No - I wasnt planning on using this, I have the TS Web Access setup though. Should I be using RWW instead?
Main Topics
Browse All TopicsHi,
I'm perhaps having some trouble understanding the whole TS Gateway / TS Web Access thing, and how it should work with regards to opening/redirecting external port 3389.
Here's the scenario:
- We have 1 SBS 2003 Server and a second Windows 2008 TS member Server.
- On the TS server, roles for Terminal Server, TS Gateway and TS Web Access have been installed.
- I've assigned a 3rd party SSL cert to the TS Gateway.
- On the firewall, I have redirected external ports 80, 443 and 3389 to the internal TS server IP.
- Externally, I can connect to the TS server using an RDP client and specifying the computer and TS Gateway settings (remote.domain.com). I can monitor the connection within TS Gateway manager and see that its established. I can also do the same by launching the RDP session from within the TS Web Access page.
My questions are:
- Do I need to have port 3389 externally open? With the current setup, if I close it nothing works as I can't connect to the computer name "remote.domain.com"
- If I don't specify the TS Gateway server in the RDP clients advanced settings, it still works and thus bypasses the encryption (because 3389 is open)?
This is my first time setting up this kind of thing and I'm a little confused about it all... Have I set it all up correctly and this just the way its supposed to work? Or am I missing something fundamental?
I want to make the the connection to the terminal server as secure and easy as possible.
Thanks in advance,
Ben
This Question has been solved and asker verified All Experts Exchange premium technology solutions are available to subscription members.
Experts Exchange has been collecting answers to technology questions since 1996…3 million and counting! If you have a question, chances are we already have your answer.
If you can't find the exact answer you're looking for, ask our exclusive community of 50,000 experts. You’ll get a personalized answer from a trusted professional.
Thousands of free tech tips, tricks, how-to’s and tutorials are available in our peer reviewed articles section. See for yourself how smart our experts are, no login required.
Access the answers to your technology questions today.
30-day free trial. Register in 60 seconds.
Members of the expert community talk about why the experience at Experts Exchange is different than what you will find anywhere else.

Try it out and discover for yourself.
30-day free trial. Register in 60 seconds.
Join the community of experts here and help other tech pros by answering question in your area of expertise. You can earn FREE access to all Experts Exchange's premium features and resources.
It's pretty simple:
3389 does not need to be open to the Internet.
TS Gateway creates an SSL tunnel on 443 and proxies TS RDP through that tunnel.
Make sure you use the SBS Wizards to configure your SBS!
Our setup guide:
http://blog.mpecsinc.ca/20
Philip
Heh ... answered a lot of SBS TS Gateway related stuff ... travelled through the brain. :)
You can use the SBS 2003 Remote Web Workplace portal to proxy into the TS as well.
There are a couple of extra steps to making TS 2008 appear in RWW:
http://msmvps.com/blogs/br
Philip
I'd go with the remote web workplace, the proxy and use of TS gateway for resource authorization will create the most secure scenario and provide a simple method for connection for all users.
I helped a friend with a similar issue (TS2008 in SBS2003), and Philip is right, that article is damn handy to get it working right.
Thanks for the suggestions guys - RWW may well be a good alternative.
However, I do like the TS Web Access site and would like to try and get that working properly if I can - based on what I said does it sound like it's setup correctly? Should I need to have port 3389 open, as well as 443 and 80?
As I said, when launching the session from within TS Web Access (or from RDP client), it goes via remote.domain.com and thus seems to require 3389 to be open - is this right?
Business Accounts
Answer for Membership
by: bharrington83Posted on 2009-09-03 at 04:30:39ID: 25249498
I assume that you have remote web workplace set up and running?