I've seen a lot of discussions about this in this forum, but I'm not able to get this to work.
I've got a single server with all of the RD roles installed on it with valid licenses. It's behind a router with a single static IP address assigned to the WAN interface with ports 3391-UDP and 443-TCP forwarded to my internal local static IP on my Windows
Server 2012 R2 machine. It is part of local domain, let's call it, "server1.domain.local."
Connections from within my local network to https://server1.domain.local/RDWeb allow a published application to run properly.
When I look at the Deployment Properties of RD Web Access Server it points to an non-editable entry called, https://server1.domain.local/RDWeb, not my external FQDN
I used the, "Change published FQDN for Server 2012 or 2012 R2 RDS Deployment" https://gallery.technet.microsoft.com/Change-published-FQDN-for-2a029b80 to see if that helps, but it doesn't seem to work. The local value still shows up in the Deployment
Properties of RD Web Access Server.
I am likely to be unable to set up a public network interface with the external FQDN on it, namely remote1.domain.com as an example. I need to keep the server behind the firewall and continue using port forwarding with NAT.
When I connect to https://remote1.domain.com/RDWeb I can see the published apps. I've had various failures from this point on. Right now I'm getting, RemoteApp Disconnected" User account not authorized, or computer not authorized, or incompatible method.
I have a public Cert that works fine. The same cert was used for all 4 required roles. I created a .pfx exported from IIS for this purpose with a third party certificate authority.
I also tried setting up an mstsc connection with the public external FQDN used as a gateway. This fails, too.
I used the Add Roles and Features, RDS installation, Quick, Session-based to set this all up.
I thought maybe my Gateway just wasn't working properly. I uninstalled it, rebooted, and re-installed it. No joy.
Domain Users can access RDS via mstsc locally.
I can't figure out where to look next.
I thought this would be instructive:
https://social.technet.microsoft.com/Forums/windowsserver/en-US/67dfab70-7e10-4e0b-a3c8-63ce776f2355/how-do-i-change-the-url-to-the-remote-web-access-server-in-windows-server-2012?forum=winserverTS
However I'm still getting nowhere.
If you have any suggestions, please be specific and clear. I expect I'm missing something. For example someone posted this at the previously mentioned page, "1. Please configure the RD Gateway FQDN in deployment settings so that it is set to the external
address for your server, for example, remote.yourdomain.com."
Obviously, if I could do that I might not have a problem, but how does one do that in my circumstance?
Help.
Thanks,
Steven