Jump to content

Recommended Posts

Posted

I have got the very basics in place all remote desktop services / roles are setup and working - yay.

 

I have installed a virtual Windows 7 pro in hyper-v and can connect to it - yay.

 

My question, which is very noobish is, how many virtual Windows 7 machines do I need to install in hyper-v. Can multiple users connect at the same time to the same virtual machine? or do they each need their own separately installed virtual os?

 

Cheers

Posted
install terminal services and it will create a virtual machine when one is required

ah I see and will play later.

 

Do I need separate Windows 7 licences for each users desktop on top of the RD CAL that I have for each user?

Posted
Unless you have a reason for going full VDI it could be easier and cheaper to just use Server 2008 R2 and grab some TS CALs, you need to license each W7 instance and these take up more resources than just another user session on a copy of server. You can get around some of this by using Server 2012 as the host and memory dedupe along with template VHDs but overall easier to just use terminal services on server 2008.
Posted

Sorry but I need some more clarification,

 

This is a small primary so not many users.

 

Unless you have a reason for going full VDI it could be easier and cheaper to just use Server 2008 R2 and grab some TS CALs

What you have just suggested is 100% what I want.

 

I have this on 2008r2 but might have over complicated the issue. Currently if I rdp remotely to a machine that is already in use it says it will log that user other off, so not what I am after.

 

What would you suggest I do to set it up the way you have suggested. Could you just outline what should be done. pm me if you prefer.

Posted

Pretty much you just need an install of Server 2008r2 with the terminal services role installed, you don't need hyper-v at all. The wizards should talk you through most of it and I think you get a 30 day trial before you have to add CALs.

 

Once you have this setup the users just remote into the server and each session is separated out, ie multiple people can log in to it at once and not kick others off. If the rest of school is Windows 7 with appropriate profiles and GPOs when they log on most things should be just as they would be on a normal station. Just install the programs you need them to have access to and grab some CALs from an MS supplier and you should be good.

 

Windows Server 2008 R2 Remote Desktop (RD) Services - Techotopia

 

You also get other cool things like remote desktop gateway which is great for sharing it online. Remote app can also allow you to just offer up a single application for stations especially handy if they are problematic apps that you would

 

TS Gateway Step-by-Step Guide

  • Thanks 1
Posted

Looks like I have gone overkill, Currently I have remote desktop services role installed with remote app manager, RD Gateway Manager, RD Session host, remote desktop services manager, and IIS. I also added the hyper-v role and installed windows 7 as a virtual machine.

 

Think I might wipe it all and start over.

Posted

not exhaustive but should give you the idea

 

vdi (virtual desktop infrastructure) 1 vm per person (or at least concurrent person) its effectively like giving everyone their own pc just they run on the server using the servers cpu/ram and you rdp into it from a n other device be it another pc ypad/android etc.

 

Plus points

its a full win7 (or whatever os you choose pc) and at least with server 2012 you can set them so once logged off for x ammount of time they revert to their standard state and you can apply updates to them all by remaking from the base image (so say you go from office 2010 to 2013 update your base image and it can be set to replace the used ones with that image) removes the need to msi packages out etc.user data is stored separate from the pc so no redirection is needed. Full workstation os so software compatability shouldnt be much of an issue. Redundancy if 1 vhd gets borked just replace it in mins.

 

negative points

licensing each vm needs a license (not sure if ees will cover this or not). For more than a few requires a server with lots of ram and processing power (disc space not so much with 2012 as you can have 20 vhd files and the server will only store the differences so its not 20*20gb its more like 1*20gb+4gb.

 

terminal server/remore desktop server

 

plus points

1 os for everyone so install say office 2013 once and its done. As its one os needs less ram/cpu/hdd as users are just connecting to sessions not a full pc. one server lic and x remote cals

 

negative points

 

its a server os so some software may not work and some software wont anyway. Audio/video playback is likely to be less good. server looks slightly different to workstation so some users may be confused. If that pc goes belly up tough (granted if your vdi host(s) do its the same )

Posted
Looks like I have gone overkill, Currently I have remote desktop services role installed with remote app manager, RD Gateway Manager, RD Session host, remote desktop services manager, and IIS. I also added the hyper-v role and installed windows 7 as a virtual machine.

 

Think I might wipe it all and start over.

 

a lot of that is only needed if you want apps via a browser (iis) or external access (RD Gateway Manager)

 

and hyper v isnt needed period

Posted

I'd start out with a single server and set up remote desktop services.

 

The licencing for RDS has a 120 day (I think that’s still current) grace period, which is plenty of time for you to find the right number of users for the school in question. The other consideration is what applications you need to run for the remote system. Personally I'd stick with the basics to start with (office, Internal web services etc.).

 

What’s the spec of the server your using? Is it Physical or virtual?

 

All in all, once the server is up and running, getting RDS working for some users shouldn’t take that long. Getting the licencing balance right will take a lot longer. It could be the case that this is already covered in your LEA/School Agreement…. But then again it might not.

Posted

Failed at the first part.

Followed this Windows Server 2008 R2 Remote Desktop (RD) Services - Techotopia

I installed remote desktop session host

then to test you should connect from a client using remote desktop client but I get a cert error,

 

'your remote desktop session failed because the remote computer cannot be authenticated'

 

cert error = 'A revocation check could not be performed for the certificate'

 

'You may not proceed....'

 

Odd thing is I can connect to an IIS ssl website on the same server and the cert gets authenticated.

Posted

Just a couple of thoughts on this.

 

VDI is covered by MDOP which is an extension to Software Assurance. EES is probably the cheapest way of licensing. (You can buy EES+MDOP). You can host the VMs on any hypervisor including ESXi and the free version of Hyper-V.

 

For best performance with VDI you'd probably want to use thin clients with RemoteFX support.

 

That said, Terminal Server is probably what the OP wants.

Posted

Plodding on with this. I am currently at the certificate import section following this - Configuring the TS Gateway Core Scenario

 

Question = which of the 3 certs I have from my cert company do I import at his stage, is it,

vpn.domain.area.sch.uk

ipsCAglobal

ipsCALEVEL1ca

 

 

 

  • To Install a certificate on the TS Gateway server
    Open the Certificates snap-in console. If you have not already added the Certificates snap-in console, you can do so by doing the following:
     
    • Click Start, click Run, type mmc, and then click OK.
    • On the File menu, click Add/Remove Snap-in.
    • In the Add or Remove Snap-ins dialog box, in the Available snap-ins list, click Certificates, and then click Add.
    • In the Certificates snap-in dialog box, click Computer account, and then click Next.
    • In the Select Computer dialog box, click Local computer: (the computer this console is running on), and then click Finish.
    • In the Add or Remove snap-ins dialog box, click OK.

     

    [*]In the Certificates snap-in console, in the console tree, expand Certificates (Local Computer), and then click Personal.

     

    [*]Right-click the Personal folder, point to All Tasks, and then click Import.

     

    [*]On the Welcome to the Certificate Import Wizard page, click Next.

     

    [*]On the File to Import page, in the File name box, specify the name of the certificate that you want to import, and then click Next.

     

    [*]On the Password page, do the following:

     

    • If you specified a password for the private key associated with the certificate earlier, type the password.
    • If you want to mark the private key for the certificate as exportable, ensure that Mark this key as exportable is selected.
    • If you want to include all extended properties for the certificate, ensure that Include all extended properties is selected.
    • Click Next.

     

    [*]On the Certificate Store page, accept the default option, and then click Next.

     

    [*]On the Completing the Certificate Import Wizard page, confirm that the correct certificate has been selected.

     

    [*]Click Finish.

Posted

YAY - got it working. Just tested by connecting from home as 2 different users, from 2 computers and all worked.

 

Currently only set up using the default settings from the links in this forum, so will need to look at locking it down a bit more.

 

Thanks to SYNACK for the initial links and sted for simple plain info. Also thanks to the rest of posters.

Posted
no problem. the only one i have uses a self signed cert as ive never looked into real ones (and a hacked hosts file) but thats partially due to ad domain being a .local and external being no domain lol. in my slight defence it was a test setup that just went live one day i will look intona domain dame and certs i assume it requires an alias to translate schhol.local to school.ac.uk or whatever and might make initial ssl less slow lol
Posted

I got hold of a free ssl cert for the school. I also did not need to do any host files hacks or changes, it worked from home using computer.domain.lan.

Going to look at locking it down to only domain computers etc. Might also put the rdp file on an encrypted memory stick. Also going to look at radius lockdown.

 

Very happy I got this far. Thanks

Posted

Now that RDS + gateway are working and users can access the 2008r2 sever as a desktop I am trying to get my head round some of the basics.

 

Installing Software, lets say Office 2010 and Sims.

 

Do I install them on the actual server as a normal install and then are they available for any user that might RDP to that server using RDS gateway?

 

Do they need to be installed as an app, which reading the MS info seems to add an icon to the desktop?

 

Or do I install then logged on as each user?

 

I have not tried any of the above as it will save me lots of time just to ask.

 

Cheers

Posted
there is an icon in control panel "install application on terminal server" (at least on 08r1) that you use for installing (so run that and point it at the installer file rather than run the installer direct) but other than that just install once as per normal
Posted

I been looking at some stuff about VDI on Friday and this morning. From what I see online, MS have made it really easy to go with VDI using Server 2012. One thing i dont get tho (prob coz i have never looked into VDI before and it's all new to me), is you still need a client PC with OS installed to connect to the VD - so what's the point of it?

Why not just have the client set up as 'per normal' and a lot less strain on the server? Or am i totally misunderstanding it?

Posted

@detjo, It's partly a question of where the processing power is. It's arguably cheaper buying huge amounts of processor power on the server than it is buying 30xhuge amounts of processing power on the desktop. Therefor you only need a £100-£200 thin client, possibly running a non MS OS, on the desktop vs. £300-£500(+) desktops running with Windows licensing.

 

The other this with both VDI's and (more so) Terminal Server, is from a tech support point of view it's much easier to manage from a central location. Things like software installs can become easier especially those that might have meant visiting each machine individually in the past.

Posted

hmm .. I see. Thanks, tmcd35 that makes sense.

So actually, this could also be used for running a VDI session on iPad (as it's running thru a browser) ?

 

There is great enthusiasm about getting iPads here at the moment but SMT main questions are: accessing/saving to MyDocs and printing. So VDI might be a solution?

Posted

Yes, but...

 

I'm yet to find any RDP client on iOS that I'm completely happy with. That and Windows really wasn't designed with a touchscreen experience in mind (and no Win8 hasn't altered my opinion on that). Technically do-able, but the question becomes why? and may lead to (can't believe it's me say this) is the iPad the right device?

 

Edit: Look at WebDAV to access "my docs" on an iOS device. Better solution than remote desktops.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...