Solved

2008 R2 Remote Destkop Services External Connector

Posted on 2013-01-04
6
888 Views
Last Modified: 2013-01-08
We would like to set up a new Windows Server 2008 R2 Remote Desktop Server.  We have around 250 people that need to connect.

Our scenario:

- Single 2008 R2 Remote Desktop Server

- This server will host one application that needs to get to a database on another server and users need to connect to a file share on a third server.

- We would like to use the Remote Desktop External Connector.

- The Remote Desktop Server computer is a member of our domain, prodata.local.

- The users are CLIENTS, not employees.  They are CLIENTS.  People that pay us money for services we provide.  We are providing the Remote Desktop Server a part of our service so they can pull their own reports and so forth from the application aforementioned.

-  All clients have a domain user account in our domain, prodata.local.

-  The users connecting to us in most cases do not have their own Windows domain.  They are small peer-to-peer networks of 3 - 8 computers, most still running Windows XP.

Can we use the External Connector in our scenario?  I have had several conversations and have yet to receive a straight answer.  Here is what I've been told so far:

*  Sure!  Just install that Connector and that puppy will open right on up and allow unlimited users!

*  This will allow unlimited external users but internal users, employees, will be blocked.  The way the server tells the difference between external users and employees is by <insert very hard to understand and barely believable process here >

*  You'll have unlimited external users and employees won't be able to connect at all.  Furthermore, external users can't access file shares and stuff.  Just because they have domain accounts means nothing.  The Session host provides its own permissions.  You'll have to mirror that file share somewhere for external users.

See what I mean?  Can someone shed some light on this?  I would very much appreciate it if the people that answer would be those who have actually done this before and have practical knowledge.  

JamesNT
0
Comment
Question by:JamesNT
  • 3
  • 2
6 Comments
 
LVL 78

Expert Comment

by:David Johnson, CD, MVP
ID: 38746322
3 EC licenses will be required (one for each server)
Yes, Unlimited Users, Users cannot be employees or contractors.. Don't have a clue if employees are blocked.. but it is a violation of the TOS.

So it looks like a viable alternative to RDS user CALS in this scenario (about 1/2 price

CAL calculator (User)
If the count includes external access:
a) If a Windows Server EC is assigned to the server (Volume Licensing only), subtract all users who are not employees or on-site contractors and agents.
b) Subtract unauthenticated external users, as these do not require a CAL.



DISCLAIMER: Licensing advice offered here is a "best effort" and based on the understanding of the respondents. Licenses can change and we may not be aware of these changes or may misunderstand them. Further, licenses can differ by country and/or region and what we understand to be true in our region could be false in your region. "they told me on Experts-Exchange" will not be a valid defense in a software audit.  All licensing questions should be confirmed with the appropriate licensing authority (the maker of the software/issuer of the license).
0
 

Author Comment

by:JamesNT
ID: 38746781
What 3 EC licenses?  The only ones I know of that I need for each server are:

*  Remote Desktop External Connector
*  Windows Server External Connector

What's the third one?

JamesNT
0
 
LVL 23

Accepted Solution

by:
Coralon earned 500 total points
ID: 38747249
The way it works --

The external connector by terms of service cannot be used for employees.  
From a physical standpoint, it uses local anonymous accounts on the server for logins.  There is no option for customization, remembering the user, etc..

If you have a reporting app that does not require anything customized for use, and you can use the application to manage the logins as opposed to AD, then you could use it.  I.e., you publish some sort of Windows app that provides it's own login, and you do not use AD for security.

However, since you have accounts on the domain, it seems likely, you either don't have that kind of app, or you need to maintain customization, so the external connector will not do what you need it to.  

Coralon
0
ScreenConnect 6.0 Free Trial

Check out the updates in one game-changing release, ScreenConnect 6.0, based on partner feedback. New features include a redesigned UI that improves session organization and overall user experience. See the enhancements for yourself!

 

Author Comment

by:JamesNT
ID: 38747563
The External Connector for RDS is starting to sound pretty useless......

JamesNT
0
 
LVL 23

Expert Comment

by:Coralon
ID: 38747949
Yeah, it really is.  They charge $10k/server for a connector that almost can't be used..  You don't need the RDS licenses with it, but the ability to use it for individual users with individualized settings is just not there.  :-\

Coralon
0
 

Author Comment

by:JamesNT
ID: 38757490
Coralon,

Looks like I found an article from Citrix that backs you up.

http://support.citrix.com/article/CTX105499

JamesNT
0

Featured Post

Enabling OSINT in Activity Based Intelligence

Activity based intelligence (ABI) requires access to all available sources of data. Recorded Future allows analysts to observe structured data on the open, deep, and dark web.

Join & Write a Comment

Suggested Solutions

Redirected folders in a windows domain can be quite useful for a number of reasons, one of them being that with redirected application data, you can give users more seamless experience when logging into different workstations.  For example, if a use…
You might have come across a situation when you have Exchange 2013 server in two different sites (Production and DR). After adding the Database copy in ECP console it displays Database copy status unknown for the DR exchange server. Issue is strange…
This tutorial will walk an individual through configuring a drive on a Windows Server 2008 to perform shadow copies in order to quickly recover deleted files and folders. Click on Start and then select Computer to view the available drives on the se…
This tutorial will walk an individual through the process of transferring the five major, necessary Active Directory Roles, commonly referred to as the FSMO roles to another domain controller. Log onto the new domain controller with a user account t…

708 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

12 Experts available now in Live!

Get 1:1 Help Now