windows server 8: remote desktop services with remotefx, more than a word!

64
Windows Server 8 Remote Desktop Services with RemoteFX, more than a word! Tom Decaluw é Infrastructure – IT Manager Macintosh Retail Group Contact me: [email protected] http://trycatch.be/ blogs/decaluwet

Upload: microsoft-technet-belgium-and-luxembourg

Post on 15-Jun-2015

3.027 views

Category:

Technology


4 download

DESCRIPTION

More info on http://www.techdays.be.

TRANSCRIPT

Page 1: Windows Server 8: Remote Desktop Services with RemoteFX, more than a word!

Windows Server 8 Remote Desktop Services with RemoteFX, more than a word!

TomDecaluwéInfrastructure – IT Manager

Macintosh Retail Group

Contact me:[email protected]://trycatch.be/blogs/decaluwet

Page 2: Windows Server 8: Remote Desktop Services with RemoteFX, more than a word!

Brief History

Install Experience RemoteFX End-user application

What are we going to cover

Wrap-up

Page 3: Windows Server 8: Remote Desktop Services with RemoteFX, more than a word!

What we have today in our labDemonet.local

TS_WIN8_DC TS_WIN8_BR_LC TS_WIN8_GW_AP TS_WIN8_SH

10.10.10.40/24 10.10.10.30/2410.10.10.50/24 10.10.10.20/24

10.10.10.5/24

Page 4: Windows Server 8: Remote Desktop Services with RemoteFX, more than a word!

Brief history

Page 5: Windows Server 8: Remote Desktop Services with RemoteFX, more than a word!

Citrix MultiWin Technology

The history

V6.1 - 2008V6.0 - 2007

V5.0 - 2000V4.0 - 1998

V7.1 - 2010V7.0 - 2009

V5.2 - 2003V5.1 - 2001

V8.0 - 2012

R2 SP1

TS is part of the core OSadded 24-bit colorConsoleSession directoryLocal resource mapping Transport layer Security TLS

Support for WPFNetwork Level Authenticationmulti-monitor

New console connectSeamless windowsEasy printRDP gateway

Media player redirectBi-directional audioBetter multi monitor supportAero glass supportBitmap acccelerationLanguage bar docking

Remote FX Media editionRemote FX

Push to the Cloud

Page 6: Windows Server 8: Remote Desktop Services with RemoteFX, more than a word!

Three historical security issues

RDP sessions are susceptible to in-memory credential harvesting that can be used for pass the hash attacks

RDP was vulnerable to a man-in-the-middle attack. Solved in Win2003 SP1 with TLS and later with NLA

Text/Pic

http://blogs.msdn.com/b/rds/archive/2008/07/21/configuring-terminal-servers-for-server-authentication-to-prevent-man-in-the-middle-attacks.aspx

http://www.sans.org/reading_room/whitepapers/testing/pass-the-hash-attacks-tools-mitigation_33283

http://www.microsoft.com/security/portal/Threat/Encyclopedia/Entry.aspx?Name=Worm%3aWin32%2fMorto.A

RDP sessions are susceptible to brute force password attacks

Page 7: Windows Server 8: Remote Desktop Services with RemoteFX, more than a word!

Will we need TS in a modern hybrid world

You as a consumer

• Legacy applications• Desktop consolidation

(VDI / Session Host)• Remote access• Business continuity• Quick adoption• …

You as a provider

• Rich cloud apps• Ease of deploy and

scale• Security• …

Not For Remote Management => server manager

Page 8: Windows Server 8: Remote Desktop Services with RemoteFX, more than a word!

Remote access connectivity model Direct

accessManaged clients

Windows 7

Windows , MAC, Linux

Slates and tablets,

smartphones, etc.

SSL gateway

TMG/UAG

RDGW

Remote Desktop

><

HTTP (s) / APP

publish

TMG

Medium level

Line of business

Low level

Line of business

Email / files read only

TR

US

THIGH Confidential

Business Intelligence

(payroll, Finance)

MEDIUM

LOW

sensetivity

EndpointsTechnology Data

Page 9: Windows Server 8: Remote Desktop Services with RemoteFX, more than a word!

Remote access connectivity model

Managed clients

Windows 7

Windows , MAC, Linux

Slates and tablets,

smartphones, etc.

TR

US

T

Endpoints

Who

Where

Device

Page 10: Windows Server 8: Remote Desktop Services with RemoteFX, more than a word!

Remote access connectivity model

Medium level

Line of business

Low level

Line of business

Email / files read only

HIGH Confidential

Business Intelligence

(payroll, Finance)

MEDIUM

LOW

sensetivity

Data

Data

Page 11: Windows Server 8: Remote Desktop Services with RemoteFX, more than a word!

Remote access connectivity model Direct

accessManaged clients

Windows 7

Windows , MAC, Linux

Slates and tablets,

smartphones, etc.

SSL / VPN gateway

TMG/UAG

RDGW

Remote Desktop

><

HTTP (s) / APP

publish

TMG

Medium level

Line of business

Low level

Line of business

Email / files read only

TR

US

THIGH Confidential

Business Intelligence

(payroll, Finance)

MEDIUM

LOW

sensetivity

EndpointsTechnology Data

Page 12: Windows Server 8: Remote Desktop Services with RemoteFX, more than a word!

Remote access connectivity model

Managed clients

Windows 7

Windows , MAC, Linux

Slates and tablets,

smartphones, etc.

TR

US

TTrust is a combination of

Idendity + Device and Health

+ Location

How sure are you the person telling you who they are are actually who they are + RBAC model

Increase by:- Complex password- Call and enable- Multi account- Multi factor auth- ....

+What device is being used and how sure are we of the health of the user.

Increase by:- Health inspection- Device jump- ...

+How confident are we about the physical and logical location

Increase by:- Changing physical

location- Logical network

Page 13: Windows Server 8: Remote Desktop Services with RemoteFX, more than a word!

The 6 roles in a Remote Desktop setup

What we have

- RD web and app- RD Gateway- Connection

broker- RD Licensing- RD Session Host- RD VDI host

Page 14: Windows Server 8: Remote Desktop Services with RemoteFX, more than a word!

4 positions of you TS gateway

RDG in the DMZ, with Active Directory

No DMZ. RDG in the LAN

Reverse Proxy in the DMZ. RDG in the LAN

TMG / UAG

RDG in the DMZ. No Active Directory

Þ Dual auth. required

Page 15: Windows Server 8: Remote Desktop Services with RemoteFX, more than a word!

2 positions for your RD session hosts

RDG in the DMZ, with Active Directory

No DMZ. RDG in the LAN

Reverse Proxy in the DMZ. RDG in the LAN

TMG / UAG

RDG in the DMZ. No Active Directory

Þ Dual auth. required

Client/isolated VLAN

Server VLAN

Page 16: Windows Server 8: Remote Desktop Services with RemoteFX, more than a word!

Installation Experience

Page 17: Windows Server 8: Remote Desktop Services with RemoteFX, more than a word!

Do it all from one system / one console

Server Manager

“One stop shop”Scenario Based install

Role Based Install

Text/Pic

Page 18: Windows Server 8: Remote Desktop Services with RemoteFX, more than a word!

DemoAdd servers to Server admin + powershell,…

Page 19: Windows Server 8: Remote Desktop Services with RemoteFX, more than a word!

Role based deployment

You are installing from a technicalviewpoint

”A function or position on a server per server basis”

Text/Icon/PicText/Icon/Pic

Text/Icon/Pic

Text/Icon/Pic

Page 20: Windows Server 8: Remote Desktop Services with RemoteFX, more than a word!

DemoRole base deploy SessionHost

Page 21: Windows Server 8: Remote Desktop Services with RemoteFX, more than a word!

Text/Icon/Pic

Scenario based deployment

You are installing with the

eye to reach a specific goal

“A model of an expected

sequence of events on all servers in one

wizard”

Page 22: Windows Server 8: Remote Desktop Services with RemoteFX, more than a word!

Text/Icon/Pic

Scenario based deployment

Currently supported roles

• Remote Desktop Session Host • Remote Desktop WebAccess • Remote Desktop Connection

Broker* Can be add after initial install:• Remote Desktop Gateway• Remote Desktop Virtualization Host• Remote Desktop Licensing Server

Page 23: Windows Server 8: Remote Desktop Services with RemoteFX, more than a word!

DemoScenario Base deploy Broker and App host

Page 24: Windows Server 8: Remote Desktop Services with RemoteFX, more than a word!

Overview based install

What we don’t need (today)

- VDI host

What We need

- RD gateway- RD licensing

What we have

- RD web and app

- Session broker- Session host

Text/Pic

Page 25: Windows Server 8: Remote Desktop Services with RemoteFX, more than a word!

DemoOverview base install the Gateway and Licensing Role

+ check default RDGW CAP and RAP

Page 26: Windows Server 8: Remote Desktop Services with RemoteFX, more than a word!

Remote FX

Page 27: Windows Server 8: Remote Desktop Services with RemoteFX, more than a word!

Key focus points

Fast and fluid graphics

Wide range of network

conditions

New client devices & form

factors

Windows Metro style user interface

Mobile devices, WAN

Touch, Slates

Page 28: Windows Server 8: Remote Desktop Services with RemoteFX, more than a word!

What’s new in Remote Desktop Win8

Broad Range of Clients Supported

RemoteFX For WAN

RemoteFX Adaptive Graphics

RemoteFX Media Remoting

RemoteFX Multi Touch

RemoteFX USB Redirection

Metro Style Remote Desktop App

Choice of Software or Physical GPU, vGPU for VM

Available for Sessions, VM’s and Physical Machines

Desktop remoting experience

New experience

No more tradeoffs

Rem

ote

FX

Page 29: Windows Server 8: Remote Desktop Services with RemoteFX, more than a word!

Remote FX

Network

Page 30: Windows Server 8: Remote Desktop Services with RemoteFX, more than a word!

RemoteFX adaptive system

vs

Auto-tuning

Page 31: Windows Server 8: Remote Desktop Services with RemoteFX, more than a word!

Network issues

Latency Packet LossLimited

bandwidth

End to end delay/ping (e.g. 100ms) Burst or Random

E.g. <2 Mbps vs 100Mbps for LAN

TCP => UDP (good for packet loss and latency)

Page 32: Windows Server 8: Remote Desktop Services with RemoteFX, more than a word!

RemoteFX for WAN – Multi transport (old) RemoteFX

Adaptive Graphics

VC

Dynamic Virtual Channel Management

Network autodetect

RemoteFX Graphics Dynamic

Virtual Channel

RemoteFX Media

Remoting

RemoteFX Audio

RemoteFX TCP Transport

Audio PluginsVideo Encode

PluginsInput

Control

Devices

VC VC

NETWORK (TCP Packets)

Page 33: Windows Server 8: Remote Desktop Services with RemoteFX, more than a word!

RemoteFX for WAN – Multi transport (New) RemoteFX

Adaptive Graphics

VC

Dynamic Virtual Channel Management

Network autodetect

RemoteFX Graphics Dynamic

Virtual Channel

RemoteFX Media

Remoting

RemoteFX Audio

RemoteFX TCP Transport RemoteFX UDP transport

Audio PluginsVideo Encode

PluginsInput

Control

Devices

VC VC

NETWORK (TCP & UDP Packets)

Page 34: Windows Server 8: Remote Desktop Services with RemoteFX, more than a word!

DemoSniff a win8 normal RDP sessionTCP 3389UDP 3389

Page 35: Windows Server 8: Remote Desktop Services with RemoteFX, more than a word!

Remote FX

Engine

Page 36: Windows Server 8: Remote Desktop Services with RemoteFX, more than a word!

RemoteFX Graphics Architecture Overview

Windows Metro style UI and Applications (HTML, XAML, Native, etc..)

RemoteFX Intelligent Caching

RemoteFX Progressive Rendering

RemoteFX Optimized Text

Codecs

RemoteFX Media

Remoting

RemoteFX for WAN Transports

RemoteFX Calista Codec

Apps and Desktop

RemoteFX Adaptive Graphics

RemoteFX for WAN

RemoteFX Protocol Encoding

RIGHT TYPE OF CODEC FOR EACH TYPE OF CONTENT

Page 37: Windows Server 8: Remote Desktop Services with RemoteFX, more than a word!

RemoteFX Progressive Rendering

Page 38: Windows Server 8: Remote Desktop Services with RemoteFX, more than a word!

RemoteFX Optimized Text codecs

• Text is sent as text and always sharp => think of pinch zoom blurring

Page 39: Windows Server 8: Remote Desktop Services with RemoteFX, more than a word!

Remote FX Adaptive Graphics

Page 40: Windows Server 8: Remote Desktop Services with RemoteFX, more than a word!

Remote FX Adaptive Graphics

Image Content

Text Content

Video/Animations

Page 41: Windows Server 8: Remote Desktop Services with RemoteFX, more than a word!

Remote Desktop Server and network side

TS Web

Page 42: Windows Server 8: Remote Desktop Services with RemoteFX, more than a word!

New features

Remote desktop WebAccessYou can now create folders in the webpage to group apps

Text/Icon/PicText/Icon/Pic

Page 43: Windows Server 8: Remote Desktop Services with RemoteFX, more than a word!

DemoTS web access + folder creation / port change

Page 44: Windows Server 8: Remote Desktop Services with RemoteFX, more than a word!

Remote Desktop Server and network side

TS Gateway

Page 45: Windows Server 8: Remote Desktop Services with RemoteFX, more than a word!

New features

Remote desktop GatewayPublish on non standard port (requires RDP 8.0 client)Add UDP support

Text/Icon/Pic

UDP 3391

Page 46: Windows Server 8: Remote Desktop Services with RemoteFX, more than a word!

DemoDemo connect to TS direct / via GWSniff the traffic

Page 47: Windows Server 8: Remote Desktop Services with RemoteFX, more than a word!

End-user application

Page 48: Windows Server 8: Remote Desktop Services with RemoteFX, more than a word!

Two flavors

Classic mstsc.exe Metro style RDP client

<>

Both support RDP 8.0

Page 49: Windows Server 8: Remote Desktop Services with RemoteFX, more than a word!

Classic MSTSC

Detect connectin quality automatically=>

Page 50: Windows Server 8: Remote Desktop Services with RemoteFX, more than a word!

Classic MSTSC

Authenticated using LiveID

Now supports RDP 8.0=>

Page 51: Windows Server 8: Remote Desktop Services with RemoteFX, more than a word!

Classic MSTSC

Authenticated using LiveID

Now supports RDP 8.0=>

Page 52: Windows Server 8: Remote Desktop Services with RemoteFX, more than a word!

Classic MSTSCRemote actions - App bar- Charms- Snap

=>

Page 53: Windows Server 8: Remote Desktop Services with RemoteFX, more than a word!

DemoLogon to session host through MSTSC.EXE

Page 54: Windows Server 8: Remote Desktop Services with RemoteFX, more than a word!

Metro style RDP

Touch Remoting

Touch Friendly UI

Integrated with app publishing

Page 55: Windows Server 8: Remote Desktop Services with RemoteFX, more than a word!

Metro style RDP > swipe from the right

App sepcific settings

System settings

Page 56: Windows Server 8: Remote Desktop Services with RemoteFX, more than a word!

Metro style RDP > swipe from the right

Auto tuning WAN

Auto tuning CPU

Auto Codec selection

Auto selection Adaptive graphics

Page 57: Windows Server 8: Remote Desktop Services with RemoteFX, more than a word!

Metro style RDP >Subscription

RDP Autodiscover

Page 58: Windows Server 8: Remote Desktop Services with RemoteFX, more than a word!

Metro style RDP > System Access

Page 59: Windows Server 8: Remote Desktop Services with RemoteFX, more than a word!
Page 60: Windows Server 8: Remote Desktop Services with RemoteFX, more than a word!

Open sessions bar

Page 61: Windows Server 8: Remote Desktop Services with RemoteFX, more than a word!

DemoMetro app

Page 62: Windows Server 8: Remote Desktop Services with RemoteFX, more than a word!

Wrap up

1. Brief history2. Installation Experience3. Remote Desktop Server and

network side4. End-user application

Page 63: Windows Server 8: Remote Desktop Services with RemoteFX, more than a word!

MVP Freek Berson: http://microsoftplatform.blogspot.comRemote desktop team blog:http://blogs.msdn.com/b/rds/

Want more:

Page 64: Windows Server 8: Remote Desktop Services with RemoteFX, more than a word!

© 2012 Microsoft Corporation. All rights reserved. Microsoft, Windows, Windows Vista and other product names are or may be registered trademarks and/or trademarks in the U.S. and/or other countries.The information herein is for informational purposes only and represents the current view of Microsoft Corporation as of the date of this presentation. Because Microsoft must respond to changing market conditions, it should not be interpreted to be a commitment on the part of Microsoft, and Microsoft cannot guarantee the accuracy of any information provided after the date of this presentation. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN THIS PRESENTATION.

[email protected]