Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations Chris Miller on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

TS Web Access - Remote Desktop Connection

Status
Not open for further replies.

gmail2

Programmer
Jun 15, 2005
987
IE
Hi All

We've currently got some restrictions on our network which means we cannot make any major modifications due to a planned re-design in the near future. However, we've got a requirement at the moment which means that am user in office A needs RDP access to a whole load of offices in a certain region.

Office A currently only has a VPN into our head office in europe, as does every other office.

What we want to do as an interim solution, is build a 2008 TS server at our head office, and then have the user in office A RDP to all the other offices from there. I know it's not an ideal solution, but our hands are somewhat tied on this.

What I'm wondering is, is it possible to use the "Remote Desktop" tab in TS Web Access to allow users to RDP to another server but go through that 2008 server rather than communicating directly ? Similar to running RDP as a remote app I guess

Thanks in advance for any help

Irish Poetry - Karen O'Connor
Irish Poetry and Short Stories - Doghouse Books
Garten und Landschaftsbau
 
is it possible to use the "Remote Desktop" tab in TS Web Access to allow users to RDP to another server but go through that 2008 server rather than communicating directly ?"

Research Windows 2008 Terminal Services Gateway, that is one of it's functions.


........................................
Chernobyl disaster..a must see pictorial
 
Thansk for the reply technome - I don't know why but for some reason I though TS Gateway was something completely different ! Sounds like it's exactly what I'm after. I just have a few questions:

1. Can a TS Gateway server be used to provide access to a server which is on a different domain than the TS Gateway server?
2. Can the TS server (not the gateway) be server 2003 or does it have to be 2008 ?
3. The servers in question are not actually Terminal Servers, they're just regular servers that this guy needs RDP access to for administration. Will this still work ?
4. Will installing a TS Gateway server on an existing domain affected any existing CA on that domain as I see TS Gateway requires the Client Certificate Mapping Authentication to be installed
5. Does the TS Gateway server require any TS licenses ?

Sorry for all the questions. I don't want to sound lazy ... I am reading up on this myself, these are just things that I've not managed to find the answer to as yet.

Thanks again

Irish Poetry - Karen O'Connor
Irish Poetry and Short Stories - Doghouse Books
Garten und Landschaftsbau
 
1) can't see why not
2) Gateway can connect to Win OS 2008, 2003, 2000 server in admin mode, and of the mentioned OSs setup as a TS, and XP and Vista wks
3) Any of the above OS servers, being DCs or member servers.
4) For ease, I use cheap public certs (Godaddy) for the TSG, which gets the domain CA out the picture... do not make a mistake with the cert install, stops everything.
5)No TS license is required for the Gateway, though other TS servers in user mode will need standard TS licenses, nothing needed for admin mode. Win 2008 user mode needs 2008 license/cals, Win 2003 and 2000 license/cals can not be used on a 2008 server.

"I don't want to sound lazy" realize the info out there is either excessively long winded/confusing (MS) or important info is left out.

Advise you to get a bare basic setup going first before playing with advanced features, thread softly with the connection and resource authorization policies. If you will be remotely making changes, would be a good idea to have a VPN connection not dependent on the Gateway, so you can bypass the TSG in case you lock yourself out during parameter changes. Most of my clients have Sonicwall VPN, which I can connect to via a Linksys BEFVP41, if necessary. Remote connections are extremely stable, as are Web Access connection.
Warning, not all parameter changes take place immediately as they should, at times a reboot was needed. Once setup and working, no maintenance is required. Most of the TSG I setup are 32 bit, also acting as a file server for 32 bit/16 bit files for a couple old programs, which is fine, as they are fast servers and secured.
Lastly, many links are showing the TSG in the DMZ, mine are on the LAN, as SSL on 443 secures the connection.





........................................
Chernobyl disaster..a must see pictorial
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top