We are troubleshooting intermittent Remote Desktop disconnects between an on-premises office and a Windows Server 2022 Datacenter VM in Azure.
Environment:
- Windows Server 2022 VM running Remote Desktop Session Host in Azure
Site-to-site IPsec VPN between a Sophos XGS firewall and an Azure VPN Gateway
Main-office client subnet: 192.168.0.0/24
Additional remote offices connect to the Sophos firewall through Sophos RED devices
RDS licensing is configured for Per User and RD Licensing Diagnoser reports no licensing problems
The main office recently upgraded to a 1 Gbps fiber Internet connection
Some Azure firewall/security and routing configuration was changed previously to improve security
Symptoms:
Multiple users at the main office sometimes lose their RDP sessions at approximately the same time. The sessions normally reconnect afterward. During at least one occurrence, a user reported that regular Internet connectivity also failed.
The RDS event logs contain network-related disconnects, including:
0x80070079 — The semaphore timeout period has expired
0x80070040 — The specified network name is no longer available
The server logs show sessions disconnecting and reconnecting rather than being logged off. RD Licensing Diagnoser reports no problems.
Troubleshooting completed:
Replaced the Ethernet patch cable between the Sophos firewall and the main switch
Confirmed the firewall and switch ports negotiate at 1 Gbps full duplex
Restarted the firewall and main switch
Continuous ping tests have shown very little packet loss, although one-second pings may not capture a brief interruption
Configured the RDS Session Host policy “Select RDP transport protocols” to “Use only TCP” to rule out problems with RDP over UDP
Verified through Group Policy Results that the TCP-only policy is applied
The problem has continued
We are collecting additional simultaneous ping results to the firewall LAN interface, Internet, Azure VM, and remote-site addresses
Questions:
Which Azure VPN Gateway diagnostic logs and metrics should we enable to identify brief tunnel resets, IPsec renegotiations, packet loss, or routing changes?
Could an Azure Firewall, NSG, route table/UDR, or asymmetric return path cause established RDP sessions to disconnect intermittently while reconnecting shortly afterward?
What is the recommended MTU and TCP MSS configuration for a Sophos-to-Azure site-to-site IPsec VPN?
Should the Azure VPN Gateway connection use any particular DPD, IKE/IPsec, or connection-mode settings with a Sophos XGS firewall?
What should we check in Network Watcher, Effective Routes, Next Hop, Connection Monitor, or VPN Troubleshoot?
Are there specific Azure VPN Gateway metrics that can be correlated with the exact disconnect times?
We would appreciate guidance on determining whether these interruptions originate with the Azure VPN Gateway, Azure routing/firewall configuration, or the on-premises connection.We are troubleshooting intermittent Remote Desktop disconnects between an on-premises office and a Windows Server 2022 Datacenter VM in Azure.
Environment:
Windows Server 2022 VM running Remote Desktop Session Host in Azure
Site-to-site IPsec VPN between a Sophos XGS firewall and an Azure VPN Gateway
Main-office client subnet: 192.168.0.0/24
Additional remote offices connect to the Sophos firewall through Sophos RED devices
RDS licensing is configured for Per User and RD Licensing Diagnoser reports no licensing problems
The main office recently upgraded to a 1 Gbps fiber Internet connection
Some Azure firewall/security and routing configuration was changed previously to improve security
Symptoms:
Multiple users at the main office sometimes lose their RDP sessions at approximately the same time. The sessions normally reconnect afterward. During at least one occurrence, a user reported that regular Internet connectivity also failed.
The RDS event logs contain network-related disconnects, including:
0x80070079 — The semaphore timeout period has expired
0x80070040 — The specified network name is no longer available
The server logs show sessions disconnecting and reconnecting rather than being logged off. RD Licensing Diagnoser reports no problems.
Troubleshooting completed:
Replaced the Ethernet patch cable between the Sophos firewall and the main switch
Confirmed the firewall and switch ports negotiate at 1 Gbps full duplex
Restarted the firewall and main switch
Continuous ping tests have shown very little packet loss, although one-second pings may not capture a brief interruption
Configured the RDS Session Host policy “Select RDP transport protocols” to “Use only TCP” to rule out problems with RDP over UDP
Verified through Group Policy Results that the TCP-only policy is applied
The problem has continued
We are collecting additional simultaneous ping results to the firewall LAN interface, Internet, Azure VM, and remote-site addresses
Questions:
Which Azure VPN Gateway diagnostic logs and metrics should we enable to identify brief tunnel resets, IPsec renegotiations, packet loss, or routing changes?
Could an Azure Firewall, NSG, route table/UDR, or asymmetric return path cause established RDP sessions to disconnect intermittently while reconnecting shortly afterward?
What is the recommended MTU and TCP MSS configuration for a Sophos-to-Azure site-to-site IPsec VPN?
Should the Azure VPN Gateway connection use any particular DPD, IKE/IPsec, or connection-mode settings with a Sophos XGS firewall?
What should we check in Network Watcher, Effective Routes, Next Hop, Connection Monitor, or VPN Troubleshoot?
Are there specific Azure VPN Gateway metrics that can be correlated with the exact disconnect times?
We would appreciate guidance on determining whether these interruptions originate with the Azure VPN Gateway, Azure routing/firewall configuration, or the on-premises connection.