RD Gateway and RD Web Access - better together or on different servers?

I am evaluating Remote Desktop Services with 2012 R2 and initially I had all the roles on 1 server for testing.  I began thinking it would be a better setup to split the RD Gateway role and the RD Webaccess role into different servers for security purposes.
 This way I could expose only the RD Gateway to the internet and the Web Access role would not be exposed.  In all my reading and searching it seems that nearly every article I come upon has both RD Gateway and Web Access installed on the same system.
What is the ideal setup from a security standpoint to have the these two roles separate or does it not mater?  If it does not mater then I will setup 1 server with Gateway and Web Access and I will then have other servers for licensing, broker, session
host, and visualization host once I move this into production.
If these roles are on the same system how do I know if the gateway role is doing anything?  Is the FQDN\rdweb the correct URL to use even when the gateway is implemented?  
If they are separate how do I tell the gateway and web access servers to use each other?  

Hi,
As far as I know, it’s fine to have RD Gateway and RD Web Access roles installed on the same server.
 “Normally external users would log on to RD Web Access via tcp port 443, click on a RemoteApp and connect to RD Gateway via
tcp 443/udp 3391, RDG connects them to RDCB on tcp 3389 which redirects them to a RDSH server, finally the RDG connects to the RDSH on tcp 3389/udp 3389.”
Quoted from TP in this post below:
RD Gateway and RD web issue
https://social.technet.microsoft.com/Forums/windowsserver/en-US/5ab40559-23f7-4ebc-b60d-87375cc55674/rd-gateway-and-rd-web-issue?forum=winserverTS
More links below for you:
RD Gateway deployment in a perimeter network & Firewall rules
http://blogs.msdn.com/b/rds/archive/2009/07/31/rd-gateway-deployment-in-a-perimeter-network-firewall-rules.aspx
Remote Desktop Gateway/Web Server Placement
https://social.technet.microsoft.com/forums/windowsserver/en-US/b2970cf5-a5b5-494c-88b7-cd6e01f84bb6/remote-desktop-gatewayweb-server-placement
Best Regards,
Amy
Please remember to mark the replies as answers if they help and un-mark them if they provide no help. If you have feedback for TechNet Subscriber Support, contact
[email protected]

Similar Messages

  • My part for Lenovos PCs and Windows 7 are better together :) S-Series

    Hi ,
    my part for Lenovos PCs and Windows 7 are better together
    Feel free to look at this...If you have one of the small Lenovo machines
    or want to buy one in the future u are not alone
    Windows 7 Driver 
    sincerely KalvinKlein
    Want more ? For further information to get the most of your S-Class machine
    Lenovo Energymanagement 
    Backup
    Windows 7 Driver 
    Windows 7  Install
    Clean XP Install
    XP Startup
    Small WebCam Guide
    Lenovo Easy Capture
    Resolution > 1024 x 576 / 600  Works with XP Only For Windows 7 Alternate driver section
    Thinkies 2x X200s/X301 8GB 256GB SSD @ Win 7 64
    Ideas Centre A520 ,Yoga 2 256GB SSD,Yoga 2 tablet @ Win 8.1

    Hi ,
    my part for Lenovos PCs and Windows 7 are better together
    Feel free to look at this...If you have one of the small Lenovo machines
    or want to buy one in the future u are not alone
    Windows 7 Driver 
    sincerely KalvinKlein
    Want more ? For further information to get the most of your S-Class machine
    Lenovo Energymanagement 
    Backup
    Windows 7 Driver 
    Windows 7  Install
    Clean XP Install
    XP Startup
    Small WebCam Guide
    Lenovo Easy Capture
    Resolution > 1024 x 576 / 600  Works with XP Only For Windows 7 Alternate driver section
    Thinkies 2x X200s/X301 8GB 256GB SSD @ Win 7 64
    Ideas Centre A520 ,Yoga 2 256GB SSD,Yoga 2 tablet @ Win 8.1

  • Will notes in Mail sync with Notes on Exchange server and Outlook Web Access?

    Will notes in Mail 5.0 sync with Notes in latest versions of Microsoft Exchange server and Outlook Web Access?

    I was just trying to find the answer to this question myself.
    As it happens it's all here in another post: https://discussions.apple.com/thread/3416007
    Looks like Notes used to Sync in iOS4, but no longer sync in iOS5
    Thanks
    Mike

  • My ipod nano will turn on and play but the viewing screen goes out and I cannot access the information to select different playing options. Any suggestions?

    My ipod nano will turn on and play but the viewing screen will not come on and I cannot access the information to select different playing options. It glows white background light then goes dark for the entire time I am using it. Any suggestions?

    I had the same problem.  Someone here told me to make sure my earbuds were in securely.  Push until they click in place.  It solved the problem.  The music still plays even though the screen goes to sleep.  Hope this helps.

  • Remote Desktop 2012 R2 - Can't get RD Gateway with RD Web Access working through just 443

    I have one server (2012 r2 fully updated) running all remote desktop roles (RD Web Access, RD Gateway, RD Licensing, RD Connection Broker, RD Session Host) and a separate domain controller.
    I have RD Web Access published to cloud.mydomain.co.uk and accessing cloud.mydomain.co.uk/RDWeb works fine.
    I want to setup the environment so only port 443 is open from the outside (thus the RD Gateway is installed) and the user can login through RDWeb and click on an app to launch it.
    If I leave port 3389 open along with 443 and log on to RDWeb and click the remote app, this works fine.
    If I close 3389 on the external firewall and only leave open 443, I can connect AND login to RDWeb but I cannot open the connection
    This is expected:
    http://i.imgur.com/9j2HRqm.png
    Error:
    http://i.imgur.com/2LH2c7T.png
    Digging in the event viewer yielded: http://i.imgur.com/M9uHm0o.png
    Which led me to test change the following setting in the resource access policy, as a test:
    http://i.imgur.com/FlGObFr.png
    This still didn't work but yielded a different error in event viewer:
    http://i.imgur.com/LkaCfU4.png
    Now I suspect I have misconfigured something somewhere in terms of the last event where it suggests it can't connect to resource "cloud.mydomain.co.uk" I would have expected this to be the internal FQDN of my session host. Or, I am hitting some sort
    of odd problem because I have all the roles on the same box.
    Any assistance greatly appreciated. I'm keen to find the root cause behind this as I need to document this solution so don't want to invalidate by messing around too much with settings.

    Hi Gavin,
    If you use RD Gateway then you only need to open TCP port 443 and UDP port 3391 and forward them to your RD Gateway server.  You may have RD Web Access (uses TCP port 443) and RDG running on the same server.
    When an external client launches a RemoteApp they will connect to your RD Gateway via TCP port 443 and UDP port 3391, then the RDG will connect to your internal RDSH servers using TCP port 3389 and UDP port 3389 on behalf of the external client.  In
    this way the RDG will act as a middleman between your external users and your internal RDSH servers.
    In Server Manager - Remote Desktop Services - Overview - Tasks - Deployment Properties you need to specify the external FQDN of your RD Gateway server.  If you have RDWeb and RDG on the same server this would be the same FQDN that your users will use
    for RDWeb.  For example, if your users use https://rds1.yourdomain.com/rdweb to connect to your RD Web Access site, then you would enter rds1.yourdomain.com for the RD Gateway name in deployment properties.
    (Above one Quoted from this thread answered by TP).
    In addition please see that you have properly configured RD Rap & RD Rap policy under RD Gateway manager and also properly configured certificates to match server name.
    Hope it helps!
    Thanks.
    Dharmesh Solanki
    Please remember to mark the replies as answers if they help and unmark them if they provide no help. If you have feedback for TechNet Support, contact [email protected]

  • SharePoint 2013 (Foundation) and Outlook Web Access WebPart (OWAPart)

    Hi, I've read most MSDN forum threads relating to this topic, however, I haven't seen my issue anywhere.
    We're running SP 2013 foundation, and I want to use the Outlook Web Access web part.  I followed the steps outlined here:
    http://blogs.msdn.com/b/shawa/archive/2014/06/01/owa-web-part-in-sharepoint-2013.aspx
    (Sorry, can't add link since I'm new around here)
    To make the WebPart available in the site collection.  Which worked.
    When I try to actually add the WebPart to a page though, I get an error message stating: "There was an error adding the component to the page" (roughly translated from french).
    If I try to see the web part properties from the site settings > Web Parts, I get a SharePoint error page, and the help link yields no information.
    Most problems I've seen are with the actual configuration of the WebPart, but I can't even get to that step.

    I dont think you can use Outlook web app for foundation. This is not possible because those Web parts  use Microsoft.SharePoint.Portal.dll
    which is not avaliable and registered on SharePoint Foundation.
    Instead of using the OWA web parts, you could also try using the Page Viewer web part and set it to the OWA URLs... 
    If this helped you resolve your issue, please mark it Answered

  • Using facelets and Visual web jsf frameworks together

    I am developing a new jsf application and I wanted to make the page navigation simpler like making the content pages independently using woodstock components and including them in the main template page.
    I have downloaded Facelets support plugin for netbeans and installed it. I have created a new project using the wizard and i specified the two (facelets and visual web jsf) as frameworks for use. But I failed to leverage my application with facelets because I don't know how to use woodstock components with facelets.
    I am new to jsf and i want the woodstock visual components. Can't I use facelets then?
    Plz help.

    I managed to find a workaround. Thought i should share it with those who are faced with a similar issue.
    I found that a bug report had been placed in the past with Apache Dev. However, they had said that they would not modify their logic because the servlet container spec requires it (even though isapi_redirector is only a connector and not a container). They said that there is no way for the isapi_redirector to differentiate between /foo/WEB-INF when foo is a context and when foo is just a sub-directory of the ROOT web application. So, the general consensus was to err on the side of safety and risk blocking a few requests that are valid.
    However, this causes a serious issue for those using NetBeans JSF Visual Web Projects. Hence, I created my own flavour of isapi_redirector by modifying the code such that this check is not performed and leaving the onus of checking on Tomcat.
    For those who are interested, the simplest way to go about this would be to force the function uri_is_web_inf (in jk_isapi_plugin.c ) to always return FALSE.

  • Virtual PC and Citrix web access

    Hello!
    I have a PowerBook G4 running OS X Tiger. For work, I have to access my company's Citrix web site when I am not in the office physically so I can use some mainframe based applications. I'd prefer not to buy an additional PC laptop just for the web Citrix access.
    I researched on the web and found that Virtual PC 7.0 for Windows XP Professional seems to be the solution, but I didn't find anything about using Virtual PC to access a web site that has the Citrix (I think it uses Metaframe) portal to launch company email, office apps, and mainframe access.
    I have not purchase Virtual PC 7.0 yet - I am in my research stage where I'd like to know "what I am getting into". Requesting Citrix server IP address for a direct sign-on is not an option for me even if I use Virtual PC 7.0. Does anyone either have experience with similar Citrix access situations via Web or can anyone point me to some other resources website that may help me?
    Thanks!
    Angela

    Hi Angela!
    A Citrix client for Mac OS X is also available. Using this may be easier than trying to install and configure Virtual PC and then installing and configuring the Citrix client for Windows.
    Your Citrix support folks should be able to tell you what settings you need to connect and log in but they may only support you as far as Windows. You'd need to use the admin guide (found at the same link above) to configure your Mac client.
    Hope this helps! bill
    1 GHz Powerbook G4   Mac OS X (10.4.6)  

  • Excel Services and Excel Web Access Web Part on O365 SharePoint...

    I am using O365 E3 w/SharePoint and I have successfully created Pivot Charts via PowerPivot to query oData feeds from a couple of SharePoint lists. I was not able to refresh the data on O365 until I performed
    this operation.
    I updated the data connections in the report to refresh when the report is opened (which runs when the page with a referenced chart is accessed), but now there is a "Query and Refresh Data" warning that appears when the page is loaded; poor UX.
    I have read that there is a way to turn off this warning in SharePoint on-prem, but that doesn't help me with this nagging dialog box. I tried to move the report to a BI site in the collection and changed the report to use data connection files in the Data
    Collection Library hoping for enough trust for this message to cease, but ... No joy.
    Is there anything That I can do to keep the refresh on page load and lose the warning on O365? Maybe there is a Javascsript workaround someone can help with (I'm not much of a JS Dev).

    Hi,
    According to your post, I have done a test in my SharePoint on-line and reappeared your issue.
    If the issue occurred at SharePoint on- premise, go to SharePoint Central Administration > Application Management > Service Applications > Manage service applications > Excel Services
    application > Trusted File Locations and click on the Address that contains the workbook. In the External Data section, under Warn on Refresh, uncheck Refresh warning enabled and click OK.
    Refer to the following link:
    http://blogs.technet.com/b/excel_services__powerpivot_for_sharepoint_support_blog/archive/2013/10/22/excel-services-query-warning.aspx
    Unfortunately, the feature to disable the ‘Data Refresh Warning’ is not available yet in SharePoint Online.
    Because the option needs the SharePoint Central Admin level permission that is not opened to the public in Office 365 now.
    Refer to the following link:
    http://community.office365.com/en-us/f/154/t/234874.aspx
    Best Regards,
    Lisa Chen
    Forum Support
    Please remember to mark the replies as answers if they help and unmark them if they provide no help. If you have feedback for TechNet Subscriber Support, contact
    [email protected]
    Lisa Chen
    TechNet Community Support

  • Missing values of Enterprise Custom Field in Project Professional and Project Web Access

    Hi all,
    In Project Server 2010 SP2 we created a custom field called Iteration Path (without a lookup table).
    We're in an environment where Project Server task data gets synched from TFS and we've mapped the Iteration Path from TFS to the Enterprise Custom Field in Project Server.
    We've triggered synch of all synchronized work items from TFS to Project Server
    Then, in the database we can see the Iteration Path values coming across
    When I open these projects in Project Profssional, the entire column of Iteration Path is empty.
    When I open these projects in Project Web App (from Project Center), the entire column of Iteration Path is empty.
    When I open the master project which contains all these projects, no values are shown.
    Any ideas what can be wrong?
    I did already clear my cache, global.mpt, but nothing changed. We don't have this issue with other Enterprise Custom Fields that are mapped to TFS fields.
    Cheers,
    Bram
    www.projectexpert.nu

    Hi Bram,
    In the 4th item, when you say "database", which one are you talking about? Project Server DB? Draft or reporting DB? 
    If the value are not showing up in Project Pro, it is no need to clean your cache, since the value are obviously not stored in the Project Server Draft DB. The issue is more likely to come from the TFS sync for this particular field. Do you have any logs
    for the sync process? If your field in anyway different from the others, containing specific characters?
    Hope this helps.
    Guillaume Rouyre - MBA, MCP, MCTS

  • RD Web access SSO - remote desktop doesn't work

    Hi,
    This is my first post in here, and I hope you gays can help me out.
    I am currently experiencing some issues with RD Web SSO not working as I would like it to work.  I have found countless articles and guides describing how to get it to work, but no guide have yet helped me.
    The problem is that when I log in on the web access and open a published application everything works fine I wait 5 sec and the application pups up, but when I try to open "Remote Desktop" then I get a new log in box where I must enter my log in credentials
    again (after entering my credentials everything work great.)
    The problems I am currently facing is produced in a demo environment configured as follows:
    1x DC server (DC01) also the lic server
    2x RDS server (RDS01/02)
    1x RDS Connection broker (RDCM01)   I have created a farm named "farm01.mydomain.com"
    1x RDS Web access server (RDWA01)
    1x RDS Gateway (RDSGW01)
    (All the Servers are installed with Windows server 2008 (R2) SP1, and have the latest update.)
    I am publishing my demo environment on the internet, i have created a domain name for my gateway and my web access and they are both accessible from the web (rdwa.mydomain.com and rdsgw.mydomaim,com). I also have secured everything with an SSL wildcard certificate
    ( my external and intern domain names are the same so I am using one SSl certificate) that is trusted on the web.
    when I  log in on the web access server trough (IE9 or IE8 ) from another network(wan) and I open a published application (calculator), it pop ups in just a few seconds. But when I try to open my Remote desktop I get a login box where I must enter my
    username and password one more time.. after that remote desktop opens and everything works great.
    My laptop is a Windows 7 professional with RDP 7 and IE 9, and is not member of a domain (just a workstation), I have tested it from multiple workstations and networks(Also win 7 and RDP7) but even there I have the same problem.
    Thinks that I have tried tell now:
    I have created a kerberos account as mentioned on
    MSDN
    I have checked my group permissions as mentioned
    here
    And many more blogs and forums
    I have tried multiple settings on RDCM, RDWA, RDSGW and RDS server
    Right now I am out of ideas, and I hope you gays can help me out..
    thanks in advance,
    Pouyan

    Thnx for you advise,
    Did you go into your RemoteApp Deployment settings and change the server name to the farm name "farm01.mydomain.com?"
    Yes
    Also in the Session Broker's RemoteApp and Desktop Connection Properties window change the Connection ID to the farm name as well.
    actually I couldn't find out what to put on the connection ID so I had left it just default, but after changing it to the farm name it still doesn't work
    Did you sign you apps with the cert used on your RDS servers?
    yes, I am using a wildcard ssl certificate to sign all the servers/apps with.
    there is
    something that
    strikes me, when I log on the web access and click on a published application (that is hosted from the same RDS servers) then I get a information box. when I click on the "details" button I see on the bottom "use the following credentials to connect" and my
    domain and username are published there. But when I click on the "Remote desktop" icon and do the same I can't see this information!!
    Also I don't think that its an SSL problem, because after log in again it works perfect without any warning.

  • RD Web Access SSO not working correctly

    I have two Win 2008 r2 sp1 servers.  Both are RD Session host servers.  One of them is also serving as a RD Gateway server AND RD Web access server.  Most everything is working well and as planned.  However, I am having an issue with
    the the RD Web Access.
    In the RD Web access server configuration page, I've set "One or more RemoteApp sources" and I've added two servers there, separated by a semicolon (eg RDServer1;RDServer2), and as expected a long list of RemoteApps hosted on both servers is shown .  The
    issue is that whatever server is listed second (eg RDServer2) won't allow sso to work right  -- when I click a link for a RemoteApp hosted on RDServer1 I am not prompted again for login credentials.  However, when clicking a link for a RemoteApp
    hosted on RDServer2 I am prompted "Enter Your Credentials".  I've tried swapping the order of the "Source Name" servers, and after a reboot indeed links to the RemoteApps hosted on that second server now prompt for me to "Enter your credentials".
    Things I've tried:
    1. Trying various server name formats (IP address, NetBIOS name, FQDN, and more) to no apparent effect.
    2. Applied the hotfix from KB2524668 to both servers.
    3. Flushed the IE caches for the client machines.
    4.  Tried various AD login accounts
    5. Ensuring that the RD Web Access server is added to the local group "TS Web Access Computers" on both servers.
     This is one step that I'm not 100% sure of -- it is clear to me that the RD Session host server that doesn't contain RD Web access should be there, but I'm not totally clear as to whether the dual-duty RD Web server/RD Session host should have this setting.
     I've tried it both ways, but it doesn't seem to make a difference.
    I'm stumped.

    Kevin,
    That's it!  I have a separate SSL cert for each RD Session Host, and used the corresponding certs to sign RemoteApps for each.  I still don't see this requirement in the documentation (although they do mention exporting self-signed certs, but that
    is due to the fact that they are self-signed and not automatically trusted by client machines), but maybe I'm just blind.
    Regardless, the fix to my problem was to export the cert from my RDServer1, import it to RDServer2, then set RDServer2 to use that cert to sign the RemoteApp connections.
    Thanks for your assistance, I was really stuck.
    Chris

  • HP Family Better Together

    By: Mark Budgell
    Original Post on The Next Bench
    A couple months ago, when HP announced it was considering alternatives for its PC business, I wrote a bullish post about our future. Today, after announcing that the PC business will remain part of HP, I still feel the same way.
    This market is huge, shipping 1 million PCs a day.  HP is the leading PC maker with a profitable $40 billion business.  And everyone here is really dedicated to creating great products for our whole range of customers.
    Thousands of hours were spent understanding how extracting the PC business would impact everything from supply chain to product development and brand image. Our leadership teams were locked in boardrooms late into many evenings. You could tell from the tired-but-determined look on their faces, and their coffee consumption, that no one was taking it lightly.
    When the news was first announced, what might have been missed was that this was more than just a cost-benefit analysis. That was definitely part of it, but the larger goal was to ensure that the world’s leading PC company and one of the finest technology companies is firing on all cylinders. 
    For obvious reasons, I can’t share what’s on the product roadmap. I can say that our team is more committed than ever to building innovative, quality products for our customers around the world. And we’re thankful to all the customers who have remained fans of our products during the last couple of months.
    PSG and HP: We’re better together, and we’re pumped.
    I work for HP, supporting the HP Experts who volunteer their time and technical knowledge to help others.
    --Say "Thanks" by clicking the Kudos Star in the post that helped you.
    --Please mark the post that solves your problem as "Accepted Solution"

    I am very interested in this as well. I don't think there is currently a solution but I think (hope) it is something that Apple will enable in the near future. Let Apple know that this is a feature we want! Send feedback here:
    http://www.apple.com/feedback/icloud.html
    I just did.

  • Primavera p6- timesheet & web access

    hi
    i want to ask question about primavera professional project management
    can i access timesheet and p6 web module
    if yes - How
    if No- what i need to use timesheet and p6 web access
    regards
    Alaa

    Hi Alaa,
    Sounds like you need to be in the 'Primavera P6 Enterprise Project Portfolio Management' forum... this is for the old Product name Prosight not P6.
    From my understanding, Oracle Primavera PPM provides and 'Enterprise' version (which includes the Web services and Timesheets) and a 'Professional' version that provides upto 100,000 activites in each project, with not web services or timesheet tools, this may have been what you have purchased/recieved/installed.
    Best you check with your sales contact and confirm with them that you need the Enterprise version.
    Or if you have the enterprise version, you can download the required tools from the Orcle website.
    Regards,
    James

  • Web Access Has "Stopped"

    I have a simple home G5 setup -- Road Runner cable access going through simple router. Seems that after the last OSX update my web access began deteriorating. Time Warner replaced the cable modem but it hasn't helped. Today it takes several minutes to access a web page or a new link -- often the request times out and I can't connect at all. Get the "Can't open the page" message. This is true with all major browsers -- sometimes Eudora can't retrieve email either.
    I've read every post relating to this or similar issues and have tried trashing various prefs, making sure no Proxies are checked, etc., all to no avail.
    This started about 10 days ago and has deteriorated to barely being able to connect to the Internet at all (it took many tries even to get to this support forum).
    Can anyone help? Thanks for any advice.
    I had made no changes to my computer before this started happening

    My thanks to you and BDAqua for help with this issue, now resolved. I got educated on the OpenDNS system and now understand the use of those two DNS Server numbers in my Network control panel. I also was able, with the help of the OpenDNS web site and D-Link tech support, to get my router reconfigured using the OpenDNS numbers, and my web access has never been faster.
    All that's left is to wonder why my DNS resolution got messed up in the first place. It appears to me that Time Warner's (Road Runner) system of providing dynamic DNS resolution is "bad" -- nowhere as fast as the OpenDNS system.
    Anyway, for other Road Runner customers who read this thread and want to try to OpenDNS server IP addresses in your Network preferences panel, go to opendns.com -- very simple, clear web site explaining how to configure your Network panel and a wide variety of routers.

Maybe you are looking for