Networking Forums

Networking Forums > Computer Networking > Windows Networking > Audit RDP Logon but not ICA Logon

Reply
Thread Tools Display Modes

Audit RDP Logon but not ICA Logon

 
 
Paul Bergson
Guest
Posts: n/a

 
      10-04-2006, 07:28 PM
I have failed miserably so far in my attempt to audit remote connections to
Windows 2000 boxes that host Citrix. My goal is to only see connections via
RDP not Citrix session connections. I have tried logging all logons, which
produce 528 Events but then you can't tell if it is a ICA or RDP connection.

So I tried removing local auditing and auditing on the server level and
setting auditing on the RDP connection from within Terminal Services
Configuration. No luck. I went back and tried all the possible combinations
and again had no luck.

Short of hatching a program and having it generate a log in the event log I
can't find a way to determine when a user authenticates on RDP only.

Anyone ever had success on something like this?

--
Paul Bergson
MVP - Directory Services
MCT, MCSE, MCSA, Security+, BS CSci
2003, 2000 (Early Achiever), NT

http://www.pbbergs.com

Please no e-mails, any questions should be posted in the NewsGroup
This posting is provided "AS IS" with no warranties, and confers no rights.


 
Reply With Quote
 
 
 
 
Pegasus \(MVP\)
Guest
Posts: n/a

 
      10-04-2006, 10:47 PM

"Paul Bergson" <pbergson@allete_nospam.com> wrote in message
news:uYOFTt%(E-Mail Removed)...
> I have failed miserably so far in my attempt to audit remote connections

to
> Windows 2000 boxes that host Citrix. My goal is to only see connections

via
> RDP not Citrix session connections. I have tried logging all logons,

which
> produce 528 Events but then you can't tell if it is a ICA or RDP

connection.
>
> So I tried removing local auditing and auditing on the server level and
> setting auditing on the RDP connection from within Terminal Services
> Configuration. No luck. I went back and tried all the possible

combinations
> and again had no luck.
>
> Short of hatching a program and having it generate a log in the event log

I
> can't find a way to determine when a user authenticates on RDP only.
>
> Anyone ever had success on something like this?
>
> --
> Paul Bergson
> MVP - Directory Services
> MCT, MCSE, MCSA, Security+, BS CSci
> 2003, 2000 (Early Achiever), NT
>
> http://www.pbbergs.com
>
> Please no e-mails, any questions should be posted in the NewsGroup
> This posting is provided "AS IS" with no warranties, and confers no

rights.
>
>


You can insert a line into the logon script that checks
environmental variables such as %SessionName%, then
generates a logon event.


 
Reply With Quote
 
Paul Bergson
Guest
Posts: n/a

 
      10-05-2006, 12:18 PM
Yeah, that is the only thing I can see right now but had hoped to not have
to place anything in such as that, but alas I think that is my only option.

--
Paul Bergson
MVP - Directory Services
MCT, MCSE, MCSA, Security+, BS CSci
2003, 2000 (Early Achiever), NT

http://www.pbbergs.com

Please no e-mails, any questions should be posted in the NewsGroup
This posting is provided "AS IS" with no warranties, and confers no rights.

"Pegasus (MVP)" <(E-Mail Removed)> wrote in message
news:(E-Mail Removed)...
>
> "Paul Bergson" <pbergson@allete_nospam.com> wrote in message
> news:uYOFTt%(E-Mail Removed)...
>> I have failed miserably so far in my attempt to audit remote connections

> to
>> Windows 2000 boxes that host Citrix. My goal is to only see connections

> via
>> RDP not Citrix session connections. I have tried logging all logons,

> which
>> produce 528 Events but then you can't tell if it is a ICA or RDP

> connection.
>>
>> So I tried removing local auditing and auditing on the server level and
>> setting auditing on the RDP connection from within Terminal Services
>> Configuration. No luck. I went back and tried all the possible

> combinations
>> and again had no luck.
>>
>> Short of hatching a program and having it generate a log in the event log

> I
>> can't find a way to determine when a user authenticates on RDP only.
>>
>> Anyone ever had success on something like this?
>>
>> --
>> Paul Bergson
>> MVP - Directory Services
>> MCT, MCSE, MCSA, Security+, BS CSci
>> 2003, 2000 (Early Achiever), NT
>>
>> http://www.pbbergs.com
>>
>> Please no e-mails, any questions should be posted in the NewsGroup
>> This posting is provided "AS IS" with no warranties, and confers no

> rights.
>>
>>

>
> You can insert a line into the logon script that checks
> environmental variables such as %SessionName%, then
> generates a logon event.
>
>



 
Reply With Quote
 
Cláudio Rodrigues
Guest
Posts: n/a

 
      10-05-2006, 04:28 PM
Depends on what you are looking for, check RecordTS that we will be
officially releasing in Las Vegas in November at the WinConnections expo.
It records all RDP sessions like a VCR so you can watch later.
It is auditing on steroids.

--

Cláudio Rodrigues

Microsoft MVP
Windows Server - Terminal Services
"Paul Bergson" <pbergson@allete_nospam.com> wrote in message
news:(E-Mail Removed)...
> Yeah, that is the only thing I can see right now but had hoped to not have
> to place anything in such as that, but alas I think that is my only
> option.
>
> --
> Paul Bergson
> MVP - Directory Services
> MCT, MCSE, MCSA, Security+, BS CSci
> 2003, 2000 (Early Achiever), NT
>
> http://www.pbbergs.com
>
> Please no e-mails, any questions should be posted in the NewsGroup
> This posting is provided "AS IS" with no warranties, and confers no
> rights.
>
> "Pegasus (MVP)" <(E-Mail Removed)> wrote in message
> news:(E-Mail Removed)...
>>
>> "Paul Bergson" <pbergson@allete_nospam.com> wrote in message
>> news:uYOFTt%(E-Mail Removed)...
>>> I have failed miserably so far in my attempt to audit remote connections

>> to
>>> Windows 2000 boxes that host Citrix. My goal is to only see connections

>> via
>>> RDP not Citrix session connections. I have tried logging all logons,

>> which
>>> produce 528 Events but then you can't tell if it is a ICA or RDP

>> connection.
>>>
>>> So I tried removing local auditing and auditing on the server level and
>>> setting auditing on the RDP connection from within Terminal Services
>>> Configuration. No luck. I went back and tried all the possible

>> combinations
>>> and again had no luck.
>>>
>>> Short of hatching a program and having it generate a log in the event
>>> log

>> I
>>> can't find a way to determine when a user authenticates on RDP only.
>>>
>>> Anyone ever had success on something like this?
>>>
>>> --
>>> Paul Bergson
>>> MVP - Directory Services
>>> MCT, MCSE, MCSA, Security+, BS CSci
>>> 2003, 2000 (Early Achiever), NT
>>>
>>> http://www.pbbergs.com
>>>
>>> Please no e-mails, any questions should be posted in the NewsGroup
>>> This posting is provided "AS IS" with no warranties, and confers no

>> rights.
>>>
>>>

>>
>> You can insert a line into the logon script that checks
>> environmental variables such as %SessionName%, then
>> generates a logon event.
>>
>>

>
>



 
Reply With Quote
 
 
 
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
There are currently no logon servers available to service the logon request - how to fix this error? i get it when trying to access a share one hop away. Daniel Windows Networking 1 04-12-2007 11:26 PM
There are currently no logon servers available to service the logon request Hot Gal Windows Networking 1 04-30-2004 01:58 AM
local windows logon vs. Domain logon Tye Windows Networking 1 04-14-2004 09:16 AM
There are no logon servers to serve your logon request Frank Windows Networking 7 01-28-2004 02:54 PM
Primary network logon switching to windows logon from Client for Microsoft netwo David Kairo Windows Networking 5 07-23-2003 02:26 AM



1 2 3 4 5 6 7 8 9 10 11