Jump to content

Recommended Posts

Posted

I am setting up RDS for our staff to access a Session based desktop from home. There doesnt seem to be much info on the placement of the RD Gateway server. I read on older articles for 2008 Server that the RD Gateway should be in a DMZ. I also read that if you require your users to authenticate against AD then your RD Gateway Server should also be a member of the same AD.

 

How are you guys setting up your RDS Servers? Is it ok to put the RD Gateway server on the internal LAN or should it be in a DMZ? If a DMZ have you any guides on how to do this and which ports need to be open on the Firewall?

Posted

What sort of gateway you using? We use RemoteApps so only thing open is port 80/443 etc

 

If you're using the full gateway via 3389 etc it's recommended DMZ still

 

Steve

Posted
What sort of gateway you using? We use RemoteApps so only thing open is port 80/443 etc

 

If you're using the full gateway via 3389 etc it's recommended DMZ still

 

Steve

 

Haven't decided which way to go. We may just deploy RemoteApps and give staff Word/Excel/Powerpoint and SIMS or provide them with a Session based Remote Desktop.

Is it better/more secure to give them just RemoteApps?

 

With RemoteApps if we give them Word/Excel/Powerpoint can they get their usual mapped drives?

Posted

The programs run the same, as it's still running off the identical server. If it's mapped via GPO for "full RDS" desktop, it'll show for RemoteApps.

 

It just means less ports need opening, and as it's standard forms auth so helps against things like bruteforce blahblah

 

Steve

  • Thanks 1
Posted
The programs run the same, as it's still running off the identical server. If it's mapped via GPO for "full RDS" desktop, it'll show for RemoteApps.

 

It just means less ports need opening, and as it's standard forms auth so helps against things like bruteforce blahblah

 

Steve

That's good to know. RemoteApps looks like the way to go then.

Posted

It shouldn't make any difference on ports in reality, you can tunnel all of it over the gateway anyway so TCP 443 (and UDP 3391 if you want RemoteFX).

 

So full screen desktop or individually published apps - you shouldn't be allowing 3389 at all.

 

It depends how your users want to work, talk to them, POC and ask them what works best for them.

 

Someone on a mac would welcome SIMS in a window, someone on windows may prefer it in a window, or in a full screen with other windows apps they don't have locally.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...