<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Things Falling Off Aircraft (TFOA) &#187; R2</title>
	<atom:link href="http://alittlestrange.com/tfoa/tag/r2/feed/" rel="self" type="application/rss+xml" />
	<link>http://alittlestrange.com/tfoa</link>
	<description>- and other technical difficulties</description>
	<lastBuildDate>Fri, 11 Feb 2011 01:10:47 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0.5</generator>
		<item>
		<title>Intro to Windows 2008 R2 Remote Desktop Gateway</title>
		<link>http://alittlestrange.com/tfoa/2009/11/06/intro-to-windows-2008-r2-remote-desktop-gateway/#utm_source=feed&#038;utm_medium=feed&#038;utm_campaign=feed</link>
		<comments>http://alittlestrange.com/tfoa/2009/11/06/intro-to-windows-2008-r2-remote-desktop-gateway/#comments</comments>
		<pubDate>Fri, 06 Nov 2009 23:56:50 +0000</pubDate>
		<dc:creator>Bobby Shea</dc:creator>
				<category><![CDATA[Microsoft]]></category>
		<category><![CDATA[Windows 2008]]></category>
		<category><![CDATA[R2]]></category>
		<category><![CDATA[RDP]]></category>
		<category><![CDATA[Remote Acces]]></category>

		<guid isPermaLink="false">http://alittlestrange.com/tfoa/2009/11/06/intro-to-windows-2008-r2-remote-desktop-gateway/</guid>
		<description><![CDATA[google_ad_client = "pub-0267487074173409"; google_ad_width = 468; google_ad_height = 60; google_ad_format = "468x60_as"; google_ad_type = "image"; google_ad_channel = "7935081104"; google_color_border = "#000000"; google_color_bg = "#FFFFFF"; google_color_link = "#0000cc"; google_color_text = "#000000";...]]></description>
			<content:encoded><![CDATA[<div style=" text-align: center;  margin: 8px; ">
				<script type="text/javascript">
				google_ad_client = "pub-0267487074173409";
				google_ad_width = 468;
				google_ad_height = 60;
				google_ad_format = "468x60_as";
				google_ad_type = "image";
				google_ad_channel = "7935081104";
				google_color_border = "#000000";
				google_color_bg = "#FFFFFF";
				google_color_link = "#0000cc";
				google_color_text = "#000000";
				google_color_url = "#008000";
				google_ui_features = "rc:6";
				</script>
				<script type="text/javascript" src="http://pagead2.googlesyndication.com/pagead/show_ads.js"></script>
			</div><div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a title='Original Link: http://api.tweetmeme.com/share?url=http%3A%2F%2Falittlestrange.com%2Ftfoa%2F2009%2F11%2F06%2Fintro-to-windows-2008-r2-remote-desktop-gateway%2F'  href="http://alittlestrange.com/tfoa/?BF_xil0L"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Falittlestrange.com%2Ftfoa%2F2009%2F11%2F06%2Fintro-to-windows-2008-r2-remote-desktop-gateway%2F&amp;style=normal&amp;b=2" height="61" width="50" /><br />
			</a>
		</div>
<p>     Remote access to your servers and workstations through terminal services or RDP is an easy way of doing work away from the office. However, without taking into consideration the security of these connections you are opening up a fairly large whole for someone to exploit. There are many applications and scripts available that a would be attacker can use to gain access to these terminal servers if you simply opened up port 3389 to the rest of the world. Windows 2008 introduced the Terminal Server Gateway and is rebranded as the Remote Desktop Gateway in R2. By using this gateway, you not only provide pre-authorized access to you terminal server, you also gain the benefit of using RPC over HTTPS, eliminating the need for additional ports to be open on you firewall and the ability to use RDP behind most corporate firewalls using port 443.</p>
<p><span id="more-495"></span></p>
<p>I will explain the steps necessary to configure this service as well as the RDP client in order to access your servers in a more secure manner.</p>
<p>Open Server Manager and select Roles –&gt; Add Roles</p>
<p><a href="http://alittlestrange.com/tfoa/files/2009/11/image.png#utm_source=feed&amp;utm_medium=feed&amp;utm_campaign=feed"><img style="border-bottom: 0px; border-left: 0px; display: inline; border-top: 0px; border-right: 0px" title="image" src="http://alittlestrange.com/tfoa/files/2009/11/image_thumb.png" border="0" alt="image" width="240" height="106" /></a></p>
<p>Select “Remote Desktop Services” from the role list</p>
<p><a href="http://alittlestrange.com/tfoa/files/2009/11/image1.png#utm_source=feed&amp;utm_medium=feed&amp;utm_campaign=feed"><img style="border-bottom: 0px; border-left: 0px; display: inline; border-top: 0px; border-right: 0px" title="image" src="http://alittlestrange.com/tfoa/files/2009/11/image_thumb1.png" border="0" alt="image" width="240" height="135" /></a></p>
<p>And “Remote Desktop Gateway” from Role Services</p>
<p><a href="http://alittlestrange.com/tfoa/files/2009/11/image2.png#utm_source=feed&amp;utm_medium=feed&amp;utm_campaign=feed"><img style="border-bottom: 0px; border-left: 0px; display: inline; border-top: 0px; border-right: 0px" title="image" src="http://alittlestrange.com/tfoa/files/2009/11/image_thumb2.png" border="0" alt="image" width="240" height="112" /></a></p>
<p>You will be prompted to add additional services. Click “Add Required Role Services” and click Next</p>
<p><a href="http://alittlestrange.com/tfoa/files/2009/11/image3.png#utm_source=feed&amp;utm_medium=feed&amp;utm_campaign=feed"><img style="border-bottom: 0px; border-left: 0px; display: inline; border-top: 0px; border-right: 0px" title="image" src="http://alittlestrange.com/tfoa/files/2009/11/image_thumb3.png" border="0" alt="image" width="244" height="123" /></a></p>
<p>When prompted to Choose a Server Authentication Certificate for SSL select “Choose a certificate for SSL encryption later”. We do not currently have a certificate loaded and need IIS to generate the request which we will take care of later in this tutorial.</p>
<p><a href="http://alittlestrange.com/tfoa/files/2009/11/image4.png#utm_source=feed&amp;utm_medium=feed&amp;utm_campaign=feed"><img style="border-bottom: 0px; border-left: 0px; display: inline; border-top: 0px; border-right: 0px" title="image" src="http://alittlestrange.com/tfoa/files/2009/11/image_thumb4.png" border="0" alt="image" width="244" height="181" /></a></p>
<p>When prompted to Create Authorization Policy for RD Gateway select “Later”</p>
<p><a href="http://alittlestrange.com/tfoa/files/2009/11/image5.png#utm_source=feed&amp;utm_medium=feed&amp;utm_campaign=feed"><img style="border-bottom: 0px; border-left: 0px; display: inline; border-top: 0px; border-right: 0px" title="image" src="http://alittlestrange.com/tfoa/files/2009/11/image_thumb5.png" border="0" alt="image" width="244" height="181" /></a></p>
<p>On the “Network Policy and Access Services” Select Role Services page ensure the “Network Policy Server” is selected.</p>
<p><a href="http://alittlestrange.com/tfoa/files/2009/11/image6.png#utm_source=feed&amp;utm_medium=feed&amp;utm_campaign=feed"><img style="border-bottom: 0px; border-left: 0px; display: inline; border-top: 0px; border-right: 0px" title="image" src="http://alittlestrange.com/tfoa/files/2009/11/image_thumb6.png" border="0" alt="image" width="240" height="101" /></a></p>
<p>On the “Web Services (IIS)” Select Role Services accept defaults.</p>
<p><a href="http://alittlestrange.com/tfoa/files/2009/11/image7.png#utm_source=feed&amp;utm_medium=feed&amp;utm_campaign=feed"><img style="border-bottom: 0px; border-left: 0px; display: inline; border-top: 0px; border-right: 0px" title="image" src="http://alittlestrange.com/tfoa/files/2009/11/image_thumb7.png" border="0" alt="image" width="240" height="151" /></a></p>
<p>On the “Confirm Installation Selections” page ignore the 2 warnings as they will be addressed later.</p>
<p><a href="http://alittlestrange.com/tfoa/files/2009/11/image8.png#utm_source=feed&amp;utm_medium=feed&amp;utm_campaign=feed"><img style="border-bottom: 0px; border-left: 0px; display: inline; border-top: 0px; border-right: 0px" title="image" src="http://alittlestrange.com/tfoa/files/2009/11/image_thumb8.png" border="0" alt="image" width="240" height="131" /></a></p>
<p>Once complete it is time to move onto configuration.</p>
<p><a href="http://alittlestrange.com/tfoa/files/2009/11/image9.png#utm_source=feed&amp;utm_medium=feed&amp;utm_campaign=feed"><img style="border-bottom: 0px; border-left: 0px; display: inline; border-top: 0px; border-right: 0px" title="image" src="http://alittlestrange.com/tfoa/files/2009/11/image_thumb9.png" border="0" alt="image" width="240" height="130" /></a></p>
<p><strong>Generate SSL Certificate:</strong></p>
<p>Open Server Manager –&gt; Web Server (IIS) –&gt; Internet Information Services (IIS) –&gt; Hostname –&gt; Server Certificates</p>
<p><a href="http://alittlestrange.com/tfoa/files/2009/11/image10.png#utm_source=feed&amp;utm_medium=feed&amp;utm_campaign=feed"><img style="border-bottom: 0px; border-left: 0px; display: inline; border-top: 0px; border-right: 0px" title="image" src="http://alittlestrange.com/tfoa/files/2009/11/image_thumb10.png" border="0" alt="image" width="244" height="166" /></a></p>
<p>I have an Enterprise CA so I am selecting “Create Domain Certificate” if you needed to use a third party CA you would select “Create Certificate Request” (3rd party Certificates are not covered in this document)</p>
<p><a href="http://alittlestrange.com/tfoa/files/2009/11/image11.png#utm_source=feed&amp;utm_medium=feed&amp;utm_campaign=feed"><img style="border-bottom: 0px; border-left: 0px; display: inline; border-top: 0px; border-right: 0px" title="image" src="http://alittlestrange.com/tfoa/files/2009/11/image_thumb11.png" border="0" alt="image" width="244" height="95" /></a></p>
<p>Fill in your appropriate details</p>
<p><a href="http://alittlestrange.com/tfoa/files/2009/11/image12.png#utm_source=feed&amp;utm_medium=feed&amp;utm_campaign=feed"><img style="border-bottom: 0px; border-left: 0px; display: inline; border-top: 0px; border-right: 0px" title="image" src="http://alittlestrange.com/tfoa/files/2009/11/image_thumb12.png" border="0" alt="image" width="240" height="131" /></a></p>
<p>Select your Online Certificate Authority</p>
<p><a href="http://alittlestrange.com/tfoa/files/2009/11/image13.png#utm_source=feed&amp;utm_medium=feed&amp;utm_campaign=feed"><img style="border-bottom: 0px; border-left: 0px; display: inline; border-top: 0px; border-right: 0px" title="image" src="http://alittlestrange.com/tfoa/files/2009/11/image_thumb13.png" border="0" alt="image" width="240" height="131" /></a></p>
<p><strong>Assign Certificate to the RD Gateway</strong></p>
<p>Server Manager –&gt; Remote Desktop Services –&gt; RD Gateway Manager –&gt; Hostname –&gt; View or modify certificate properties.</p>
<p><a href="http://alittlestrange.com/tfoa/files/2009/11/image14.png#utm_source=feed&amp;utm_medium=feed&amp;utm_campaign=feed"><img style="border-bottom: 0px; border-left: 0px; display: inline; border-top: 0px; border-right: 0px" title="image" src="http://alittlestrange.com/tfoa/files/2009/11/image_thumb14.png" border="0" alt="image" width="240" height="91" /></a></p>
<p>Select “Import Certificate”</p>
<p><a href="http://alittlestrange.com/tfoa/files/2009/11/image15.png#utm_source=feed&amp;utm_medium=feed&amp;utm_campaign=feed"><img style="border-bottom: 0px; border-left: 0px; display: inline; border-top: 0px; border-right: 0px" title="image" src="http://alittlestrange.com/tfoa/files/2009/11/image_thumb15.png" border="0" alt="image" width="217" height="244" /></a></p>
<p>Import the recently created certificate</p>
<p><a href="http://alittlestrange.com/tfoa/files/2009/11/image16.png#utm_source=feed&amp;utm_medium=feed&amp;utm_campaign=feed"><img style="border-bottom: 0px; border-left: 0px; display: inline; border-top: 0px; border-right: 0px" title="image" src="http://alittlestrange.com/tfoa/files/2009/11/image_thumb16.png" border="0" alt="image" width="244" height="120" /></a></p>
<p><strong>Create connection authorization policy</strong></p>
<p><a href="http://alittlestrange.com/tfoa/files/2009/11/image17.png#utm_source=feed&amp;utm_medium=feed&amp;utm_campaign=feed"><img style="border-bottom: 0px; border-left: 0px; display: inline; border-top: 0px; border-right: 0px" title="image" src="http://alittlestrange.com/tfoa/files/2009/11/image_thumb17.png" border="0" alt="image" width="244" height="137" /></a></p>
<p>Name your policy</p>
<p><a href="http://alittlestrange.com/tfoa/files/2009/11/image18.png#utm_source=feed&amp;utm_medium=feed&amp;utm_campaign=feed"><img style="border-bottom: 0px; border-left: 0px; display: inline; border-top: 0px; border-right: 0px" title="image" src="http://alittlestrange.com/tfoa/files/2009/11/image_thumb18.png" border="0" alt="image" width="240" height="139" /></a></p>
<p>On the Requirements tab, Add the Users or Groups you want to have access</p>
<p><a href="http://alittlestrange.com/tfoa/files/2009/11/image19.png#utm_source=feed&amp;utm_medium=feed&amp;utm_campaign=feed"><img style="border-bottom: 0px; border-left: 0px; display: inline; border-top: 0px; border-right: 0px" title="image" src="http://alittlestrange.com/tfoa/files/2009/11/image_thumb19.png" border="0" alt="image" width="240" height="166" /></a></p>
<p>You can make changes to the other options as you see fit.</p>
<p><strong>Create resource authorization policy</strong></p>
<p><a href="http://alittlestrange.com/tfoa/files/2009/11/image17.png#utm_source=feed&amp;utm_medium=feed&amp;utm_campaign=feed"><img style="border-bottom: 0px; border-left: 0px; display: inline; border-top: 0px; border-right: 0px" title="image" src="http://alittlestrange.com/tfoa/files/2009/11/image_thumb17.png" border="0" alt="image" width="244" height="137" /></a></p>
<p>Name your policy</p>
<p><a href="http://alittlestrange.com/tfoa/files/2009/11/image20.png#utm_source=feed&amp;utm_medium=feed&amp;utm_campaign=feed"><img style="border-bottom: 0px; border-left: 0px; display: inline; border-top: 0px; border-right: 0px" title="image" src="http://alittlestrange.com/tfoa/files/2009/11/image_thumb20.png" border="0" alt="image" width="240" height="147" /></a></p>
<p>Select which Users or Groups can connect to remote computers</p>
<p><a href="http://alittlestrange.com/tfoa/files/2009/11/image21.png#utm_source=feed&amp;utm_medium=feed&amp;utm_campaign=feed"><img style="border-bottom: 0px; border-left: 0px; display: inline; border-top: 0px; border-right: 0px" title="image" src="http://alittlestrange.com/tfoa/files/2009/11/image_thumb21.png" border="0" alt="image" width="240" height="125" /></a></p>
<p>On the Network Resource tab you can specify which resources are available to connect the the RD Gateway. for the purpose of this tutorial we will use “Allow users to connect to any network resource”</p>
<p><a href="http://alittlestrange.com/tfoa/files/2009/11/image22.png#utm_source=feed&amp;utm_medium=feed&amp;utm_campaign=feed"><img style="border-bottom: 0px; border-left: 0px; display: inline; border-top: 0px; border-right: 0px" title="image" src="http://alittlestrange.com/tfoa/files/2009/11/image_thumb22.png" border="0" alt="image" width="233" height="240" /></a></p>
<p>On the Allowed Ports tab accept the default “Allow connections only through TCP port 3389”</p>
<p><a href="http://alittlestrange.com/tfoa/files/2009/11/image23.png#utm_source=feed&amp;utm_medium=feed&amp;utm_campaign=feed"><img style="border-bottom: 0px; border-left: 0px; display: inline; border-top: 0px; border-right: 0px" title="image" src="http://alittlestrange.com/tfoa/files/2009/11/image_thumb23.png" border="0" alt="image" width="244" height="171" /></a></p>
<p><strong>Client Configuration</strong></p>
<p>Open Remote Desktop Connection</p>
<p>Enter the host you want to connect to:</p>
<p><a href="http://alittlestrange.com/tfoa/files/2009/11/image24.png#utm_source=feed&amp;utm_medium=feed&amp;utm_campaign=feed"><img style="border-bottom: 0px; border-left: 0px; display: inline; border-top: 0px; border-right: 0px" title="image" src="http://alittlestrange.com/tfoa/files/2009/11/image_thumb24.png" border="0" alt="image" width="244" height="192" /></a></p>
<p>On the Advanced tab click “Settings” under Connect from anywhere</p>
<p><a href="http://alittlestrange.com/tfoa/files/2009/11/image25.png#utm_source=feed&amp;utm_medium=feed&amp;utm_campaign=feed"><img style="border-bottom: 0px; border-left: 0px; display: inline; border-top: 0px; border-right: 0px" title="image" src="http://alittlestrange.com/tfoa/files/2009/11/image_thumb25.png" border="0" alt="image" width="231" height="240" /></a></p>
<p>Select “User these TS Gateway server settings” and enter you server name</p>
<p><a href="http://alittlestrange.com/tfoa/files/2009/11/image26.png#utm_source=feed&amp;utm_medium=feed&amp;utm_campaign=feed"><img style="border-bottom: 0px; border-left: 0px; display: inline; border-top: 0px; border-right: 0px" title="image" src="http://alittlestrange.com/tfoa/files/2009/11/image_thumb26.png" border="0" alt="image" width="240" height="175" /></a></p>
<p>Enter you credentials</p>
<p><a href="http://alittlestrange.com/tfoa/files/2009/11/image27.png#utm_source=feed&amp;utm_medium=feed&amp;utm_campaign=feed"><img style="border-bottom: 0px; border-left: 0px; display: inline; border-top: 0px; border-right: 0px" title="image" src="http://alittlestrange.com/tfoa/files/2009/11/image_thumb27.png" border="0" alt="image" width="244" height="240" /></a></p>
<p>You should now be connected to your intended host.</p>
<p>You can monitor the remote connections through the Monitoring tab under “RD Gateway Manager” in Server Manager.</p>
<p><a href="http://alittlestrange.com/tfoa/files/2009/11/image28.png#utm_source=feed&amp;utm_medium=feed&amp;utm_campaign=feed"><img style="border-bottom: 0px; border-left: 0px; display: inline; border-top: 0px; border-right: 0px" title="image" src="http://alittlestrange.com/tfoa/files/2009/11/image_thumb28.png" border="0" alt="image" width="244" height="187" /></a></p>
<p> </p>
<p>I may cover more of the features and configuration of the RD Gateway at a later time, but for now you should be able to enjoy most of the benefits and security this service provides.</p>

<p class="FacebookLikeButton"><fb:like href="http%3A%2F%2Falittlestrange.com%2Ftfoa%2F2009%2F11%2F06%2Fintro-to-windows-2008-r2-remote-desktop-gateway%2F" layout="standard" show_faces="true" width="450" action="like" colorscheme="light"></fb:like></p>
]]></content:encoded>
			<wfw:commentRss>http://alittlestrange.com/tfoa/2009/11/06/intro-to-windows-2008-r2-remote-desktop-gateway/feed/</wfw:commentRss>
		<slash:comments>6</slash:comments>
		</item>
	</channel>
</rss>

