Note
Access to this page requires authorization. You can try signing in or changing directories.
Access to this page requires authorization. You can try changing directories.
Applies To: Windows Small Business Server 2011 Standard
Problem The Terminal Services (TS) Gateway role service is not configured properly.
Features affected The Connect Computer feature in Remote Web Workplace does not work.
Solution To resolve this issue, you must manually configure TS Gateway as follows:
Configure the RPC application for TS Gateway.
Configure the RpcWithCert application for TS Gateway.
Configure the certificate for TS Gateway.
Repair TS Gateway policies.
Configure Connection Authorization policies.
Configure Resource Authorization policies.
Click Start, click All Programs, click Administrative Tools, and then click Internet Information Services (IIS) Manager.
In the User Account Control window, click Continue.
In the Internet Information Services (IIS) Manager console, double-click ServerName, double-click Sites, and then double-click SBS Web Applications.
Select the RPC application, and then, in the IIS section of the center pane, double-click SSL Settings.
Select Require SSL and Require 128-bit SSL.
In the Actions pane, click Apply.
Select the RPC application, and then, in the IIS section of the center pane, double-click Authentication.
For Windows Authentication, select Enable. For Anonymous Authentication, select Disable.
Click Start, click All Programs, click Administrative Tools, and then click Internet Information Services (IIS) Manager.
In the User Account Control window, click Continue.
In the Internet Information Services (IIS) Manager console, double-click ServerName, double-click Sites, and then double-click SBS Web Applications.
Select the RPC application, and then, in the IIS section of the center pane, double-click SSL Settings.
Select Require SSL and Require 128-bit SSL. For Client Certificates, select Require
In the Actions pane, click Apply.
Select the RpcWithCert application, and then, in the IIS section of the center pane, double-click Authentication.
For Anonymous Authentication, select Disabled.
Click Start, point to Administrative Tools, point to Terminal Services, and then click TS Gateway Manager.
Right-click <ServerName> (Local), and then click Properties.
In the ServerName Properties window, click the SSL Certificate tab
Select Select an existing certificate for SSL encryption, and then click Browse Certificates.
In the certificate list, select Sites.
Click Install, and then click OK.
Click Start, point to Administrative Tools, point to Terminal Services, and then click TS Gateway Manager.
Expand <ServerName> (Local), and then expand Policies.
Delete all the policies in Connection Authorization Policies and in Resource Authorization Policies.
Click Start, point to Administrative Tools, point to Terminal Services, and then click TS Gateway Manager.
Expand <ServerName> (Local), and then expand Policies.
Right-click Connection Authorization Policies, click Create New Policy, and then click Custom.
In the Create New Policy window, do the following:
- On the General tab, in Policy, type General Connection Authorization Policy.
On the Requirements tab, in Supported Windows authentication methods, select Password and Smart card. For User group membership, add “<Domain>/Domain Users”.
On the Device Redirection tab, keep the default options.
To create the policy, click OK.
Click Start, point to Administrative Tools, point to Terminal Services, and then click TS Gateway Manager.
Expand <servername>(Local), expand Policies.
Right-click Resource Authorization Policies select Create New Policy, and then click Custom.
In the Create New Policy window, do the following:
- On the General tab, for Policy name, type General Resource Authorization Policy (1). For description, type Allow authorized users to access all company network resources.
On the User Groups tab, for User group membership, add “<domain>/Domain Users”.
On the Computer tab do the following:
Select the Select an existing Active Directory security group option and click Browse.
In the Select Users, Computers and Groups, for Enter the object name to select, type Domain Controllers, click Check Names, and then click OK.
Click Start, point to Administrative Tools, point to Terminal Services, and then click TS Gateway Manager.
Expand <servername>(Local), expand Policies.
Right-click Resource Authorization Policies select Create New Policy, and then click Custom.
In the Create New Policy window, do the following:
- On the General tab, for Policy name, type General Resource Authorization Policy (2). For description, type Allow authorized users to access all company network resources.
On the User Groups tab, for User group membership, add “<domain>/Domain Users”.
On the Computer tab do the following:
Select the Select an existing Active Directory security group option and click Browse.
In the Select Users, Computers and Groups, for Enter the object name to select, type Domain Computers, click Check Names, and then click OK.