Solved

RemoteApp Server 2008 R2

Posted on 2012-12-27
8
1,039 Views
Last Modified: 2013-11-21
Hello,

When we deploy RemoteApp in Server 2008 R2. Upon clicking on the app:

1) Is the application opened using port 80/443  or still uses 3389?
2) Is there anyway to just move RemoteApp data on 80/443 and block 3389?
3) Is there a way to disable RDP and only enable RemoteApp. My understanding of RemoteApp is that it still uses RDP to open the Apps, but not exactly sure..

Thanks
0
Comment
Question by:masdf123
8 Comments
 
LVL 13

Expert Comment

by:rhinoceros
Comment Utility
0
 
LVL 4

Expert Comment

by:jjjosef
Comment Utility
Have a look at the article published on Expert-Exchange itself

It might be helpful for You

Expert Exchange Article

For your Third Query follow the bellow procedure
      
Go to the RDP properties in Terminal Services Configuration Console
In environment tab, select the option "Start the following program when the user....”
Path: c:\windows\system32\logoff.exe
 Start in: c:\windows\system32
0
 
LVL 1

Author Comment

by:masdf123
Comment Utility
Can someone please answer my questions specifically?
0
What Is Threat Intelligence?

Threat intelligence is often discussed, but rarely understood. Starting with a precise definition, along with clear business goals, is essential.

 
LVL 77

Assisted Solution

by:Rob Williams
Rob Williams earned 334 total points
Comment Utility
I think a general answer, will answer all 3 questions.
If you enable the TS Gateway service, when you connect to the server you use only port 443 to access the server.  You are authenticated, and then the TS Gateway server uses port 3389 internally to connect to the Terminal Server (now called Remote Desktop Services (RDS)  server, which can be but does not need to be the same server.  In this case external access to port 3389 is not needed at all, no router/firewall opening or port forwarding for port 3389 is required.  Port 3389 is only needed internally, but is needed.  Without the TS Gateway service port 3389 is required externally.  RDP is always needed, even with RemotApps, as it is the protocol/service used for accessing and communicating with the server or PC to which you are connecting.  It is possible to change the the RDP listening port to something other than 3389.

These days due to a virus that spreads via RDP and port 3389, the TS Gateway service, which uses SSL, should always be used instead of direct connections using 3389.
0
 
LVL 27

Assisted Solution

by:Steve
Steve earned 166 total points
Comment Utility
1) Is the application opened using port 80/443  or still uses 3389?

3389

2) Is there anyway to just move RemoteApp data on 80/443 and block 3389?

Kindof. You can set RDP port to anything you like but you will find issues if it conflicts with another used port, like 443. This doesnt change how it connects, it just changes the port number.
You should try the Web Access feature of Remoteapp, as that uses port 443 (https) and may do what you want.


3) Is there a way to disable RDP and only enable RemoteApp. My understanding of RemoteApp is that it still uses RDP to open the Apps, but not exactly sure..

Again, it's a yes & no. You can use remote web apps and block port 3389 completely, or just set the TS to log users straight off if they log in directly (using login script or group policy etc.)
0
 
LVL 77

Accepted Solution

by:
Rob Williams earned 334 total points
Comment Utility
As mentioned, if TS Gateway is used there is no need for 3389 or any other redirected port. Handshaking and Internet to server RDP traffic all uses SSL/443.
0

Featured Post

What Security Threats Are You Missing?

Enhance your security with threat intelligence from the web. Get trending threat insights on hackers, exploits, and suspicious IP addresses delivered to your inbox with our free Cyber Daily.

Join & Write a Comment

Find out how to use Active Directory data for email signature management in Microsoft Exchange and Office 365.
Possible fixes for Windows 7 and Windows Server 2008 updating problem. Solutions mentioned are from Microsoft themselves. I started a case with them from our Microsoft Silver Partner option to open a case and get direct support from Microsoft. If s…
This tutorial will walk an individual through configuring a drive on a Windows Server 2008 to perform shadow copies in order to quickly recover deleted files and folders. Click on Start and then select Computer to view the available drives on the se…
This tutorial will walk an individual through the steps necessary to install and configure the Windows Server Backup Utility. Directly connect an external storage device such as a USB drive, or CD\DVD burner: If the device is a USB drive, ensure i…

763 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

10 Experts available now in Live!

Get 1:1 Help Now