Skip to main content

Allow configuring the Remote Computer (Full Address) independently from the RD Gateway address

This feature request is related to our support ticket #141578, which contains the technical background and discussion.

When generating a Windows client configured to use Remote Desktop Gateway (RDG), the Client Generator currently sets the RDP Full Address to 127.0.0.2.

This causes Windows to use TERMSRV/127.0.0.2 for NTLM authentication and NLA identity verification.

Many enterprise customers enforce the Group Policy "Restrict NTLM: Outgoing NTLM traffic to remote servers (Deny All)". In these environments, administrators must create explicit exceptions. They generally do not accept exceptions for TERMSRV/127.0.0.2, as they require hostnames or FQDNs instead of loopback IP addresses.

We would like the Client Generator to provide two independent configuration fields, similar to the native Microsoft Remote Desktop client:

  • RD Gateway address

  • Remote Computer (Full Address)

This would allow administrators to specify a hostname such as backend1.company.com as the Remote Computer while continuing to use the TSplus RD Gateway normally.

Benefits

  • Better compatibility with enterprise security policies.

  • Support for environments where outbound NTLM is restricted.

  • Eliminates the need to create exceptions for TERMSRV/127.0.0.2.

  • Aligns the TSplus Client Generator with the behavior of the native Microsoft Remote Desktop client (mstsc).

Thank you for considering this enhancement.

Status: Completed

Log in to comment and vote

No comments yet

Be the first to share your thoughts.