DESKTOP

Windows Server 2008 R2 : Managing Remote Access to Your Server - Understand Remote Desktop Services

7/17/2012 3:03:54 PM
One of the improved areas in Windows Server 2008 R2 is Remote Desktop Services (RDS). RDS is not fundamentally new; in prior versions of Windows, RDS was known as Terminal Services. Table 1 shows the Terminal Services features from Windows Server 2008 with the newly named equivalent services in Windows Server 2008 R2.
Table 1. Remote Desktop Services
Windows 2008 Terminal ServicesWindows Server 2008 R2 RDS
Terminal ServerRemote Desktop Session Host
Terminal Services LicensingRemote Desktop Licensing
Terminal Services Session BrokerRemote Desktop Connection Broker
Terminal Services GatewayRemote Desktop Gateway
Terminal Services Web AccessRemote Desktop Web Access

In addition to these new role services in Windows Server 2008 R2 RDS, Windows Server 2008 R2 also has a new service called Remote Desktop Virtualization Host. This service provides your organization with the ability to create a Virtual Desktop Infrastructure (VDI). VDI is an architectural model where a desktop OS runs in a server-based virtual machine environment. This allows you to connect to the desktop using the Remote Desktop Protocol (RDP) and work with the desktop as if the desktop were locally on the user's physical machine.

1. Understand the Remote Desktop Services Role Services Requirements

After you have determined which RDS role services you want to use on your server, you need to install appropriate prerequisite services for the roles. Table 2 lists which RDS role services require additional services.

Table 2. Role Services Prerequisites
RDS Role ServicePrerequisites
Remote Desktop Virtualization HostThis new role to Windows Server 2008 R2 requires you have, the Hyper-V role installed on your server. In combination with other RDS role services, this service is key to providing your network with a VDI.
Remote Desktop Connection BrokerThis role service requires your server be a member of a domain before you can install the service. If the Windows Server 2008 R2 server is not a member of a domain, you will see a message similar to Figure 1.
Remote Desktop GatewayThis role service requires the Web Server role, which includes IIS 6 management compatibility for the metabase. Also, this will install IIS security including basic Windows authentication, and client certificate mapping authentication. Additionally, it requires the Network Policy Server and the RPC over HTTP Proxy feature.
Remote Desktop Web AccessThis role service requires the Web Server role, which includes common HTTP features (HTTP Redirection) and Windows authentication for security. Additionally, some IIS 6 management compatibilities for the metabase are required.

Figure 1. RD Connection Broker error

2. Install Additional Role Services and Prerequisites for Remote Desktop Services

The installation for Remote Desktop Servers can be easy if you are just installing the core Remote Desktop Session Host or can be complicated if you choose to install all the role services. In this section, you will see some of the additional choices you will have when you install other RDS role services.

  1. To open Server Manager, select Start => Administrative Tools => Server Manager.

  2. Click Roles in the tree menu on the left.

  3. Click Add Roles in the details pane on the right to begin installing Remote Desktop Services.

  4. On the Add Roles Wizard welcome page, click Next. You can also select "Skip this page by default" to ignore the page for future role installations.

  5. On the Select Server Roles page, select Remote Desktop Services. Then click Next.

  6. Read the welcome screen, and then click Next.

  7. On the Select Roles Services page, select which role services you need to install.

Depending on what role services you have selected, you may see additional choices during your installation. If you choose to install these roles after you have already installed the core Remote Desktop Services, you will need to add role services via Server Manager. Whether you add the role services during your initial install of RDS or after you have installed RDS, the process is similar.

2.1. Install Remote Desktop Gateway

Remote Desktop Gateway provides an access mechanism for your Windows Server 2008 R2 Remote Desktop Services via the Internet. The RD Gateway allows your users who are outside your network to securely connect to the RDS server with the SSL protocol over the Internet without having to use a VPN.

When you make the choice to install Remote Desktop Gateway, you may see a screen similar to Figure 2 prompting you to install the prerequisite services.

Figure 2. Remote Desktop Gateway prerequisites

To add the Remote Desktop Gateway service after you have installed RDS, follow these steps:

  1. To open Server Manager, select Start => Administrative Tools => Server Manager.

  2. Expand Roles by clicking the + sign, and click Remote Desktop Services.

  3. Right-click Remote Desktop Services, and select Add Role Services.

  4. On the Add Role Services screen, select Remote Desktop Gateway.

  5. Click Add Required Role Services (if prompted).

  6. Click Next in the Add Role Services screen.

  7. Select your server certificate required for the SSL communication between clients and the Remote Desktop Gateway server, and click Next.

  8. Select Now if you want to configure your connection authorization policy (CAP). The RD Gateway server requires a CAP allowing you to determine which users are allowed to use the gateway. You can configure these later by selecting Later. Select Now, and then click Next.

  9. Click Add if you want to add groups allowed to use your RD Gateway server. By default administrators are the only group allowed to connect. After you have added your groups, click Next.

  10. Provide a name for your CAP, and you can also choose which authentication mechanism you want to use; by default you will see password and smart card. You can choose one or the other or both. After you have made your selection, click Next.

  11. A part of your CAP is also the Resource Authorization Policy (RAP). The RAP allows you to control which computers a user may access via the gateway. You can choose a preconfigured group of computers, or you can choose all computers on the network. Choosing the All option will allow users through the gateway to connect any computer they have permissions to on your network, so you want to use this option with caution. If someone compromises the gateway, they will be able to access any computer on your network. After you have made your selection, click Next.

    If you have installed the prerequisites prior to installing the Remote Desktop Gateway role, you may not see the following steps.

  12. On the Introduction to Network Policy and Access Services page, review the information, and then click Next.

  13. Review the installed role services, and click Next.

  14. On the Introduction to Web Server (IIS) page, review the information, and then click Next.

  15. Review the installed role services, and click Next.

  16. Review the confirmation screen, and then click Install.

  17. Review the summary screen, and click Close.

2.2. Install Remote Desktop Web Access

Remote Desktop Web Access provides a way for your users to access your RDS applications via a website on your network. This allows your users to use a browser to connect and leverage RDS.

When you make the choice to install Remote Desktop Web Access, you may see a screen similar to Figure 3 prompting you to install the prerequisite services.

Figure 3. Remote Desktop Gateway prerequisites

To add the Remote Desktop Gateway service after you have installed RDS, follow these steps:

  1. To open Server Manager, select Start => Administrative Tools => Server Manager.

  2. Expand Roles by clicking the + sign, and click Remote Desktop Services.

  3. Right-click Remote Desktop Services, and select Add Role Services.

  4. On the Add Role Services screen, select Remote Desktop Web Access.

  5. Click Add Required Role Services (If Prompted).

  6. Click Next in the Add Role Services screen.

    If you installed the prerequisites prior to installing the RD Web Access, you may not see the following steps.

  7. Review the installed role services, and click Next.

  8. On the Introduction to Web Server (IIS) page, review the information, and then click Next.

  9. Review the installed role services, and click Next.

  10. Review the confirmation screen, and then click Install.

  11. Review the summary screen, and click Close.

Other  
  •  Windows Server 2008 R2 : Perform Backup and Recovery with Command Tools
  •  Elgato Thunderbolt Ssd 120gb
  •  CM Storm – Quick Fire Rapid
  •  By Design: Just Mobile Accessory = Efficiency!
  •  Big Print Possible
  •  Too Many Driver Updates
  •  PNY – Nvidia GeForce GTX 670 2GB
  •  Coolermater Hyper 412 Slim CPU Cooler
  •  Asus Rog Tytan CG8565 - Clash Of The Tytan
  •  Asus EEEPC X101CH - A Place For Netbooks?
  •  MacBook Pro with Retina display screen release
  •  MacBook Air and Pro are upgraded with Core i Ivy Bridge and USB 3.0
  •  Water Cools The PC Better
  •  Acer Aspire Timeline Ultra M3-581TG : Ultra-Size, Ultra-Power
  •  MSI GT70 : Turbo-Charged Gaming
  •  Kingston HyperX BLU 8GB RAM : The Blu of affordability and performance
  •  Kingston HyperX 3K SSD : SSD For The Budget Conscious
  •  AMD Radeon HD7750 : Single slot awesomeness
  •  HP Omni 27
  •  WD's My Passport (2TB) - Never leave home without it
  •  
    Top 10
    Tracking Results and Measuring Success : Competitive and Diagnostic Search Metrics (part 7) - Temporal Link Growth Measurements
    Tracking Results and Measuring Success : Competitive and Diagnostic Search Metrics (part 6) - Web Traffic Comparison
    Tracking Results and Measuring Success : Competitive and Diagnostic Search Metrics (part 5) - Tracking the Blogosphere, Search Engine Robot Traffic Analysis
    Tracking Results and Measuring Success : Competitive and Diagnostic Search Metrics (part 4) - Rankings, Crawl Errors
    Tracking Results and Measuring Success : Competitive and Diagnostic Search Metrics (part 3) - Measuring the value of a link
    Tracking Results and Measuring Success : Competitive and Diagnostic Search Metrics (part 2) - Search-engine-supplied tools, Third-party link-measuring tools
    Tracking Results and Measuring Success : Competitive and Diagnostic Search Metrics (part 1) - Site Indexing Data
    Windows Vista : Migrating User State Data - Developing Migration Files, Using USMT in BDD 2007
    Windows 7 : Sharing Resources on a Network - Using Public Folders, Identifying Shared Folders, Sharing a Printer
    Windows 7 : Sharing Resources on a Network - Windows 7 Homegroups
    Most View
    Designing a Windows Server 2008 R2 Active Directory : Choosing a Domain Structure
    Personalizing Windows 8 : Tweaking Your Touch Experience
    Filemaker Go 12 For Ipad
    Windows 8's Unexpected Features (Part 3)
    MSI R7970 Lightning - A Powerful Card with Some Great New Ideas
    The .NET Security Architecture
    Befriend Digital Zoom
    Programming Microsoft SQL Server 2005: Overview of SQL CLR - Visual Studio/SQL Server Integration
    Identifying the Technical Goals and Objectives to Implement Windows Server 2008 R2
    Installing Exchange Server 2010 : Installing dedicated server roles
    Java Mobile Edition Security : Permissions and User Controls
    Windows Server 2003 : Securing and Troubleshooting Authentication
    Control Your PC With Your Phone (Part 1)
    Shoot Your Best-Ever Portraits (Part 3) - Location setups
    The Download Directory (Part 3) - A-PDF Split 3.6 & IsMyLcdOK 1.66
    LG IPS235V - An affordable 23-inch full HD LCD
    IIS 7.0 : Using Command Line Tools - Getting Started with Appcmd (part 2) - Understanding Appcmd Output, Using Range Operators
    Sony Xperia Active : For outdoor sports
    The 50 Best Headphones You Can Buy (Part 9)
    Linux Expert Advice – May 2012 (Part 1) - Configure defaut programs