Jump to content

Recommended Posts

Posted (edited)

EDIT: ALL THE BELOW IN THIS POST IS SORTED PLEASE SEE POST #11 FOR NEW QUESTION: http://www.edugeek.net/forums/windows-server-2008-r2/65818-2008r2-terminal-services.html#post588694

 

I'm trying to lock down our terminal server which is used for home access, it's only temporary while i finish bug testing remote app but it'd be handy to have running properly incase we need it...

 

I'm using a group policy loopback processing policy set to replace and these are my current issues:

Start Menu - Control panel, Administrative tools, Windows security

Disable Task manager

Start Menu redirection

Disable C: A: and D:

 

So at the moment on the main start menu i can't get rid of control panel or admin tools (not that they can do anything in it as it's all locked down to the extent the mmcs don't run) and the windows security selection which brings me to my next point... running task manager, in theory i don't think they'll be able to run task manager with the windows security bit done but i'd like to make sure by locking them out of that completely.

 

Start menu redirection, im trying to redirect them in the computer policy to a different start menu than they are usually redirected to but for some reason although the desktop redirection is working the start menu won't no matter what i set.

 

Disabling the drives i've set in GPO but for some reason that isn't taking effect!

 

The machine is running as a VM if that matters at all, i don't expect many people to be able to help too much with the start menu redirection but any idea why the others won't work? They are all set to various things in group policy but they aren't taking effect. (all set in the user section of the computers policy)

Edited by mrbios
Posted
never used gpresult before but i ran rsop.msc using a test user and it's not actually applying the policy at all, event viewer gives me nothing more than i already know as well. It's still trying to apply the User GPO and not overriding it with the loopback setting :/
Posted

Just disabled my new policy, enabled my old policy, old server 2003R2 server picks up the change straight away, server 2008R2 server does not.

 

Seems no matter what i do i can't get the server 2008R2 server to pickup that policy >_< same security settings on the policies etc so i can't see why it wouldn't apply. The stupid thing is that for some reason it's partially applied.........to the administrator account! WHAT THE HELL! (doesn't show up in rsop that it has, but something i've obviously done previously has applied to it as the start menu is redirected for administrator, and is stuck that way)

Posted

{ABD85540-7075-41C4-AD50-39E8BA891508} Domain.local/Domain Computers/Servers/SIMS Terminal Server Inaccessible

{0758C2F9-E923-47E9-924F-EA57A213C5AB} Domain.local/Domain Computers/Servers/SIMS Terminal Server Inaccessible

 

Unsure how i check if those two are infact the GPs im after but it's highly likely!

Posted
Ah i've partially fixed it, i copied the existing GPO, pasted it with the default security settings and it now picks it up. Only problem now is that desktop and start menu redirection aren't working ¬_¬
Posted (edited)

I know with our server, we block inheritance for other gpo's and just assign a gpo to the container that the servers in...takes a bit of fiddling though. if you like I can email a report of what our gpo does (which settings) pm if you would like.

 

this publishes anything in the C:\startmenu container to the start menu. (we use app-v and it publishes to this dir.) it also publishes my computer to the start menu, only giving them access to their Network area and any shares (readonly etc)

Edited by sacrej
Posted

Ah no worries, i've just got it all working now, copying the GPO and redoing i with default security worked a treat, for the start menu redirection i had some silly setting enabled i used to use on server 2003 (copied the previous 2003 GPO and just added to it to comply with server 2008R2) i think i've finshed that task now :D

 

Now on to convincing the SMT that the current school calendar is crap and needs replacing (excel spreadsheet edited by multiple people *spit spit spit*)..... :p

Posted (edited)

New Question same thread title applies......

 

Question 1.

This terminal server was setup initially to test the remote app capability of server 2008R2 and now that i've tested it i want to move forwards with it, currently the following roles are installed:

Remote Desktop Session Host

Remote Desktop Connection Broker

Remote Desktop Gateway

Remote Desktop Web Access

 

I want this server to be the server people connect to for the web front end of remote app, when an app is loaded i want it to load from a different server. Do i require just Remote Desktop Gateway on tis server or do i need the Web Access part as well? I'm unsure what session host and connection broker both do specifically and whether they are required for this functionality.

 

Question 2:

Once i've established that which roles do i require in order for the app end to be the remote app source as well as a server than can be directly remote desktoped to? The explanations of them all feel as though they overlap so i'm getting confused as to what is required for each area of functionality.

 

Question 3:

Next want this as secure as possible, i have a wildcard certificate for *.websitedomain.net can i use this certificate as the digital certificate on this or should i just use a self signed one?

 

Question 4:

Is there any way of getting remoteapp working properly in firefox etc? As it uses activex controls will it only ever be useable in IE?

Edited by mrbios
Posted

Not answer answer to all...but..

 

The connection broker i believe is used more in a farm situation with NLB. It also acts as a connection policy server, but depending how you set this up, we used normal GPO's to control this.

 

I would not advise having the gateway and session host on the same server. The gateway will be the initial point of connection, the session host is then the server that loads the app the users try to access. For access control, we allowed a large group of people onto the gateway, then permissioned access to each app and hid the irrelevant icons from display to each user.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...