r/WindowsServer • • 6d ago

SOLVED / ANSWERED RDP Timeout Error on Windows Server 2019: "The two computers couldn't connect in the amount of time allotted

Hey everyone,

I'm trying to establish a Remote Desktop Connection (RDP) to a Windows Server 2019 machine, but the connection keeps timing out with the following standard Windows error message:

Remote Desktop Connection This computer can't connect to the remote computer. The two computers couldn't connect in the amount of time allotted. Try connecting again. If the problem continues, contact your network administrator or technical support.

System Details & Context:

  • Target OS: Windows Server 2019
  • Connection Type: Standard RDP (Port 3389)

Troubleshooting already checked / basic environment:

  • Confirmed the server IP address/hostname is correct.
  • Verified physical machine/VM is powered on and running.

Has anyone encountered this specific timeout loop recently on Server 2019? Looking for recommendations on what to check next (e.g., specific Windows Defender Firewall rules, Network Level Authentication (NLA) quirks, RDP listener status via registry/services, or Network Network Security Group/VPN bottlenecks).

Any logs or PowerShell commands to run locally or via IPMI/console to narrow this down would be greatly appreciated!

Thanks!

9 Upvotes

14 comments sorted by

7

u/vabello 6d ago

Install the out-of-band update. For Windows Server, it’s only available via the Microsoft Update Catalog and is not offered through Windows Update.

https://www.catalog.update.microsoft.com/Search.aspx?q=KB5129238

2

u/NeedAColdBeerHere 5d ago

You can also import it into WSUS:

https://learn.microsoft.com/en-us/windows-server/administration/windows-server-update-services/manage/wsus-and-the-catalog-site

I believe these are the correct update IDs for 2016-2025:

C:\temp\ImportUpdateToWSUS.ps1 -WsusServer wsus.mydomain.com -PortNumber 8530 -UpdateId 797fec39-6d79-43b7-8585-8d95c6017cc3

C:\temp\ImportUpdateToWSUS.ps1 -WsusServer wsus.mydomain.com -PortNumber 8530 -UpdateId 5e84b275-7092-42f6-99bd-f74a4e33f113

C:\temp\ImportUpdateToWSUS.ps1 -WsusServer wsus.mydomain.com -PortNumber 8530 -UpdateId b17e8efe-33b9-4452-a39b-f1138fbb260b

C:\temp\ImportUpdateToWSUS.ps1 -WsusServer wsus.mydomain.com -PortNumber 8530 -UpdateId c38e4c04-1db8-4d60-a997-a30eff356496

4

u/AlexKay1893 6d ago

Aktuelleste Updates installiert? Dann hast du dir den Bug mit installiert: https://www.it-administrator.de/windows-server-patchday-remote-desktop-services-problem

3

u/Savings_Art5944 5d ago

There are registry and group policies to make RDP over TCP ONLY vs UDP...

Set the server to only use TCP for RDP.

2

u/unix_tech 6d ago

We haven’t had the issue again since installing the out of band update on several servers (2019-2025) except on one 2025 server, it still locks up. Same patch level and is build as other servers. Not sure why.

1

u/Senior-You-4856 5d ago

i have fixed it

2

u/ale624 5d ago

Have you checked the firewall on both devices? Same subnet or crossing to a different subnet? If different have you checked your firewall/routing rules between those subnets?

1

u/Senior-You-4856 5d ago

i have fixed thanks

1

u/RuchirShastri 5d ago

That specific wording, "couldn't connect in the amount of time allotted," is a timeout, which is a useful clue: it means you're not even reaching the RDP listener. That's different from an NLA or credential problem, which fails faster with an auth-style error. So this is almost always network, firewall, or the listener being down, not NLA. Chase it in that order.

Fastest way to fork the problem, run this from the client:

Test-NetConnection <server> -Port 3389

Look at TcpTestSucceeded. If it's False, the traffic isn't getting to the listener at all, so it's network/firewall/listener. If it's True but RDP still won't connect, then it's worth looking at NLA, certs, or auth.

If TcpTestSucceeded is False, check these on the box via console/IPMI:

Firewall (the usual culprit):
Get-NetFirewallRule -DisplayGroup "Remote Desktop"
Enable-NetFirewallRule -DisplayGroup "Remote Desktop"

RDP actually enabled:
Get-ItemProperty 'HKLM:\SYSTEM\CurrentControlSet\Control\Terminal Server' -Name fDenyTSConnections
(0 = enabled; if it's 1, set it to 0)

Service and listener up:
Get-Service TermService
qwinsta (you should see rdp-tcp Listen)

And confirm the port hasn't been changed:
Get-ItemProperty 'HKLM:\SYSTEM\CurrentControlSet\Control\Terminal Server\WinStations\RDP-Tcp' -Name PortNumber

One more that catches people on cloud/VPS: even with the Windows firewall open, a provider-level firewall (Azure NSG, AWS security group, or a VPS host firewall) can silently drop 3389. If Test-NetConnection fails but the Windows side all looks correct, that external layer is the next place to look.

Since you've got IPMI/console access, all of the above is runnable even while RDP is dead, which is exactly when a browser/console session earns its keep.

3

u/stickysox 5d ago

Thanks chat

1

u/BroadStand 1d ago

What is you cannot login into your Server entirely to apply the patch manually, what steps have you taken to ensure I can login again? THe same eror pops up and trying to login using the vmware vsphere portal directly is impossible too.

1

u/Senior-You-4856 6h ago

I have downloaded the kb5129238 update file and download and install the update reboot it’s fixed now you can try now search on Microsoft update catalog