Remote CDE Login Fails!

Gents:

We have our TSOL servers configured much like guard servers...one NIC per Security Family with workstations on that specific LAN and at a specific maximum level.

Only 127.0.0.1 lives in the TSOL family on any of our systems.

That being said, here's our challenge:

We still would like to be able to use some workstations to Remote CDE login to our servers. All of our "administrators" have Remote Administration granted. When entering the remote host, it only shows up some of the time (otherwise, it goes right back to the local host). When it does show the correct hostname, we log in with our administrator account and are greeted with the first two "grey" boxes (the last one showing the security labels for that particular session). However, the screen goes black after clicking OK and the session reverts back to the local workstation.

I've seen lots of docs on "headless" systems, but this is not an initial install. We would like remote CDE access to the server for obvious reasons of convenience. However, we also have a need to segregate LANs to their respective levels (Unclass, Secret-1, Secret-2 and so forth).

Any guidance here would be appreciated greatly!

[1259 byte] By [TheNewGuy] at [2007-11-25 23:04:47]
# 1
Just as a quick WAG...Are all your machines using the same label_encodings file? Of course different encodings may be enabled or disabled on different machines, but is the underlying encodings file identical across the network?
Red at 2007-7-5 17:56:20 > top of Java-index,General,Sun Alert and Security Discussion...