Solved

2008 R2 Remote Destkop Services External Connector

Posted on 2013-01-04
6
890 Views
Last Modified: 2013-01-08
We would like to set up a new Windows Server 2008 R2 Remote Desktop Server.  We have around 250 people that need to connect.

Our scenario:

- Single 2008 R2 Remote Desktop Server

- This server will host one application that needs to get to a database on another server and users need to connect to a file share on a third server.

- We would like to use the Remote Desktop External Connector.

- The Remote Desktop Server computer is a member of our domain, prodata.local.

- The users are CLIENTS, not employees.  They are CLIENTS.  People that pay us money for services we provide.  We are providing the Remote Desktop Server a part of our service so they can pull their own reports and so forth from the application aforementioned.

-  All clients have a domain user account in our domain, prodata.local.

-  The users connecting to us in most cases do not have their own Windows domain.  They are small peer-to-peer networks of 3 - 8 computers, most still running Windows XP.

Can we use the External Connector in our scenario?  I have had several conversations and have yet to receive a straight answer.  Here is what I've been told so far:

*  Sure!  Just install that Connector and that puppy will open right on up and allow unlimited users!

*  This will allow unlimited external users but internal users, employees, will be blocked.  The way the server tells the difference between external users and employees is by <insert very hard to understand and barely believable process here >

*  You'll have unlimited external users and employees won't be able to connect at all.  Furthermore, external users can't access file shares and stuff.  Just because they have domain accounts means nothing.  The Session host provides its own permissions.  You'll have to mirror that file share somewhere for external users.

See what I mean?  Can someone shed some light on this?  I would very much appreciate it if the people that answer would be those who have actually done this before and have practical knowledge.  

JamesNT
0
Comment
Question by:JamesNT
  • 3
  • 2
6 Comments
 
LVL 78

Expert Comment

by:David Johnson, CD, MVP
ID: 38746322
3 EC licenses will be required (one for each server)
Yes, Unlimited Users, Users cannot be employees or contractors.. Don't have a clue if employees are blocked.. but it is a violation of the TOS.

So it looks like a viable alternative to RDS user CALS in this scenario (about 1/2 price

CAL calculator (User)
If the count includes external access:
a) If a Windows Server EC is assigned to the server (Volume Licensing only), subtract all users who are not employees or on-site contractors and agents.
b) Subtract unauthenticated external users, as these do not require a CAL.



DISCLAIMER: Licensing advice offered here is a "best effort" and based on the understanding of the respondents. Licenses can change and we may not be aware of these changes or may misunderstand them. Further, licenses can differ by country and/or region and what we understand to be true in our region could be false in your region. "they told me on Experts-Exchange" will not be a valid defense in a software audit.  All licensing questions should be confirmed with the appropriate licensing authority (the maker of the software/issuer of the license).
0
 

Author Comment

by:JamesNT
ID: 38746781
What 3 EC licenses?  The only ones I know of that I need for each server are:

*  Remote Desktop External Connector
*  Windows Server External Connector

What's the third one?

JamesNT
0
 
LVL 24

Accepted Solution

by:
Coralon earned 500 total points
ID: 38747249
The way it works --

The external connector by terms of service cannot be used for employees.  
From a physical standpoint, it uses local anonymous accounts on the server for logins.  There is no option for customization, remembering the user, etc..

If you have a reporting app that does not require anything customized for use, and you can use the application to manage the logins as opposed to AD, then you could use it.  I.e., you publish some sort of Windows app that provides it's own login, and you do not use AD for security.

However, since you have accounts on the domain, it seems likely, you either don't have that kind of app, or you need to maintain customization, so the external connector will not do what you need it to.  

Coralon
0
Don't lose your head updating email signatures!

Do your end users still have the wrong email signature? Do email signature updates bore you or fill you with a sense of dread? You can make this a whole lot easier on yourself by trusting an Exclaimer email signature management solution. Over 50 million users do...so should you!

 

Author Comment

by:JamesNT
ID: 38747563
The External Connector for RDS is starting to sound pretty useless......

JamesNT
0
 
LVL 24

Expert Comment

by:Coralon
ID: 38747949
Yeah, it really is.  They charge $10k/server for a connector that almost can't be used..  You don't need the RDS licenses with it, but the ability to use it for individual users with individualized settings is just not there.  :-\

Coralon
0
 

Author Comment

by:JamesNT
ID: 38757490
Coralon,

Looks like I found an article from Citrix that backs you up.

http://support.citrix.com/article/CTX105499

JamesNT
0

Featured Post

Netscaler Common Configuration How To guides

If you use NetScaler you will want to see these guides. The NetScaler How To Guides show administrators how to get NetScaler up and configured by providing instructions for common scenarios and some not so common ones.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Sometimes drives fill up and we don't know why.  If you don't understand the best way to use the tools available, you may end up being stumped as to why your drive says it's not full when you have no space left!  Here's how you can find out...
The recent Microsoft changes on update philosophy for Windows pre-10 and their impact on existing WSUS implementations.
To efficiently enable the rotation of USB drives for backups, storage pools need to be created. This way no matter which USB drive is installed, the backups will successfully write without any administrative intervention. Multiple USB devices need t…
This tutorial will walk an individual through the steps necessary to join and promote the first Windows Server 2012 domain controller into an Active Directory environment running on Windows Server 2008. Determine the location of the FSMO roles by lo…

911 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

16 Experts available now in Live!

Get 1:1 Help Now