Hi Bblythe Xiao,
I would like to share the resolution for the issue that I posted in this forum.
We have CyberArk configured as PAM for any server logins within the environment. We have 2 PSM (Privileged Session Manager) servers, setup with a Remote Desktop Connection broker for the Windows based user login to servers. We identified that the RDS connection was successful from the first PSM server, but failing when the user sessions are hitting the second PSM server. This was confirmed with the TCP connection test from the second PSM server and it was failing for TCP port 3389 to our destination RDSH servers. There were no configuration issues identified in the non-working PSM server as both were built from the same Image with identical configuration. The network log analysis at different integration points suggested there were no restrictions in terms of traffic movement. During the tests, a communication was initiated from the non-working PSM server, and it was noticed in logs that the TCP acknowledgement packets were not received by the PSM server from the RDSH servers. Upon further checking, it was noticed that an inbound rule was missing in the internal firewall device for the new subnets hosting the RDSH servers.
Once the firewall rule was added, the connection started working fine through the second PSM server and CALs were issued properly as expected.
I would like to thank you for your assistance throughout our troubleshooting, and request to mark this post as resolved.
Regards,
Arindam Basu.