From: WildPacket on
Windows 2008 TSweb,TSG, TS all running on the same server..

I have opened RDP and HTTPS port on the firewall to access my apps via
TSWebAccess from Internet. Works fien no issues so far ....

Using the WAN side IP if I RDP into my server across the internet it hits
straight to my Win2008 Server where TSWeb and TSGateway is running.

Just want to confirm that I need to open RDP port in my firwall - correct???

I know we can use a different port number in the firewall, TServer Gateway
etc.

Is there some other way ..so nobody can use RDP and hit my server if they
grab my wan IP?

Advise Please.

Thanks

From: Rob Leitman [MSFT] on

"WildPacket" <WildPacket(a)discussions.microsoft.com> wrote in message
news:338B8CE0-D183-46AF-81DE-D81B3F9FC583(a)microsoft.com...
> Windows 2008 TSweb,TSG, TS all running on the same server..
>
> I have opened RDP and HTTPS port on the firewall to access my apps via
> TSWebAccess from Internet. Works fien no issues so far ....
>
> Using the WAN side IP if I RDP into my server across the internet it hits
> straight to my Win2008 Server where TSWeb and TSGateway is running.
>
> Just want to confirm that I need to open RDP port in my firwall -
> correct???
>
> I know we can use a different port number in the firewall, TServer Gateway
> etc.
>
> Is there some other way ..so nobody can use RDP and hit my server if they
> grab my wan IP?

If you're using TS Gateway, there's no need to open the RDP port in the
firewall. All traffic goes over HTTPS.

Rob


From: WildPacket on
Rob .. thanks.

we are testing an app via
https://terminalserver.ourdomain.com/ts
and it works fine ...

If I turn rdp port off in the firewall ... the users dont connect?????

Why is that then ... or something is misconfigured..?

ts, tsweb, tsgateway, application and tslicense all on this one server.








"Rob Leitman [MSFT]" wrote:

>
> "WildPacket" <WildPacket(a)discussions.microsoft.com> wrote in message
> news:338B8CE0-D183-46AF-81DE-D81B3F9FC583(a)microsoft.com...
> > Windows 2008 TSweb,TSG, TS all running on the same server..
> >
> > I have opened RDP and HTTPS port on the firewall to access my apps via
> > TSWebAccess from Internet. Works fien no issues so far ....
> >
> > Using the WAN side IP if I RDP into my server across the internet it hits
> > straight to my Win2008 Server where TSWeb and TSGateway is running.
> >
> > Just want to confirm that I need to open RDP port in my firwall -
> > correct???
> >
> > I know we can use a different port number in the firewall, TServer Gateway
> > etc.
> >
> > Is there some other way ..so nobody can use RDP and hit my server if they
> > grab my wan IP?
>
> If you're using TS Gateway, there's no need to open the RDP port in the
> firewall. All traffic goes over HTTPS.
>
> Rob
>
>
>
From: Rob Leitman [MSFT] on

"WildPacket" <WildPacket(a)discussions.microsoft.com> wrote in message
news:9C937305-38C3-4A88-A6E3-BAB9CAA86A39(a)microsoft.com...
> Rob .. thanks.
>
> we are testing an app via
> https://terminalserver.ourdomain.com/ts
> and it works fine ...
>
> If I turn rdp port off in the firewall ... the users dont connect?????
>
> Why is that then ... or something is misconfigured..?
>
> ts, tsweb, tsgateway, application and tslicense all on this one server.

Did you set the Deployment Settings in RemoteApp Manager to have the
RemoteApps use TS Gateway? If not, they won't use it, and will try to
connect via RDP (3389).

Rob


From: WildPacket on
Rob Thanks.

"I THINK" I did. Let me run it by you .....

On the TS Remoteapp Manger Properties -> Under TSGateway tab in the server
name field I have the same name as the CN on the certificate ...???

And on the Terminal Server tab in the server name field I have the same name
as the CN on the certificate

Is that right????

Thanks,







"Rob Leitman [MSFT]" wrote:

>
> "WildPacket" <WildPacket(a)discussions.microsoft.com> wrote in message
> news:9C937305-38C3-4A88-A6E3-BAB9CAA86A39(a)microsoft.com...
> > Rob .. thanks.
> >
> > we are testing an app via
> > https://terminalserver.ourdomain.com/ts
> > and it works fine ...
> >
> > If I turn rdp port off in the firewall ... the users dont connect?????
> >
> > Why is that then ... or something is misconfigured..?
> >
> > ts, tsweb, tsgateway, application and tslicense all on this one server.
>
> Did you set the Deployment Settings in RemoteApp Manager to have the
> RemoteApps use TS Gateway? If not, they won't use it, and will try to
> connect via RDP (3389).
>
> Rob
>
>
>