it can help get me pointed in the right direction.

And, seriously, thanks in advance because this is going to be a HUGE HUGE HUGE time-saver, and my boss is going to love me for it.  You guys rock!!!

‹ LF Blacksmith for Eternium Runed Blade picture caption contest ›
  • Everything Else
  • Login or register to post comments
karlizeth's picture

Thanks again you guys,

karlizeth — Fri, 08/29/2008 - 07:00

Thanks again you guys, awesome info and stuff I'd have a hell of a time trying to learn on my own. Will give the info listed on both of the above two posts a whirl today; also giving router config part 2 a shot (as mentioned in nessence's original post) a try later this afternoon.

  • Login or register to post comments
Agoney's picture

If its Cisco, i gurantee its

Agoney — Thu, 08/28/2008 - 21:37

If its Cisco, i gurantee its some type of ACL mismatch (well, mismatch in a sense that only one network can fully see the other. It's actually more secure this way, in a sense).

Your best bet is UltraVNC imo. It works on vista, and you can re-configure the port its accepted on (Dufe explained this above). It's free, relatively easy to install, and all you need is either the PC name or pc IP address. Of course, you will have to be able to see the remote computers on your network for this to occur. (IE, access list allows you to view them).

  • Login or register to post comments
Dufe's picture

A quick run-down for

Dufe — Thu, 08/28/2008 - 20:53

A quick run-down for ya:

Every different application that uses tcp should be trying to communicate on a different port number.  These port numbers are basically a way of letting the computers know which application on the source/destination a particular data packet is supposed to be going to/coming from.  Security settings on routers/firewalls are often configured to only allow traffic on certain ports.

In your case, it sounds like the ports used for certain network functions are open, while the one used by RDT is blocked.  If this is the case, you may have to re-configure routers/firewalls to allow traffic on that port.  Sometimes Windows Firewall/other firewall software on the PC itself also blocks this by default.  I don't think RDT can be configured to run on a different port, but my memory says that some of the other software options can - just don't remember which ones.

  • Login or register to post comments
karlizeth's picture

I should mention that at

karlizeth — Thu, 08/28/2008 - 20:42

I should mention that at some point, when my boss was at a remote location working on a computer that had an existing connection to the server at our main office through a vpn, HE was able to remote into MY computer, but I couldn't do the reverse. I then tried to set up the same vpn configuration on my own desktop, which allowed me to locate the computer he was working on via a search (which I couldn't see before). But neither the computer name nor its current IP address would work when I tried to get on it. I wonder, do you think our router could be blocking that type of connection via a firewall? It's a relatively heavy duty cisco router.

Lastly, tonight I'm going to attempt to configure my home router to connect to my work computer. Because I wasn't able to configure any of the routers off-site, I can at least test it out at home to see if it's going to work or not and hopefully save myself some time.

  • Login or register to post comments

Or you could just get a copy

GrayVon — Thu, 08/28/2008 - 18:24

Or you could just get a copy of PCAnywhere ...

Or if your looking for a freebie, Try LogMeIn.com

  • Login or register to post comments
karlizeth's picture

Ag, I think that might be

karlizeth — Thu, 08/28/2008 - 14:43

Ag, I think that might be next week's task. Things were going great on my end; got everything set up the way it should be, only to discover that between the lady at my office who coordinated the installation of the routers at our other locations and the guy who installed them, 3 out of 4 of our remote locations have no info about the logins for the router. Their answer was "oh, gee, I thought we had taped the login info to the bottom of the router." So, at all but 1 location we can't access the router w/o resetting it, and nobody on my staff has time to do that right now. All because no one thought to write down some fucking user names and passwords.....swell.

  • Login or register to post comments
Agoney's picture

Still saying VNC would be

Agoney — Thu, 08/28/2008 - 09:42

Still saying VNC would be the easiest! :P

  • Login or register to post comments
karlizeth's picture

Carno, that looks like a

karlizeth — Wed, 08/27/2008 - 19:38

Carno, that looks like a fantastic solution. Very doable given our current setup. Will tackle one location tomorrow or Friday and see what happens!!!!

  • Login or register to post comments
karlizeth's picture

I'm not sure what you mean

karlizeth — Wed, 08/27/2008 - 19:13

I'm not sure what you mean by "what vpn we use" other than i know it gets pointed to our server as an "vpn.xxxxxxxxx.org" type thing (off the top of my head anyway). I can get into the cisco router at work pretty easily, but I don't know about getting into the router at other locations.

  • Login or register to post comments
karlizeth's picture

Dufe, domain thing is a

karlizeth — Wed, 08/27/2008 - 18:33

Dufe, domain thing is a definite no go. I simply do not have time to make it happen and I'm the only one that could do it. This is what happens when you make your HR person do IT work....

  • Login or register to post comments
nessence's picture

I also just noticed you say

nessence — Wed, 08/27/2008 - 18:17

I also just noticed you say your remote computers connect to the database via VPN.

You could also use that. When the remote computer connects to the VPN it will be assigned an IP address on the VPN. You should be able to remote desktop to that address if you have port 3389 on the remote computer's firewall. Also, if you open the VPN manager (it's called "routing and remote access") on your server you can see the IP addresses the VPN server gives out. The only sucky part about this is that you have to call and ask anyone you want to remote control to connect the VPN.

  • Login or register to post comments
nessence's picture

Karli: You will need to

nessence — Wed, 08/27/2008 - 18:10

Karli:

You will need to change settings on your company's firewall and/or Internet router.

Internet -> Your ISP -> Your Router -> [Company Desktops]

Your router should have an ip address which is public - it will be something OTHER than 192.168, 172.,  10.. An example would be 64.233.187.99.

This address is the address on your router, on the port which connects to your ISP. The other addresses will be on the Internal port of your router. For example, your desktop IP address maybe 192.168.0.65.

It will be the same scenario at each location. All of the desktops behind the router are on the same 'network' and will have similar IP addresses - as you've stated - assigned dynamically. This is why at your office you can connect to all the other desktops - they are on the same network as your computer. The remote computers are on a different network so you can't get to them. The desktop networks are likely 'private' networks and that's why you can't get from one to the other. If your desktops are not using public IP addresses then you have other problems (ie, let's talk about that if it's the case :) ).

The simplest solution is to setup a 'host' remote desktop workstation at each remote site. This could be an existing computer. This requires going into the router/firewall at each remote location and forwarding port 3389 on the router to the IP address of the 'host'. The 'host' needs to have a static private IP address. You will want to write down the public IP address for each public router. The best way to check out how to setup your internet router or firewall for this is to look in the manual under "port mapping", possibly in a section about NAT. Once configured, your router will basically forward all traffic to/from port 3389 on the 'host' desktop to whatever connects to port 3389 on the public IP address of the router. With this setup, you can open remote desktop on your workstation, enter the public IP address of a remote office router, and connect to that remote office's 'host' desktop. What you do from here is to then run remote desktop client on the 'host' computer and use *that* computer to connect to the rest of the computers in that office. Yes, you're basically piggy-backing off the 'host' computer. Also, any firewall software (windows, zonealarm, symantec, etc.) on the remote office computers will need to have an 'exception' added for port 3389. You should be able to google/helpfile this with the words firewall exception.

The remote office network must have different private IP addresses from your home office. If not, it won't work properly. If this is the situation, the easiest thing to do would be to change the IP address network in your home office (as opposed to ALL the remotes).

There are other ways to do this but they get complicated and/or expensive.

The last option is to install MSN messenger on every desktop and use the 'remote assistance' feature. I'm pretty sure that's what it's called... however, you rmileage may vary as to how reliable this works through your firewall. Another option is to use paid for service like gotomypc.com. Gotomypc.com is owned by Citrix so they likely have a good product. I haven't used it and don't know what it costs but it's still an option.

Here is how to open firewall exception if you just use Windows XP Firewall, as long as an overview of what you'll be doing:

http://support.microsoft.com/default.aspx?scid=kb;en-us;q308127 

 

  • Login or register to post comments

Here is a link that should

runhilan — Wed, 08/27/2008 - 17:34

Here is a link that should help but to sum these up you will need acces to your router/firewall hardware to open ports, if you dont have acces it will never work. Find out what hardware your routers are and you may be able to hack you way in and open the ports needed. Do you know what VPN you use? RDT has the sound of the host computer broadcast on the computer you are on.

http://www.grc.com/nat/nat.htm

  • Login or register to post comments
Dufe's picture

I would very strongly

Dufe — Wed, 08/27/2008 - 17:32

I would very strongly recommend you try to get a domain going for a number of reasons.  It would also make things like RDT a bit easier to manage for someone who is less experiences with networking in general.

  • Login or register to post comments
Agoney's picture

You could try to install

Agoney — Wed, 08/27/2008 - 17:24

You could try to install RealVNC or UltraVNC on each of the computers. UltraVNC is the only one that works on vista machines tho. If you can ping across your network via pc name, that's all you need to have to connection.

You can password protect the connection, as well as designate where the source connection is only allowed from. We have near 1500 computers in my network, and the majority of them have this software on it.

  • Login or register to post comments
karlizeth's picture

Runhilan, I've been to the

karlizeth — Wed, 08/27/2008 - 17:19

Runhilan, I've been to the site you linked before and read through most of the other stuff; I don't quite follow the port stuff though. It kinda goes over my head. I don't understand the significance of it, how I would check to see my current configuration is, etc. I don't get the reference about sound, either. Can you explain a bit?

  • Login or register to post comments

Port 3389 is the only port

runhilan — Wed, 08/27/2008 - 17:14

Port 3389 is the only port you need to open. Windows will attempt to stream sound through User Datagram Protocol (UDP) first. If no port is available for UDP, sound will stream through a virtual channel in Remote Desktop Protocol, which uses port 3389.

And here is a quick RDT tutorial.

http://www.microsoft.com/windowsxp/using/mobility/rdfaq.mspx

  • Login or register to post comments
karlizeth's picture

Each computer has its own

karlizeth — Wed, 08/27/2008 - 17:12

Each computer has its own accounts and security though I think. We use the standards windows login screen, not the one I've seen in bigger companies that have the more formal login screen. Anyone who is an administrator on their computer can add/remove users, change access, etc etc. So yeah, not super secure, I know...
Same thing at both my office and the remote locations, except the remote locations have no server hub.  They use the VPN to dial into the database that lives on XXXXserver here at the main office.

  • Login or register to post comments
karlizeth's picture

Um, well, I know that all

karlizeth — Wed, 08/27/2008 - 17:14

Um, well, I know that all the computers here at the main office are in the workgroup "XXXXNET". (Xs for privacy). However, the server itself has it's own name, "XXXXserver". There is nothing listed in the domain name when you go into computer properties.  When I create connections via ODBC/VPN I have to tell it to point to XXXXserver though. Did that make sense? I am still very weak on networking stuff.

  • Login or register to post comments
Dufe's picture

Do you guys run a domain

Dufe — Wed, 08/27/2008 - 17:04

Do you guys run a domain server?  Or does every computer have it's own seperate computer accounts/security/etc?

  • Login or register to post comments

Comment viewing options

Select your preferred way to display the comments and click "Save settings" to activate your changes.

Random image

Atar wins the simulator

User login

  • Create new account
  • Request new password

Navigation

  • Content
    • Compose tips
    • Blogs
  • Raid Parses
  • The Downfall Handbook
  • Recent posts
  • Search
  • User list
  • Polls

Who's online

There are currently 8 users and 5 guests online.

Online users

  • Luminaire
  • Shihli
  • Desteran
  • Dufe
  • moriella
  • Olorien
  • Rahn
  • karlizeth

Who's new

  • Mortal
  • rembrant
  • Avessar
  • ckross
  • Verticy

Latest image

Fail

  • November, 2008 (133)
  • October, 2008 (242)
  • September, 2008 (300)
  • August, 2008 (352)
  • July, 2008 (370)
  • June, 2008 (590)
  • May, 2008 (475)
  • April, 2008 (481)
  • March, 2008 (428)
  • February, 2008 (684)
  • 1
  • 2
  • next ›
  • last »

Upcoming events

  • Naxx-10:(2 days)
  • Naxx 10man(11 days)
  • Wrath Raid 1 Sign Ups(14 days)
  • Wrath Raid 2 Sign Ups(54 days)
Add to iCalendar
more

Recent comments

  • Back by Christmas.
    2 hours 55 min ago
  • Aight I'll talk to you
    7 hours 5 min ago
  • I view this as kind of a
    8 hours 6 min ago
  • I was always under the
    9 hours 33 min ago
  • Yup   we sure was,    That
    9 hours 59 min ago
  • Use WoWMatrix.
    10 hours 56 sec ago
  • These are the mats per single
    10 hours 13 min ago
  • Grasen and I were just
    10 hours 57 min ago
  • Not to be a massive dick,
    11 hours 5 min ago
  •  I'm going to be raiding on
    11 hours 30 min ago

Active forum topics

  • Curse Client Issue
  • Get Flasked!
  • Caronte new computer
  • Druids - Glyph of Innervate
  • Boomkin and Priest? Inscription Tomes
  • Priest leveling and level 80 specs
  • Fellow Droods
more

Recent blog posts

  • Eric and WoW
  • Climbing a broken ladder!
  • This forward I recieved
  • Hi from Afton!
  • More Pics of Karlibosh (aka Colin)
  • Resto Shammies
  • Rupta's Plans for Wrath
  • Deleyna & Wrath...
  • sic
  • Preparation for entry level Naxxramas
more

Poll

Ablonde Should get a name Change
Agree
50%
Disagree
0%
Who's Ablonde?
17%
<_<
33%
Total votes: 18
  • 7 comments
  • Older polls

WoWInsider

  • WoW Insider on Massively Speaking this week
  • Design a disease timer for DeathKnight.info
  • Living without General chat
  • Is Wrath too easy?
  • New continent, old friends
more

WoR Feed

  • Feral Changes Part II, Blue Posts, WOWDB Update
  • Desktop Wallpaper Contest: Prizes &amp; Winners Announced
  • Wrath Online Upgrade, Blue Posts, Sweepstakes Reminder
  • Raiding Guild Spotlight: Vodka of Mannoroth-US
  • WotLK cleared... already?
more

Search

  • home
  • forums
  • gallery
  • calendar
  • handbook
  • tracker

I notice your oeuvre is monochromatic.
This site is proudly powered by Drupal.