Good afternoon.
There is a terminal farm with 3 session hosts, 1 connection broker and 1 session host for browsers and various SOFTWARE (this session host lives in a separate collection).
Recently the host for browsers began to fall off periodically from a farm is session, on a host there are errors of the following type:
"Remote desktop connection broker on server one is TSGW02.local.local returned an error when notifying to disconnect the session.
Session ID: 153
Error: the RPC Server is unavailable. "
"Remote desktop services was unable to join the connection broker on server one-TSGW02.local.local.
Error: the Current asynchronous message was dropped by the asynchronous dispatcher because there is a new message that will override the current one."
"A TCP/IP error occurred while trying to establish an outgoing connection because the selected local endpoint was recently used to connect to the same remote endpoint.
This error typically occurs when an outgoing connection is opened and closed at a high frequency, causing all available local ports to be used, and TCP/IP must re-use the local port for the outgoing connection.
To reduce the risk of data corruption, TCP/IP requires that there be a minimum amount of time between serial connections from a specific starting point to a specific endpoint."
"An error occurred while processing group policy. Windows was unable to apply WMI filter on group policy object 'cn={981F11B1-2073-4F7A-8D1E-760047BAF4D8},cn=policies,cn=system,DC=local,DC=local'.
Possible causes include disabling RSOP, disabling or stopping the WMI (Windows management Instrumentation) service, and other WMI errors.
Verify that the WMI service is started and that the service is set to start automatically. New settings or GPOs cannot be processed until this situation is corrected."
"The host server for the session connect to remote desktop cannot communicate with the license server for the rd one-tsgw02.local.local.
Verify that the remote desktop licensing service is running on the license server, that the license server accepts network requests, and that the license server is registered in WINS and DNS."
Nothing was installed or changed on the session host (since its normal operation).
Antivirus installed Kaspersky, base current, finds nothing. Physical servers also have no complaints (Hyper-V cluster, tried different nodes, including datastores).
At the time when the problem occurs (in the diagnosis) turned off the antivirus, as well as the built-in firewall - to no avail.
The most interesting thing is that if you make a wmi request from the connection broker , for example get-wmiobject Win32_OperatingSystem, then the problematic host responds and gives information.
If you try to make the same request from the problematic host anywhere (to the same broker), then you receive an error that WMI is not running on the remote host, or problems in the firewall.
What could be the problem?
![]()
![]()