Solved

Route RDP connections based on username

Posted on 2011-03-25
9
786 Views
Last Modified: 2013-11-21
We have 7 RDP servers named server1, server2, etc.
Users can connect to only one of the seven servers because their data is only stored on that server. It happens sometime that we move a user to another server and that they need to adjust their connection settings.

We don't want our users to connect to a specific server but instead let them connect to a sort of gateway server that redirects them to the right server based on their username.

Is this possible? And if yes: what do we need?

0
Comment
Question by:mvanrooij
9 Comments
 
LVL 38

Expert Comment

by:Aaron Tomosky
ID: 35217839
Not in my realm of expertise but couldn't you setup dfs so all users could use any server?
0
 
LVL 1

Author Comment

by:mvanrooij
ID: 35217866
No, I don't want all the data on all of our servers.
0
 
LVL 11

Expert Comment

by:yelbaglf
ID: 35219566
Is there any reason why you're not using terminal services profiles, instead of storing user data on your servers?
0
 
LVL 1

Author Comment

by:mvanrooij
ID: 35219632
Yes, we have enough reasons for not using roaming profiles.
0
What Should I Do With This Threat Intelligence?

Are you wondering if you actually need threat intelligence? The answer is yes. We explain the basics for creating useful threat intelligence.

 
LVL 4

Expert Comment

by:reredok
ID: 35221648
use terminalserver gateway and set the ad-group in policy (it's an connection policy) which user can connect server. this works also with sessionbroker
0
 
LVL 1

Author Comment

by:mvanrooij
ID: 35223664
Would you please explain this a little more?
0
 
LVL 4

Accepted Solution

by:
reredok earned 500 total points
ID: 35224928
http://technet.microsoft.com/en-us/library/cc731264(WS.10).aspx

windows 2008/Windows 2008 R2 Terminal Services Gateway:

1.) Install Terminalserver Terminalservergateway/Remotedesktopgateway (Role)

2.) use a self certificate for testing

3.) Create a Terminal Services Connection Authorization Policies (TS CAPs). You use TS CAPs to specify users and computers that are able to make connections to the TS
Gateway server

4.) Create aTerminal Services Resource Authorization Policies (TS RAPs). A TS CAP specifies which users can connect to the TS Gateway server. A TS RAP specifies
the network resources that users can connect to through TS Gateway. You specify network
resources through an Active Directory security group.

5.) Edit the rdp-Connection or RDP File to use TerminalserverGateway


You need 2 Group of Terminalserver

User1...User10 -> Terminalserver1
User11...User20 -> Terminalserver2

It works great!


0
 
LVL 1

Author Comment

by:mvanrooij
ID: 35226405
Thank you, but unfortunately the Mac version of remote desktop doesn't support ts gateway.
I guess we'll have to wait until ms brings out a new version.
0
 
LVL 1

Author Closing Comment

by:mvanrooij
ID: 35226409
Mac remote desktop won't support this solution.
0

Featured Post

6 Surprising Benefits of Threat Intelligence

All sorts of threat intelligence is available on the web. Intelligence you can learn from, and use to anticipate and prepare for future attacks.

Join & Write a Comment

Like many organizations, your foray into cloud computing may have started with an ancillary or security service, like email spam and virus protection. For some, the first or second step into the cloud was moving email off-premise. For others, a clou…
Data center, now-a-days, is referred as the home of all the advanced technologies. In-fact, most of the businesses are now establishing their entire organizational structure around the IT capabilities.
How to install and configure Citrix XenApp 6.5 - Part 1. In this video tutorial we have explained step by step installation of Citrix XenApp 6.5 Server on Windows Server 2008 R2 is explained in this video. We have explained the difference between…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…

743 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

13 Experts available now in Live!

Get 1:1 Help Now