Start a Conversation

Unsolved

This post is more than 5 years old

1295

January 18th, 2011 14:00

Connection Broker Options for MAC

So, one issue we are starting to hit is that in the Microsoft world of RDS/RDGateway the actual Gateway server facilitates the connection with the broker on behalf of the clients so that its stictly an SSL connection as far as the client is concerned.

With the Quest setup, the RDP stream is SSL, but there needs to be an initial connection on an alternate port then 80/443 through the gateway server 9in our case we picked 4000).

Unfortunately, this alternate port is partly our selection (since we were learning when we set it up) and partly the fact the connection broker session is not using the SSL connection

Please tell me there are plans to fix this sooner rather then later as it sucks having a basic Microsoft product with more functionality then our purchased product...especially since Microsoft usually does things ass backwards.

January 20th, 2011 09:00

Hello,

We do have this functionality.

You can setup the SSL Gateway to act as a Connection Broker proxy that listens on port 443 and forwards the queries on to the Connection Broker on which ever port your CB listens on.

sslcb.jpg

That screenshot if from my test lab so the SSL Gateway and Connection Broker are on the same machine.

This would allow the Client to talk to the Connection Broker via the SSL Gateway and port 443.

Thanks, Andrew.

1 Rookie

 • 

98 Posts

January 20th, 2011 21:00

This is what Mine looks like.  I assume I would have to have a secondary external IP coming into the Server and listening on another IP on the Gateway server for 443 and then send that to the connection Broker.

secureit.jpg

1 Rookie

 • 

98 Posts

January 24th, 2011 21:00

Hey Andrew…here is how we are currently running:

Scenario 1 – Users login to website when not hear home computer

Scenario 2 – Users are configured with RDP Client (we are moving from this due to no load balancing and single session enforcement)

Scenario 3 – Users are running App portal for MAC or PC (our new preferred method)

Eventually I plan on phasing out Scenario 2

January 24th, 2011 21:00

Hi,  yes you can only have 2 of the 3 listening on 443 AND on the same IP.

So, if everything needs to be SSL you get 2 choices.

What you have already:

1, All on the same IP but 1 of the options listening on a different port

or:

2. All on 443 but 1 of the options listening on a different IP

This assumes that you're Users actually go via a Website - I thought when we've talked previously that your Guys use AppPortal now? If they do, you can skip the Web Interface proxy and just have 1 IP with the RDP and Connection Broker Proxy on 443.

January 24th, 2011 22:00

Ok.

I'd add a 2nd IP address so RDP, Web and CB can all be secured on 443. You already have a wildcard certificate, so this is easy.

You probably know this, but just in case...

The RDP Proxy secures the actual session no matter which scenario you use. Eg, not just scenario 2.

Thanks.

No Events found!

Top