Showing posts with label RD Gateway. Show all posts
Showing posts with label RD Gateway. Show all posts

Monday, 13 January 2014

RDWeb in Windows Server 2012 R2

If you have not seen RDWeb in Windows Server 2012 R2 yet, then a look at the feature along with the full Remote Desktop Services suite of abilities in Windows Server 2012 R2 is a must.

image

Our "Collaborate Anywhere" solution (sound familiar eh? ;) ) is based upon RDWeb and the AuthAnvil Secure Access Portal that we are investing heavily in.

We believe that Cloud has it's place however on-premises still provides the _same_ feature set and location flexibility to our clients that Cloud vendors extol to Cloud alone with the added benefit of data ownership and security.

Philip Elder
Microsoft Cluster MVP
MPECS Inc.
Co-Author: SBS 2008 Blueprint Book

Chef de partie in the SMBKitchen
Find out more at
Third Tier: Enterprise Solutions for Small Business

Thursday, 2 January 2014

RD Gateway and RemoteApp Error: Remote Desktop can't connect to the remote computer "RDS.Domain.Local" for one of these reasons:

We just finished setting up a Windows Server 2012 R2 Standard RDS server and began testing the RD Gateway, RDWeb, and RemoteApp features and hit this:

image

RemoteApp Disconnected

Remote Desktop can't connect to the remote computer "RDS.Domain.Local" for one of these reasons:

1) Your user account is not authorized to access the RD Gateway "remote.domain.ca"

2) Your computer is not authorized to access the RD Gateway "remote.domain.ca"

3) You are using an incompatible authentication method (for example, the RD Gateway might be expecting a smart card but you provided a password)

Contact your network administrator for assistance.

The third reason is out while the first two are not applicable since our access policies are set up correctly.

Our search brought us to:

Following Solution 1 we puzzled about trying to figure out where the NPS thing was!

Click on NAP in Server Manager and then right click on the server name. Choose Network Policy Server in the menu.

Once the NPS console comes up right click on the root node NPS (Local) and click Register server in Active Directory.

image

Click OK twice and then test again.

image

Good to go!

Philip Elder
Microsoft MVP
MPECS Inc.
Co-Author: SBS 2008 Blueprint Book

Chef de partie in the SMBKitchen
Find out more at
Third Tier: Enterprise Solutions for Small Business

Wednesday, 9 October 2013

SSL Certificates: CSR Decoder to Verify Settings

When it comes to creating a certificate request sometimes we can miss a character or typo something.

If the processing takes longer than expected and the certificate provider does not provide much more than a "Processing" status it may be a good idea to verify the settings in the CSR file.

The CSR Decoder site can do that:

We hit a snag with a CSR that was taking too long and sure enough there was a typo in the common name that caused it to hang up.

Philip Elder
MPECS Inc.
Microsoft Small Business Specialists
Co-Author: SBS 2008 Blueprint Book

Chef de partie in the SMBKitchen
Find out more at
www.thirdtier.net/enterprise-solutions-for-small-business/

Windows Live Writer

Friday, 8 March 2013

Some thoughts on possibly migrating to Windows Server 2012 Essentials and Cloud

This post is a copy of a comment left on Susan Bradley’s post here: A Social Question About the Future of SMB Servers.

In our move from SBS to the Stack we've seen about a 15% increase in overall licensing costs for our clients (Open Value Agreement with the 3 year spread payment option).

Most businesses can absorb a 15% uptake on their server side licensing costs. Those that can't have other problems needing to be dealt with first.

We've done a few 2012 Essentials with Exchange 2013 greenfield deploys and are relatively happy with the results barring a few deadly misses in Exchange 2013 RTM.

Many of you may have used our SBS 2003 to SBS 2011 Standard migration guide. It's one of the busiest pages on our blog. One of the reasons that guide and the others that we have was put together was due to the terrible documentation from so many different Microsoft sources for the whole process.

Why should the SBS to W2012E migration documentation be any different? It is not, in fact as already mentioned it is worse than before.

The biggest drawback to bringing a well thought-out SBS Standard setup into a W2012E via migration is the huge step back we would take with the AD/GPO structure.

SBS 2003, 2008, and 2011 Standard all had a beautiful OU structure that was easy to manage with simple to deploy targeted GPO settings.

With W2012E we lose all of that and in the end had to resort to WMI filtering to gain some of the targeting we had previously.

Since RDS has been a part of our client's licensing makeup since Day 1 with us we will be avoiding W2012E. RDWeb on 2012 or even 2008 R2 works well as a landing page. Users can then open their RemoteApp or log on to their internal desktop PC or dedicated VM.

DirectAccess gives our clients the ability to access their files seamlessly. Again, all are on Desktop OS SA+MDOP with Enterprise on their laptops. So, this is a fairly seamless transition from VPN.

Yes, the solution stack is a bit more complex. But, and I mean BUT, we gain access to the ability to put together solutions that we could only have dreamed of with the one-box solution SBS gave us.

Is W2012E a worthy successor of SBS? In all reality we are comparing Apples to Oranges here. IMNSHO W2012E is a blip on the road to the Cloud in Microsoft's eyes.

It is up to us to build and provide the best on-premises SBS-Like IT Solution our clients need.

While many Cloud vendors, including Microsoft, can’t seem to see beyond their particular vision for SMB IT over the next five to ten years those of us on the ground have a _very different_ vision of what SMB IT is all about.

To us, the Cloud tends to be a cookie cutter solution. That is, the customer must fit their business structures _into_ the Cloud Vendor’s product confines.

SMB IT is anything but cookie cutter.

When we are invited into a small business to have a chat with a business owner or business IT contact about their IT needs and how to address them we have a distinct advantage over Cloud.

  1. Face-to-Face time. We build a business relationship with our business contacts _and_ their users.
    • This is one area of SMB IT that surveyors, enterprise oriented vendors, and others always seem to miss or outright get wrong.
  2. We tailor an IT Solution to the client’s very particular needs.
    • We don’t modify their business processes to fit a cookie-cutter solution.

The idea here for us is to take what the business has already built up in the way of business processes and workflows and help them grow more efficient.

The attitude that SMB IT belongs in the Cloud, whether it be from Microsoft, Cloud vendor, or Cloud Proponent is at best misplaced.

I really wish folks would stop telling us that on-premises IT Solutions for SMB should not exist anymore.

Ultimately, the decision is up to the small business owner and IT management to decide what is best for their company.

We prefer to give SMB IT an on-premises virtualized solution stack that incorporates all of the SBS Standard goodness across two to four virtual machines (VMs) as an option and then _let the market decide_ whether Cloud or on-premises is right for them.

The EOLd Essential Business Server in a virtualized setting would have been a great product to build a virtualized product stack today with almost the entire greenfield deploy being wizard driven. A solid migration story may have changed that product’s longevity too.

It is our end-game here at MPECS Inc. to provide the best on-premises solution stack that our client’s IT budget can buy.

And, with our blog here, as well as others, and the SMBKitchen initiative it is our goal to provide SMB IT Solution Providers with the best Microsoft Stack solution _your_ clients can buy along with the skillset needed to properly deploy and maintain that solution set!

Providing SMB businesses with an SMB IT Solution built on the Microsoft Stack that runs stable and provides the same SBS like experience they are all used to is one of the _only_ ways we can push back against the Cloud’s onrush.

Remember, value is not about the lowest price. If it was, Wal-Mart would be the _only_ retailer on the block and Mercedes Benz, BMW, and Cadillac would be out of business.

And, cost of “ownership” is always higher when someone else owns the equipment. That is one reality that has yet to be made concrete in the SMB Cloud initiatives.

One more thing, Susan and I have been having an ongoing conversation since the above was posted. Might be wise to have a boo yourself. :)

Philip Elder
MPECS Inc.
Microsoft Small Business Specialists
Co-Author: SBS 2008 Blueprint Book

Chef de partie in the SMBKitchen
Find out more at
www.thirdtier.net/enterprise-solutions-for-small-business/

Windows Live Writer

Wednesday, 14 September 2011

VDI: What version of Windows 7 Desktop OS to Install?

When it comes to setting up a client’s Virtual Desktop Infrastructure (VDI), we have already configured their Software Assurance plus MDOP to gain access to VDI.

So, do we install Windows 7 Professional or Windows 7 Enterprise into those VMs?

In many cases there will be no need for Enterprise to be installed for regular VM access.

However, there will be some cases where Enterprise does make sense. One is for a firm or company that uses multiple monitors on their remote and local desktop.

Windows 7 Enterprise and Ultimate give us access to the ability to RDP into the VM and utilize multiple monitors at the source.

Note that both endpoints in the RDP connection must be either Enterprise or Ultimate. No other Windows desktop OS versions support this RDP capability.

Now, depending on the Internet connection the client uses we would tailor a GPO with RDP related settings to limit bit depth to 15bpp and the number of monitors to 2 for smaller connections while we would up the number of monitors for larger connections.

Also note that users connecting to their office desktop via the SBS 2011 Remote Web Access portal that have two monitors hooked up to their home machine will get both monitors in the remote session if using Ultimate at home and Enterprise/Ultimate on their office desktop.

We find that clients that utilize multiple monitors see their user’s productivity increase exponentially.

Philip Elder
MPECS Inc.
Microsoft Small Business Specialists
Co-Author: SBS 2008 Blueprint Book

*Our original iMac was stolen (previous blog post). We now have a new MacBook Pro courtesy of Vlad Mazek, owner of OWN.

Windows Live Writer

Monday, 18 July 2011

SBS 2011 – Remote Desktop Gateway Management

The RD Gateway services are installed and configured by default during the SBS 2011 OS install and then by the Getting Started Tasks Wizards in the SBS Console.

Technically, we are licensed to use the RD Gateway service via the Remote Web Access portal.

If we create RDP files to gain direct access to our desktops on the SBS network or we install and configure an RDS server then we are required to have RDS CALs for each user.

When we have RD Gateway services being utilized in this manner though we may require access to the RD Gateway service.

To do so, we need to install the RD Gateway UI via an elevated command prompt.

  • dism /online /Enable-Feature:Gateway-UI.

Note that there will be some errors that come up when opening the RD Gateway console that can be safely ignored. The errors are SBSisms.

Hat Tip: Susan Bradley

Philip Elder
MPECS Inc.
Microsoft Small Business Specialists
Co-Author: SBS 2008 Blueprint Book

*Our original iMac was stolen (previous blog post). We now have a new MacBook Pro courtesy of Vlad Mazek, owner of OWN.

Windows Live Writer

Friday, 8 July 2011

Providing IT Support – Out-of-Band Management Required

A paraphrase of a post to the SBS2K Yahoo Group.

In our opinion a server should _never_ be deployed without iDRAC Enterprise, iLO Advanced, Intel RMM, or other out-of-band (OOB) device. Period.

Professional grade tools for professionals.

We get:

  • KVM, USB, and drive redirection to the server.
  • BIOS, Firmware, RAID BIOS, etc access.
  • BMC Management and sensor logs/data.
  • Power cycle and reset ability (frozen OS).
  • At-a-glance view of all firmware versions.

What this does for us:

  • Immediate access to the _console_
  • No travel time delays ... response is quick.
  • No need for client intervention in most cases.

When patching or working on servers we create two connections to the box. One via RD Gateway and one via OOB. It is our preference to have physical access to that box at all times.

With the lack of a speaker on the Dell PERC RAID controllers and Open Manage may or may not e-mailing us about a failed drive we prefer to watch all reboot cycles for any anomalies.

If there is a failure, we can recover that server without any client intervention after the tier 1 tech has done their stuff.

I am sorry, but there is something totally unprofessional about, "I am sorry Mr. Customer, but could you sit at the server and see why I am locked out?" Or having to call a client’s user or contact in before or after business hours to find out why something broke. As IT Professionals we need to set the bar higher than that.

With gas at $1.10/Litre (US Gal = 3.78L, IMP Gal = 4.54L) here and rising at this time _not_ having to travel to client sites for out of scope work is a great thing.

Why?

Because they then _do_ see us when we are there for _positive_ things like rotating their backups or our bi-weekly "how are things?" visit (billable as soon as they say, "Can you fix this?" :*) ).

This aspect more than reinforces our _good_ presence in their business. Thus it strengthens our business relationship with our client contact and their users as we are seen and heard when things are good.

Philip Elder
MPECS Inc.
Microsoft Small Business Specialists
Co-Author: SBS 2008 Blueprint Book

*Our original iMac was stolen (previous blog post). We now have a new MacBook Pro courtesy of Vlad Mazek, owner of OWN.

Windows Live Writer

Tuesday, 31 May 2011

SBS 2011 – Remote Desktop Gateway Not Available After Update Reboot?

We are in the process of running updates on our newly migrated to SBS 2011 server.

After the server came up from its post update install reboot every logon attempt came up with a “Remote Desktop Gateway service is not available” error.

We flipped over to the Intel Remote Management Module 3 KVM session to see what was going on (we always open a KVM session to watch the server’s reboot cycle) and found the SBS 2011 CTRL+ALT+DEL logon screen.

So, everything looked normal there.

After logging into the KVM session we tried to log on via RDP one more time and it worked.

A look into the Services MMC in the SBS Native Tools Console’s Computer node turned up the following:

image

  • Remote Desktop Gateway: Started – Automatic (Delayed Start)

Ah, not to panic then. We just need to be a bit more patient as things come up after that boot cycle! :)

Philip Elder
MPECS Inc.
Microsoft Small Business Specialists
Co-Author: SBS 2008 Blueprint Book

*Our original iMac was stolen (previous blog post). We now have a new MacBook Pro courtesy of Vlad Mazek, owner of OWN.

Windows Live Writer