27 Votes

 


What is a Remote Desktop Gateway

A Remote Desktop Gateway Server enables users to connect to remote computers on a corporate network from any external computer. The RD Gateway uses the Remote Desktop Protocol & the HTTPS Protocol to create a secure encrypted connection.

A 2012 RD Gateway server uses port 443 (HTTPS), which provides a secure connection using a Secure Sockets Layer (SSL) tunnel.

A Remote Desktop Gateway Provides The following Benefits:

  • Enables Remote Desktop Connections to a corporate network without having to set up a virtual private network (VPN).
  • Enables connections to remote computers across firewalls.
  • Allows you to share a network connection with other programs running on your computer. This enables you to use your ISP connection instead of your corporate network to send and receive data over a remote connection.

http://windows.microsoft.com/en-us/windows7/what-is-a-remote-desktop-gateway-server

Please see the following linkFor more information on deploying a Gateway on the perimeter network: http://blogs.msdn.com/b/rds/archive/2009/07/31/rd-gateway-deployment-in-a-perimeter-network-firewall-rules.aspx 

Deploying a remote desktop Gateway

Gateway1

To start the install, Click on the RD Gateway Icon Highlighted in green on the Deployment Overview.

gateway2

Select the server you want to install the role on.

gateway3

Enter the External FQDN in the SSL Certificate Name (for this example I am using a internal address)

gateway4

RDS Gateway is installing…………

gateway5

gateway6

Once the install is complete, you can use the links at the bottom of the install window to configure certificates and review the RD Gateway properties for the deployment.

gateway7

As highlighted in red, you can seen the Gateway certificate located in the deployment properties under certificates.

gateway8

Under the Tab RD Gateway, you can configure the login method and basic gateway settings.

gateway9

Once the gateway is installed you will see the RD Gateway symbol appear.

 

Configuring the Gateway Manager

gateway10

by right clicking on the local gateway server, you can open the properties.

gateway11

You can configure the advanced gateway settings by navigating to the Properties.

gateway12

The General tab allows you to configure maximum connection.

gateway13

The SSL Certificate tab allows you to import a external certificate, create a self-signed and import from a personal store. I would recommend that you assign all certificates and apply the RD Gateway Certificate last. This is the certificates are not modified by the certificate tab in the RDS deployment properties.

gateway14

The Transport Tab allows you to configure RCP-HTTP and the HTTP settings. You can change the defaults to meet corporate security requirements.

gateway15

The Remote Desktop Connection Authorisation Policies (RD CAP) store enables you to configure local or central NPS Services for centralised management.

gateway16

The Messaging tab is great for notifying users of outages and maintenance times or other administrator messages.

gateway17

Please see the hyperlink below for information on SSL Bridging and tunnelling.

http://www.isaserver.org/tutorials/Understanding_SSL_bridging_and_tunneling_within_ISA.html

gateway18

The Auditing tab allows you to select what to audit in the log files.

Gateway19

The Server Farm tab allows you to configure multiple Gateway servers for use in a farm (High Availability).

Gateway20

Connection Policies allow you to configure user access.

gateway21

gateway22

gateway23

You can  disable the redirection features for enhanced security.

gateway24

The Timeouts Tab allows you to limit client sessions.

gateway25

Resource authorisation Policies allow you to specify the network computers that users can connect to.

gateway26gateway27

You can define user access in user groups tab.

gateway28

The Network Resource tab is used to specify the network resources.

gateway29

The Allowed ports Tab enables you can change the ports to enhance security.

Creating Computer Groups

when creating a High available Connection broker configuration or a Remote desktop session server Farm you need to create server groups using the manage locally stored computer groups.

gateway30

gateway31

Click Create Group

Gateway32

enter the name and the description of the computer group

gateway33

For connection brokers and RDSH servers, you need to add the servers and the farm name as mentioned in this tab.