Showing posts with label RDP. Show all posts
Showing posts with label RDP. Show all posts

Friday, 5 February 2016

Some Remote Desktop Session Host Guidelines

We’ve put about four years and two versions into our Small Business Solution (SBS). We have it running on-premises on standalone Hyper-V servers as well as on Hyper-V clusters (Clustered Storage Spaces and Hyper-V cluster we just deployed for a 15 seat accounting firm).

It is the foundation for the Cloud Office services we’ve been offering for the last year or so.

Since our Cloud Office solution runs in Remote Desktop Services we figured we’d share some pearls around delivering Remote Desktop Session Host based environments to clients:

  • ~512MB/User is cutting it tight
  • ~20 to 25 users in a 12GB to 16GB vRAM Hyper-V VM works okay with 2-3 vCPUs
  • RDP via 8.1 RDP clients saturates a 1Mb DSL uplink at ~13-15 users depending on workload
  • ALL browsers can bring the RDSHs to their knees
  • Printing can be a bear to manage (Use Universal Print Drivers and Isolation where possible)
  • Group Policy configuration and lockdown is mandatory
  • Two partitions with User Profile Disks (UPDs), if used, on the second partition
  • NOTE: UPDs + Office 2013 and earlier + Exchange 2013 and earlier = Broken Search!!!
  • NOTE: RDSH Search Indexes for Outlook OSTs in UPDs can fill up the C: partition!
    • Office 2016 and Exchange 2016 together are supposed to address the broken search situation in RDSH setups were UPDs are used. We have yet to begin testing the two together.

Our Cloud Office (SBS) is running on clusters we’ve designed based on Scale-Out File Server and Hyper-V.

Need a clustered solution for your SMB/SME clients? Drop us a line. They are _very_ affordable. ;)

Philip Elder
Microsoft High Availability MVP
MPECS Inc.
Co-Author: SBS 2008 Blueprint Book

Wednesday, 27 February 2013

RDP Client in Windows 8 and Server 2012 Neat Features

While working from a Windows 8 Enterprise system here in the shop we connected remotely to a Windows Server 2012 Hyper-V environment that we are in the process of setting up for a new client.

A couple of neat new features in the MSTSC (Click Start (WINKey+R) –> Run –> mstsc [Enter]), that is the Microsoft Remote Desktop Connection Client (MicroSoft Terminal Services Client) are the following:

image

There is a little drop down menu available on the far left of the RDP status bar at the top of the session that gives us access to Windows 8/Server 2012 specific features.

The other thing we noticed was the “wireless” status bars to the right of the Pin.

Click on that and we see the following:

image

The drop down menu will certainly be handy for windowed RDP sessions since that is how we run most of our remote management sessions.

The connection status bars not so much. It is pretty obvious when we are having connection issues.

Have a great day and thanks for reading! :)

Philip Elder
MPECS Inc.
Microsoft Small Business Specialists
Co-Author: SBS 2008 Blueprint Book

Chef de partie in the SMBKitchen
Find out more at
www.thirdtier.net/enterprise-solutions-for-small-business/

Windows Live Writer

Friday, 24 February 2012

RDP: Set up a Monitor Span for Non-Windows 7 Enterprise/Ultimate End Points

In order to get true multi-monitor client connections going both ends need to be Windows 7 Enterprise and/or Ultimate. Or, when connecting to Remote Desktop Services the client needs to be one of those client OSs.

To get around that for all other client OSs we can do the following:

  1. Set up an SSL VPN connection (or PPTP).
    • Disable the Use Remote Gateway setting for IPv4 and IPv6.
  2. Start –> type: MSTSC [Enter]
    • Machine.Domain.Local
    • Full Screen
    • Redirect needed resources.
    • Do not change Gateway settings from default.
  3. Save As onto the desktop.
  4. Right click RDP file and Open With…
    • C:\Windows\notepad.exe
  5. Add the following line to the RDP file:
    • span monitors:i:1
  6. Save the RDP file.
  7. Open the VPN connection.
  8. Double click on the RDP Desktop file.
  9. Log on to the desktop machine.

Users will need to get used to all dialogue boxes saddling the two monitors since that is where the “middle” of the spanned setup is.

The local monitor pair must be side-by-side and the same resolution.

We tested running the RDP file with a Remote Desktop Gateway setting and it seemed to only connect one monitor.

Philip Elder
MPECS Inc.
Microsoft Small Business Specialists
Co-Author: SBS 2008 Blueprint Book

*Our original iMac was stolen (previous blog post). We now have a new MacBook Pro courtesy of Vlad Mazek, owner of OWN.

Windows Live Writer

Saturday, 17 September 2011

SBS 2011: Configure SBS Connect Wizard for Windows 8

Our post on tweaking the SBS 2008 Connect Wizard is here:

The Official SBS Blog Post:

There are a few differences in the settings for SBS 2011. Make sure to make a backup of the GP.XML file and the supportedOS.XML files before modifying them in any way.

After installing  the Windows 8 desktop OS:

  1. On SBS 2011 Open SBS Native Tools Console.
  2. Open the Group Policy Management Console.
    1. If it is not there add it and save the MMC so that it is there later.
  3. Navigate to the Windows SBS Client Policy GPO and copy the GUID (Unique ID).
  4. Paste the GUID into the following path:
    1. \Windows\sysvol\domain\Policies\{YOUR-GUID-HERE}\machine\SBS
  5. Click Start –> NotePad –> Right click and Run As Admin.
  6. File –> Open –> Paste the above path in and open GP.XML.
    • Make sure File Type is set to All Files (*.*).
  7. Append the following to (Version>= . . . ) found in the GP.XML
    • and ‘6.2.8102’
    • image
    • image
  8. Save and close NotePad.
  9. Click Start –> NotePad –> Right click and Run As Admin.
    1. File –> Open –> Paste the following path and open supportedOS.XML.
      • C:\Program Files\Windows Small Business Server\Bin\WebApp\ClientDeployment\packageFiles\
      • Make sure File Type is set to All Files (*.*).
  10. Replace the supportedOS.XML file contents with the following:
    • <SupportedConfigurations>
        <SupportedOS>
          <!-- Name is not used by the code but might be helpful in identifying the OS that is described by these parameters -->
          <!-- ExcludedSuite, RequiredSuite, and RequiredProductType are the numbers as specified in the OSVERSIONINFOEX structure -->
          <!-- Architecture is the number as specified in the SYSTEM_INFO structure –>
    •     <OS id="1" Name="Windows XP SP2, x86" Major="5" Minor="1" Build="2600" SPMajor="2" SPMinor="" ExcludedSuite="512" RequiredSuite="" RequiredProductType="1" Architecture="0"/>
          <OS id="2" Name="Windows XP SP2, AMD64" Major="5" Minor="2" Build="3790" SPMajor="2" SPMinor="" ExcludedSuite="512" RequiredSuite="" RequiredProductType="1" Architecture="9"/>
          <OS id="3" Name="Windows Vista, x86" Major="6" Minor="0" Build="6000" SPMajor="" SPMinor="" ExcludedSuite="512" RequiredSuite="" RequiredProductType="1" Architecture="0"/>
          <OS id="4" Name="Windows Vista, AMD64" Major="6" Minor="0" Build="6000" SPMajor="" SPMinor="" ExcludedSuite="512" RequiredSuite="" RequiredProductType="1" Architecture="9"/>
          <OS id="5" Name="Windows 7, AMD64" Major="6" Minor="1" Build="7000" SPMajor="" SPMinor="" ExcludedSuite="512" RequiredSuite="" RequiredProductType="1" Architecture="9"/>
          <OS id="6" Name="Windows 7, x86" Major="6" Minor="1" Build="7000" SPMajor="" SPMinor="" ExcludedSuite="512" RequiredSuite="" RequiredProductType="1" Architecture="0"/>
          <OS id="7" Name="Windows 8, AMD64" Major="6" Minor="2" Build="8102" SPMajor="" SPMinor="" ExcludedSuite="512" RequiredSuite="" RequiredProductType="1" Architecture="9"/>
          <OS id="8" Name="Windows 8, x86" Major="6" Minor="2" Build="8102" SPMajor="" SPMinor="" ExcludedSuite="512" RequiredSuite="" RequiredProductType="1" Architecture="0"/>
        </SupportedOS>
      </SupportedConfigurations>
    • image
  11. On the Windows 8 system: Open IE and open the http://connect wizard.
  12. At the _bottom_ of the IE window click the Turn on Intranet settings button.
    • image
  13. Click the Yes button to the “Are you sure . . . ?” prompt.
  14. Click the Start Connect Computer Program link.
    • image
  15. Step through the Connect Wizard.

image

The Windows 8 machine/VM will step through and complete its configuration.

Please use the supportedOS.XML file and the paths TXT file found in the above ZIP archive. The GP.XML file found in the archive is from an SBS 2008 setup so please ignore it for SBS 2011.

RDP and Windows 8

NOTE: We are experiencing a problem connecting to the VM via RDP on Windows SBS 2011 networks even with the firewall exceptions in place. At this point we are not sure if there is a problem using the RDP client in Windows 7/Windows Server 2008 R2 or if there is a bug in the Windows 8 OS RDP setup.

Philip Elder
MPECS Inc.
Microsoft Small Business Specialists
Co-Author: SBS 2008 Blueprint Book

*Our original iMac was stolen (previous blog post). We now have a new MacBook Pro courtesy of Vlad Mazek, owner of OWN.

Windows Live Writer

Wednesday, 14 September 2011

VDI: What version of Windows 7 Desktop OS to Install?

When it comes to setting up a client’s Virtual Desktop Infrastructure (VDI), we have already configured their Software Assurance plus MDOP to gain access to VDI.

So, do we install Windows 7 Professional or Windows 7 Enterprise into those VMs?

In many cases there will be no need for Enterprise to be installed for regular VM access.

However, there will be some cases where Enterprise does make sense. One is for a firm or company that uses multiple monitors on their remote and local desktop.

Windows 7 Enterprise and Ultimate give us access to the ability to RDP into the VM and utilize multiple monitors at the source.

Note that both endpoints in the RDP connection must be either Enterprise or Ultimate. No other Windows desktop OS versions support this RDP capability.

Now, depending on the Internet connection the client uses we would tailor a GPO with RDP related settings to limit bit depth to 15bpp and the number of monitors to 2 for smaller connections while we would up the number of monitors for larger connections.

Also note that users connecting to their office desktop via the SBS 2011 Remote Web Access portal that have two monitors hooked up to their home machine will get both monitors in the remote session if using Ultimate at home and Enterprise/Ultimate on their office desktop.

We find that clients that utilize multiple monitors see their user’s productivity increase exponentially.

Philip Elder
MPECS Inc.
Microsoft Small Business Specialists
Co-Author: SBS 2008 Blueprint Book

*Our original iMac was stolen (previous blog post). We now have a new MacBook Pro courtesy of Vlad Mazek, owner of OWN.

Windows Live Writer

Friday, 8 July 2011

Providing IT Support – Out-of-Band Management Required

A paraphrase of a post to the SBS2K Yahoo Group.

In our opinion a server should _never_ be deployed without iDRAC Enterprise, iLO Advanced, Intel RMM, or other out-of-band (OOB) device. Period.

Professional grade tools for professionals.

We get:

  • KVM, USB, and drive redirection to the server.
  • BIOS, Firmware, RAID BIOS, etc access.
  • BMC Management and sensor logs/data.
  • Power cycle and reset ability (frozen OS).
  • At-a-glance view of all firmware versions.

What this does for us:

  • Immediate access to the _console_
  • No travel time delays ... response is quick.
  • No need for client intervention in most cases.

When patching or working on servers we create two connections to the box. One via RD Gateway and one via OOB. It is our preference to have physical access to that box at all times.

With the lack of a speaker on the Dell PERC RAID controllers and Open Manage may or may not e-mailing us about a failed drive we prefer to watch all reboot cycles for any anomalies.

If there is a failure, we can recover that server without any client intervention after the tier 1 tech has done their stuff.

I am sorry, but there is something totally unprofessional about, "I am sorry Mr. Customer, but could you sit at the server and see why I am locked out?" Or having to call a client’s user or contact in before or after business hours to find out why something broke. As IT Professionals we need to set the bar higher than that.

With gas at $1.10/Litre (US Gal = 3.78L, IMP Gal = 4.54L) here and rising at this time _not_ having to travel to client sites for out of scope work is a great thing.

Why?

Because they then _do_ see us when we are there for _positive_ things like rotating their backups or our bi-weekly "how are things?" visit (billable as soon as they say, "Can you fix this?" :*) ).

This aspect more than reinforces our _good_ presence in their business. Thus it strengthens our business relationship with our client contact and their users as we are seen and heard when things are good.

Philip Elder
MPECS Inc.
Microsoft Small Business Specialists
Co-Author: SBS 2008 Blueprint Book

*Our original iMac was stolen (previous blog post). We now have a new MacBook Pro courtesy of Vlad Mazek, owner of OWN.

Windows Live Writer

Tuesday, 31 May 2011

SBS 2011 – Remote Desktop Gateway Not Available After Update Reboot?

We are in the process of running updates on our newly migrated to SBS 2011 server.

After the server came up from its post update install reboot every logon attempt came up with a “Remote Desktop Gateway service is not available” error.

We flipped over to the Intel Remote Management Module 3 KVM session to see what was going on (we always open a KVM session to watch the server’s reboot cycle) and found the SBS 2011 CTRL+ALT+DEL logon screen.

So, everything looked normal there.

After logging into the KVM session we tried to log on via RDP one more time and it worked.

A look into the Services MMC in the SBS Native Tools Console’s Computer node turned up the following:

image

  • Remote Desktop Gateway: Started – Automatic (Delayed Start)

Ah, not to panic then. We just need to be a bit more patient as things come up after that boot cycle! :)

Philip Elder
MPECS Inc.
Microsoft Small Business Specialists
Co-Author: SBS 2008 Blueprint Book

*Our original iMac was stolen (previous blog post). We now have a new MacBook Pro courtesy of Vlad Mazek, owner of OWN.

Windows Live Writer

Saturday, 15 January 2011

SBS – Setting Limits To RDP Sessions

As the Windows Server operating system gets more advanced in the methods that we use to remotely connect to our Remote Desktop Services/Terminal Services servers or desktops behind TS/RDS Gateway we need to be mindful of the bandwidth requirements for the connections.

With SBS 2011 we can connect to our office based PC with multiple monitors, stream video, stream sound, and a lot more on that one connection.

So, out of the box we set some limits to what we can and cannot do with our RDP connection to an SBS network.

image

The above screenshot is of a GPO setting opened in our SBS 2011’s GPMC. In this setting we are putting a limit on the number of monitors that a remotely connected user can use for their connection at 2.

Note that in any GPO setting that allows for a comment, including the GPO itself, we put comments in as above or with a brief description as to why the policy was enabled or disabled. We try and do this to keep track of the changes we have made with the descriptions helping us to understand why things were they way they were later on in the life of the SBS network.

image

The rest of the settings in the Windows Computers Policy are as follows:

image

  • Enforce removal of the remote PC’s wallpaper.
    • This one is pretty obvious as the high resolution colour images will hit the screen refresh rate significantly.
  • Limit colours to 15 bits.
  • Maximum remotely connected monitors: 2.
  • Remove the “Disconnect” button from the Shutdown Dialogue.
    • We request that users always log off their remote sessions when done.
  • Enable the Windows Security item on the Start menu.
    • This item gives them the ability to access the Windows Security menu to make changes if they get stuck.
    • image

The settings will be in a slightly different location for GPOs in SBS 2008 and SBS 2003 as RDS was Terminal Services in those editions.

In certain circumstances we will also enable the Restrict Remote Desktop Services users to a single Remote Desktop Services session setting.

Philip Elder
MPECS Inc.
Microsoft Small Business Specialists
Co-Author: SBS 2008 Blueprint Book

*Our original iMac was stolen (previous blog post). We now have a new MacBook Pro courtesy of Vlad Mazek, owner of OWN.

Windows Live Writer

Wednesday, 22 December 2010

Remote Desktop Connection Manager – Multiple RDP Sessions Managed Easily

This is a pretty kewl utility:

image

We can set up all of the servers and desktops that we manage on a regular basis in the Connection Manager and have quick and easy access to them.

The RDCM can store credentials as well so we will only allow that to happen on workstations or laptops that are BitLocker enabled.

Hat Tip: Jason Miller

Philip Elder
MPECS Inc.
Microsoft Small Business Specialists
Co-Author: SBS 2008 Blueprint Book

*Our original iMac was stolen (previous blog post). We now have a new MacBook Pro courtesy of Vlad Mazek, owner of OWN.

Windows Live Writer

Thursday, 14 October 2010

Intel Remote Management 3 A Must

Today, the cost of adding in the Intel Remote Management 3 (RMM3) module in most Intel Server Systems or server boards is very low. To our clients it is actually worth about one visit. So, why not have one installed where we can so that on-site time is reduced?

For Dell we have the DRAC i6 Enterprise, HP has the iLO with Advanced license, and there are others.

What these components do for us is provide a number of out-of-band management features. That means that we do not need an OS to work with the server.

  • Console access to the OS, BIOS, firmware, and other server components.
    • This is done by redirected KVM session over HTTPS.
  • Ability to reset the server, power it up, or power it down.
  • Check the server’s sensor logs for errors.

The initial setup of the RMM3 is done in the BIOS of the server. We enable USER3, rename the user, give it a password, and make sure that it has Administrator permissions.

When we first hit the IP address of the RMM3 we need to log on using the above created user:

image

The page that we will be greeted with will be a summary of the system.

From an RMM3 on an SR1625URR Server System:

image

From an RMM3 on an SR1630HGPRX Server System:

image

The FRU Information link gives us our server’s PBA (Part/Model Number), serial number, and other needed information if we are in need of support or warranty replacement.

The Server Health tab gives us a view of the server’s sensor status along with access to the server’s internal Event Log.

The SR1625URR’s sensor readings:

image

The SR1630HGPRX sensor readings:

image

Note the difference in the number of sensors between the server systems. The SR1625URR is a dual Intel Xeon Nehalem 5000 series 1U server while the SR1630HGPRX is an Intel Xeon Nehalem 3000 series 1U server.

While all of the above features are very helpful as far as keeping an eye on the server’s health and for troubleshooting purposes the key RMM3 feature is its ability to give us console access to the server’s OS.

image

Once we click the Launch Console button we will need to approve some Java security warnings before the redirected KVM session begins.

Once we do get our session we are “sitting in front of the server”.

This is a screenshot of the SR1625URR’s KVM session:

image

We currently have both 1U server’s RMM3 network ports connected to our own internal network. Once we have plugged in the needed optical disk for the OS install if needed and/or USB flash drives we no longer need to be standing at the workbench to run a fresh OS install as is the case in the above screenshot.

We can have a technician run several OS installs and post install configurations while working at their own station.

Once these servers are ready to go into production, the RMM3 Ethernet ports will be set with an ISP delivered static IP address and a GoDaddy certificate will be installed to eliminate the SSL warnings for the Web portal.

When it comes to a standard access method such as Terminal Services/Remote Desktop Services or TS/RDS via TS/RDS Gateway we are stuck if the underlying services get knocked out by an update or something breaks along the way.

Using the RMM3/DRAC/iLO to run those updates means that we do not need to be concerned about the underlying services plus we can watch the server reboot through its BIOS POST as well as RAID Controller POST status indicators.

Philip Elder
MPECS Inc.
Microsoft Small Business Specialists
Co-Author: SBS 2008 Blueprint Book

*Our original iMac was stolen (previous blog post). We now have a new MacBook Pro courtesy of Vlad Mazek, owner of OWN.

Windows Live Writer

Monday, 23 August 2010

SBS v7 – Multi-Monitor Goodness via RDS Gateway (TS Gateway)

One of the neat little advantages of the new RDP protocol version that comes built into Windows Server 2008 R2 and thus SBS v7 is the ability to serve remote desktops out to clients that have multiple monitors and have that remote desktop session _on_ those multiple monitors.

image

The above screenshot is of the remote desktop session from home that has a 22” wide LCD on the right and an older Acer 19” 4x3 standard aspect ratio LCD on the left.

The 22” is sitting on top of a Mini-ITX system, so it is actually quite a bit higher than the Acer thus the shift between the two screens.

The Remote Desktop Connection Setting

To get the multiple monitor setup to work, we need to enable the following setting in the Remote Desktop Connection client:

image

Use all my monitors for the remote session

One thing to keep in mind is that with the additional monitors comes the need for additional bandwidth. As a result, for offices with smaller upload speeds, one will need to keep in mind which users should be able to connect with multiple monitors and which ones should not.

Web Site Animation Caveat

It should also be noted that when connected to a remote desktop session and there is a need to browse the Web, that sites that have some sort of animation on them will cause the session to grind virtually to a stop. So, after clicking the next link on the site, be patient as it may take a few rounds of animation for that click to be registered remotely.

Hopefully the next page does not have any animation on it!

Philip Elder
MPECS Inc.
Microsoft Small Business Specialists
Co-Author: SBS 2008 Blueprint Book

*Our original iMac was stolen (previous blog post). We now have a new MacBook Pro courtesy of Vlad Mazek, owner of OWN.

Windows Live Writer

Friday, 30 April 2010

What a TSGrinder Grind Against an SBS Looks Like

On some of our older SBS 2003 installs where we have no out-of-band remote management setup in place, we open up port 3389 on the router to the server to run our updates.

Once we are finished, we normally close the port back up. Now, this particular evening we had run a series of updates across more than half of the servers that we manage one Saturday.

It seems that one of the firewall ports did not get closed and someone took an interest in that particular server:

image

  • Logon attempts: 3,282
  • IP: 64.46.44.76

Now, the IP may not be relevant since the machine behind it may be a zombie.

Things were relatively quite until a few days later:

image

  • Logon attempts: 5
  • IP: 113.53.231.2

Then this one kept at it for a number of days:

image

  • Logon attempts: 1,906
  • IP: 84.53.64.91

The above IP kept after the server until this day:

image

  • Logon attempts: 2,414
  • IP: 84.53.64.91

And another shot of a report that was taken manually in the SBS Console not long after the above:

image

  • Logon attempts: 4,545
  • IP: 84.53.64.91

Note the different numbers between the automatically generated report and the one manually created by us. The disparity may be due to the fact that the TS service was being hammered so frequently.

While the grind was happening we could not log on to the server via a direct TS connection. We were almost instantly bumped out as soon as we saw the logon screen.

Fortunately, we could log onto RWW and TS via the RWW RDP connection that uses a proxy port of 4125. If that had failed, then we would have connected to a workstation and ran:

  • mstsc /v:servername /admin

From there we would have had console access and could do what needed to be done which was to close the 3389 publishing rule in ISA.

TS Client help screenshot:

image

As a rule, we do not allow port 3389 to be opened to the Internet by default.

Philip Elder
MPECS Inc.
Microsoft Small Business Specialists
Co-Author: SBS 2008 Blueprint Book

*Our original iMac was stolen (previous blog post). We now have a new MacBook Pro courtesy of Vlad Mazek, owner of OWN.

Windows Live Writer

Monday, 5 April 2010

Router/Firewall Ports To Forward For Windows Home Server

There are two ports that need to be forwarded at the router/firewall to the Windows Home Server box:

  • 443 HTTPS TCP (SSL Web)
  • 4125 RDP Proxy Port (RDP connections to the desktops)

Note that the 4125 proxy port is inherited from WHS’s bigger cousin Small Business Server 2003.

Port 80 is optional in that it redirects to 443 anyway. So, we suggest leaving that port closed and remembering the “s” in the WHS URL.

Once the remote access firewall ports are properly configured we see the following on an HP based WHS:

image

And the following on an Acer based WHS:

image

Philip Elder
MPECS Inc.
Microsoft Small Business Specialists
Co-Author: SBS 2008 Blueprint Book

*Our original iMac was stolen (previous blog post). We now have a new MacBook Pro courtesy of Vlad Mazek, owner of OWN.

Windows Live Writer

Tuesday, 1 September 2009

SBS 2008 – SharePoint Services Service Pack 2 Choke

We have mentioned in the past to hold off on installing that service pack:

We happened to have one of our SBS 2008 hosting servers come free today, so we took a chance on installing SharePoint v3 Service Pack two and sure enough things went sideways.

The default fix from the SBS Blog does not work for us either:

Another aspect to this situation: The Service Pack kills the TS Gateway service and thus kills any possibility of gaining remote access to the box via RWW or RDP.

If VPN is not configured on the box, which is the case in many of our client locations, then we would be in a real pickle.

Updating Rule #1: Always have an out-of-band management access on servers being updated.

Some of them are:

Otherwise we are asking someone to go to the console to log on and either get the services back up and running, reboot the server, or help with the troubleshooting process. All are not very viable options.

So, now we are in the process of troubleshooting the hosed SharePoint install. Fortunately we have out-of-band access.

Philip Elder
MPECS Inc.
Microsoft Small Business Specialists
Co-Author: SBS 2008 Blueprint Book

*All Mac on SBS posts will not be written on a Mac until we replace our now missing iMac! (previous blog post)

Windows Live Writer

Friday, 26 June 2009

Windows 7 – Remote Desktop Multi-Monitor Goodness

The TS Gateway service allows us direct access to our desktops.

The new RDP version allows us to /mulitmon to use the two monitors we have connected to this workstation on the remote desktop:

image

Here is a list of the new RDP version’s command line switches:

image

Just remember that the TS Gateway service does allow for direct connections to any TS enabled system inside the SBS network. As a result, it would be a good idea to look at AuthAnvil by Scorpion Software to provide another level of authentication protection.

Philip Elder
MPECS Inc.
Microsoft Small Business Specialists
Co-Author: SBS 2008 Blueprint Book

*All Mac on SBS posts will not be written on a Mac until we replace our now missing iMac! (previous blog post)

Windows Live Writer

Saturday, 2 May 2009

Windows 7 Release Candidate RDP Supports Multi-Monitors!

Need we say more:

09-05-02 Win7 - RDP Client Supports Multi-Monitors

Use all my monitors for the remote session

What a huge leap ahead.

Most users that we work with have discovered the significant increase in productivity that two or more monitors can provide for them in their offices. Now they can have that same productivity from home.

The multi-monitor feature will make Windows 7 a very valuable upgrade option for those that connect to their in-house/office systems via the Remote Web Workplace and always have at least two monitors connected to the remote workstation.

It will be a great feature for those that manage networks via remote connections too.

Philip Elder
MPECS Inc.
Microsoft Small Business Specialists
Co-Author: SBS 2008 Blueprint Book

*All Mac on SBS posts will not be written on a Mac until we replace our now missing iMac! (previous blog post)

Windows Live Writer

Tuesday, 24 March 2009

SBS 2008 – Terminal Services Gateway server is temporarily unavailable

Here is one of those cryptic error messages when connecting to an SBS server via RDP:

09-03-24 SBS 2008 - Gateway Temporarily Not Available

Remote Desktop Disconnected

This computer can’t connect to the remote computer because the Terminal Services Gateway server is temporarily unavailable. Try reconnecting later or contact your network administrator for assistance.

Now, since we are the network administrators, we now need to figure out just what is going on.

The first instinct is the Internet connection may be down. But, when we bring up the Remote Web Workplace (RWW), the site is there.

Try and log onto the RWW, and this is what we are greeted with:

09-03-24 SBS - RWW - Change Password Page

RWW: Password change needed

If we did not try and log onto RWW, the next logical step would have been to troubleshoot what was going on with the TS Gateway service in the logs.

Once into the server, the TS custom view in the Event Viewer had no errors whatsoever.

In our custom logon failure Event Viewer Custom View (SBS CodePlex) however, we found the following:

An account failed to log on.

Subject:
    Security ID:        NETWORK SERVICE
    Account Name:        SBS$
    Account Domain:        MySBSDomain
    Logon ID:        0x3e4

Logon Type:            3

Account For Which Logon Failed:
    Security ID:        NULL SID
    Account Name:        MyUserName
    Account Domain:       

Failure Information:
    Failure Reason:        The specified account's password has expired.
    Status:            0xc000006e
    Sub Status:        0xc0000071

A quick run through the logs produced the above. We made sure that all of the services were happy before accomplishing the folder recovery we needed to and then logged off.

Philip Elder
MPECS Inc.
Microsoft Small Business Specialists
Co-Author: SBS 2008 Blueprint Book

*All Mac on SBS posts will not be written on a Mac until we replace our now missing iMac! (previous blog post)

Windows Live Writer

Tuesday, 17 March 2009

SBS 2008 – Who is Connected by RDP? TS Gateway Manager Knows

When it is time to install patches or software that may bring about the need for a server reboot, we need to know who is working on what on the server.

For files, the default place to check is in the Sessions node in the Computer Management console. Any open files, where they are located, and who has them open are there.

For remote connections, the VPN is managed by RRAS, so any connections can be found in the Routing and Remote Access node under the same Computer Management console.

For RDP though, we now have the ability to actually see who is connected to any server or desktop resources within the SBS network using the TS Gateway Manager:

09-03-17 SBS 2008 - TS Gateway Manager

TS Gateway Manager

We can see how long they have been connected, to what server or desktop they are connected to, and whether the connection has been idle.

The console can be opened by clicking on the Start button and typing the console name in the Search field. Otherwise it is under the Terminal Services folder nested in the Administrative Tools folder in the All Programs list.

Once we know who to get in touch with to let them know that there is a need to reboot, we can be assured that no one will lose any data.

Philip Elder
MPECS Inc.
Microsoft Small Business Specialists
Co-Author: SBS 2008 Blueprint Book

*All Mac on SBS posts will not be written on a Mac until we replace our now missing iMac! (previous blog post)

Windows Live Writer

Saturday, 14 March 2009

AuthAnvil – Want to See a Neat Security Demo Video?

With the advent of the TS Gateway service on SBS 2008, the only thing protecting our production SBS 2008 networks is a password.

Even  with a passphrase in place, there are some pretty sophisticated password dictionaries out there.

We will be looking to providing another layer of protection to our SBS 2008 networks.

That protection will be provided by Dana Epp’s (Security MVP blog link) AuthAnvil security product.

Check out the video that demonstrates AuthAnvil in action:

09-03-14 AuthAnvil

Scorpion Software: AuthAnvil Demonstration Video

Something to keep in mind is that TSGrinder (Live Search) has been reworked to now be able to attack the new TS setup on Windows Server 2008.

The video link: Scorpion Software: AuthAnvil Demonstration Video

Scorpion Software also offers a partner program: Scorpion Software Partner Program.

Much like Vlad’s OwnWebNow, Scropion Software is another reputable product vendor that delivers on a great business relationship and a great product set that is well supported.

Do check out Dana’s blog. It is a good read!

Philip Elder
MPECS Inc.
Microsoft Small Business Specialists
Co-Author: SBS 2008 Blueprint Book

*All Mac on SBS posts will not be written on a Mac until we replace our now missing iMac! (previous blog post)

Monday, 9 March 2009

SBS 2008 – Remove the Single TS User Restriction on the Server

We have a need to have two TS sessions on our SBS 2008 lab systems for training purposes.

To accomplish this, we need to remove the following setting in the Terminal Services Configuration:

09-03-09 SBS 2008 - Remove Single Session in TS

Remove  the Single Session Restriction

  1. Click Start and type: Terminal Services Configuration [Enter] (the console will come up immediately while typing)
  2. Click Continue at the UAC prompt.
  3. Double click on the Restrict each user to a single session setting.
  4. Uncheck the setting.
  5. Click Apply and OK.

Note that if the setting has been changed while connected to the server in an RDP session, the session will need to be closed before another admin can share a Terminal Services session.

Philip Elder
MPECS Inc.
Microsoft Small Business Specialists
Co-Author: SBS 2008 Blueprint Book

*All Mac on SBS posts will not be written on a Mac until we replace our now missing iMac!

Windows Live Writer