TechNet
Products
IT Resources
Downloads
Training
Support
Products
Windows
Windows Server
System Center
Microsoft Edge
Office
Office 365
Exchange Server
SQL Server
SharePoint Products
Skype for Business
See all products »
Resources
Channel 9 Video
Evaluation Center
Learning Resources
Microsoft Tech Companion App
Microsoft Technical Communities
Microsoft Virtual Academy
Script Center
Server and Tools Blogs
TechNet Blogs
TechNet Flash Newsletter
TechNet Gallery
TechNet Library
TechNet Magazine
TechNet Wiki
Windows Sysinternals
Virtual Labs
Solutions
Networking
Cloud and Datacenter
Security
Virtualization
Updates
Service Packs
Security Bulletins
Windows Update
Trials
Windows Server 2016
System Center 2016
Windows 10 Enterprise
SQL Server 2016
See all trials »
Related Sites
Microsoft Download Center
Microsoft Evaluation Center
Drivers
Windows Sysinternals
TechNet Gallery
Training
Expert-led, virtual classes
Training Catalog
Class Locator
Microsoft Virtual Academy
Free Windows Server 2012 courses
Free Windows 8 courses
SQL Server training
Microsoft Official Courses On-Demand
Certifications
Certification overview
Special offers
MCSE Cloud Platform and Infrastructure
MCSE: Mobility
MCSE: Data Management and Analytics
MCSE Productivity
Other resources
Microsoft Events
Exam Replay
Born To Learn blog
Find technical communities in your area
Azure training
Official Practice Tests
Support options
For business
For developers
For IT professionals
For technical support
Support offerings
More support
Microsoft Premier Online
TechNet Forums
MSDN Forums
Security Bulletins & Advisories
Not an IT pro?
Microsoft Customer Support
Microsoft Community Forums
Sign in
Home
Library
Wiki
Learn
Gallery
Downloads
Support
Forums
Blogs
Resources For IT Professionals
United States (English)
Россия (Pусский)
中国(简体中文)
Brasil (Português)
Skip to locale bar
Editing: Test Lab Guide: Demonstrate Forefront UAG SP1 RC DirectAccess with Secure Socket Tunneling Protocol (SSTP) and Remote Desktop Gateway (RDG) - Community Edition
Wiki
>
TechNet Articles
>
Test Lab Guide: Demonstrate Forefront UAG SP1 RC DirectAccess with Secure Socket Tunneling Protocol (SSTP) and Remote Desktop Gateway (RDG) - Community Edition
Article
History
Title
<p>[TOC]<br /> <br /> This is the text of the <a href="http://go.microsoft.com/fwlink/?LinkId=206505"><span style="color: #0066dd;">Test Lab Guide: Demonstrate UAG SP1 RC DirectAccess with Secure Socket Tunneling Protocol (SSTP)</span> and Remote Desktop Gateway (RDG)</a> Test Lab Guide, which you can download at <a href="http://go.microsoft.com/fwlink/?LinkId=206505">http://go.microsoft.com/fwlink/?LinkId=206505</a> </p> <p>I am posting the entire text of the Test Lab Guide here with the goal that the community can improve on the Test Lab Guide by adding new options, demonstrating new features, or just correct errors in the text :) In fact, you can make any changes you like - that is the nature of a wiki. I'm looking forward to seeing how you all can make this great Test Lab Guide even better!</p> <p>========================================================</p> <h1 style="margin: 24pt 0in 0pt;"><a name="Introduction"></a><a name="_Toc277586240"></a><a name="_Toc265500018"><span style="font-family: cambria; color: #365f91;">Introduction</span></a><o:p></o:p></h1> <p class="MsoNormal" style="margin: 0in 0in 10pt;"><span style="font-family: calibri; font-size: small;">DirectAccess is a new feature in the Windows 7 and Windows Server 2008 R2 operating systems that gives users the experience of being seamlessly connected to their intranet any time they have Internet access. With DirectAccess enabled, requests for intranet resources (such as e-mail servers, shared folders, or intranet Web sites) are securely directed to the intranet, without requiring users to connect to a VPN. DirectAccess provides increased productivity for a mobile workforce by offering the same connectivity experience both inside and outside the office. <o:p></o:p></span></p> <p class="MsoNormal" style="margin: 0in 0in 10pt;"><span style="font-family: calibri; font-size: small;">Forefront Unified Access Gateway (UAG) SP1 RC extends the value of the Windows DirectAccess solution by adding features that meet the requirements of many enterprise deployments:<o:p></o:p></span></p> <ul style="margin-top: 0in; list-style-type: disc;"> <li class="MsoNormal" style="margin: 0in 0in 10pt;"><span style="font-family: calibri; font-size: small;">Support for arrays of up to 8 UAG DirectAccess servers where configuration is done once on an array master and is automatically deployed to all other members of the array<o:p></o:p></span></li> <li class="MsoNormal" style="margin: 0in 0in 10pt;"><span style="font-family: calibri; font-size: small;">Support for Network Load Balancing, which enables the UAG DirectAccess SP1 RC array to be highly available without requiring the use of an external hardware load balancer<o:p></o:p></span></li> <li class="MsoNormal" style="margin: 0in 0in 10pt;"><span style="font-family: calibri; font-size: small;">Support for IPv4-only networks, network segments, or server or application resources with the help of NAT64/DNS64 IPv6/IPv4 transition technologies.<o:p></o:p></span></li> </ul> <p class="MsoNormal" style="margin: 0in 0in 10pt;"><span style="font-family: calibri; font-size: small;">To learn more about UAG DirectAccess, see the following resources:<o:p></o:p></span></p> <p class="MsoListParagraphCxSpFirst" style="line-height: 150%; text-indent: -0.25in; margin: 2pt 79.9pt 0pt 0.5in;"><span style="font-family: symbol;"><span style="font-size: small;">·</span><span style="font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; font-family: 'times new roman'; font-size: 7pt;"> </span></span><a href="http://technet.microsoft.com/en-us/library/ee406191.aspx"><span style="line-height: 150%; font-size: 10pt; font-family: calibri; color: #0000ff;">Forefront UAG DirectAccess Design Guide</span></a><o:p></o:p></p> <p class="MsoListParagraphCxSpLast" style="line-height: 150%; text-indent: -0.25in; margin: 0in 79.9pt 6pt 0.5in;"><span class="MsoHyperlink" style="line-height: 150%; font-family: symbol; font-size: 10pt; text-decoration: underline; color: #0000ff;">·<span style="font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; font-family: 'times new roman'; font-size: 7pt;"> </span></span><a href="http://technet.microsoft.com/en-us/library/dd857320.aspx"><span style="line-height: 150%; font-size: 10pt; font-family: calibri; color: #0000ff;">Forefront UAG DirectAccess Deployment Guide</span></a><span class="MsoHyperlink" style="line-height: 150%; font-size: 10pt;"><o:p></o:p></span></p> <p class="MsoNormal" style="margin: 0in 0in 10pt;"><span style="font-size: small; font-family: calibri;">UAG SP1 RC supports hosting multiple roles on a single UAG server or UAG array. For example, you might want to host both the DirectAccess server and SSTP VPN server roles on the same server or array. Windows 7 clients that are configured DirectAccess clients will automatically use DirectAccess to connect to intranet resources. Windows 7 clients that are not domain members, or who are not configured as DirectAccess clients can use SSTP to connect to the intranet using a network level VPN connection. Windows 7, Windows Vista and Windows XP clients can connect to Remote Desktop and RemoteApps through a UAG server that is configured to host the Remote Desktop Gateway role. In this guide, we demonstrate how a UAG server can support the combined, DirectAccess, SSTP and Remote Desktop Gateway server roles.<o:p></o:p></span></p> <h2 style="margin: 10pt 0in 0pt;"><a name="In_this_guide"></a><a name="_Toc277586241"></a><a name="_Toc265500019"></a><a name="_Toc250629632"><span style="font-family: cambria; font-size: medium; color: #4f81bd;">In this guide</span></a><o:p></o:p></h2> <p class="MsoNormal" style="margin: 0in 0in 10pt;"><span style="font-family: calibri; font-size: small;">This guide provides step-by-step instructions for configuring UAG DirectAccess SP1 RC with SSTP and Remote Desktop Gateway in a test lab so that you can see how it works. You will set up and deploy UAG DirectAccess SP1 RC using five server computers, two client computers, Windows Server 2008 R2 Enterprise edition, and Windows 7 Ultimate Edition. The Test Lab simulates intranet, Internet, and a home networks, and demonstrates a co-located Forefront UAG DirectAccess and SSTP VPN server role deployment. The starting point for this paper is the </span><a href="http://go.microsoft.com/fwlink/?LinkId=204993"><span style="line-height: 115%; font-size: 10pt; font-family: calibri;">Test Lab Guide: Demonstrate UAG SP1 RC DirectAccess</span></a><span style="font-family: calibri;"><span class="MsoHyperlink" style="line-height: 115%; font-size: 10pt; text-decoration: underline; color: #0000ff;"> </span><span style="font-size: small;">. <o:p></o:p></span></span></p> <table cellpadding="0" border="1" class="MsoNormalTable" style="margin: auto auto auto 3.75pt; width: 97%; border: 1pt solid #dddddd;"> <tbody> <tr> <td valign="bottom" style="border-color: #cccccc #cccccc #c8cdde; border-width: 1pt; border-style: solid; background-color: #efeff7; padding: 3.75pt; background-position: initial initial; background-repeat: initial initial;"> <p class="MsoNormal" style="margin: 0in 0in 10pt;"><strong><span><v:shapetype coordsize="21600,21600" o:spt="75" o:preferrelative="t" path="m@4@5l@4@11@9@11@9@5xe" filled="f" stroked="f" id="_x0000_t75"><v:stroke joinstyle="miter"></v:stroke><v:formulas><v:f eqn="if lineDrawn pixelLineWidth 0"></v:f><v:f eqn="sum @0 1 0"></v:f><v:f eqn="sum 0 0 @1"></v:f><v:f eqn="prod @2 1 2"></v:f><v:f eqn="prod @3 21600 pixelWidth"></v:f><v:f eqn="prod @3 21600 pixelHeight"></v:f><v:f eqn="sum @0 0 1"></v:f><v:f eqn="prod @6 1 2"></v:f><v:f eqn="prod @7 21600 pixelWidth"></v:f><v:f eqn="sum @8 21600 0"></v:f><v:f eqn="prod @7 21600 pixelHeight"></v:f><v:f eqn="sum @10 21600 0"></v:f></v:formulas><v:path o:extrusionok="f" gradientshapeok="t" o:connecttype="rect"></v:path><o:lock v:ext="edit" aspectratio="t"></o:lock></v:shapetype><v:shape o:spid="_x0000_i1029" alt="Description: Important" type="#_x0000_t75" id="Picture_x0020_3" style="width: 7.5pt; height: 7.5pt; visibility: visible;"><v:imagedata src="file:///C:\Users\tomsh\AppData\Local\Temp\msohtmlclip1\01\clip_image001.gif" o:title="Important"><span style="font-family: calibri; font-size: small;"></span></v:imagedata></v:shape></span><span style="font-size: small; font-family: calibri;">Important: <o:p></o:p></span></strong></p> </td> </tr> <tr> <td valign="top" style="border-color: #cccccc #d5d5d3 #cccccc #cccccc; border-width: 1pt; border-style: solid; background-color: #f7f7ff; padding: 3.75pt; background-position: initial initial; background-repeat: initial initial;"> <p class="MsoNormal" style="margin: 0in 0in 10pt;"><span style="font-family: calibri; font-size: small;">These instructions are designed for configuring a test lab using the minimum number of computers. Individual computers are needed to separate the services provided on the network, and to show clearly the required functionality. This configuration is not designed to reflect best practices, nor does it reflect a required or recommended configuration for a production network. The configuration, including IP addresses and all other configuration parameters, is designed to work only on a separate test lab network. For more information on planning and deploying DirectAccess with Forefront UAG, please see the </span><a href="http://technet.microsoft.com/en-us/library/ee406191.aspx"><span style="line-height: 115%; font-size: 10pt; font-family: calibri; color: #0000ff;">Forefront UAG DirectAccess design guide</span></a><span style="font-family: calibri; font-size: small;"> and the </span><a href="http://technet.microsoft.com/en-us/library/dd857320.aspx"><span style="line-height: 115%; font-size: 10pt; font-family: calibri; color: #0000ff;">Forefront UAG DirectAccess deployment guide</span></a><o:p></o:p></p> </td> </tr> </tbody> </table> <h1 style="margin: 24pt 0in 0pt;"><a name="Overview_of_the_test_lab_scenario"></a><a name="_Toc277586242"></a><a name="_Toc267915211"><span style="font-family: cambria; color: #365f91;">Overview of the test lab scenario</span></a><o:p></o:p></h1> <p class="MsoNormal" style="margin: 0in 0in 10pt;"><span style="font-size: small; font-family: calibri;">In this test lab scenario, Forefront UAG DirectAccess SP1 RC is deployed with:<o:p></o:p></span></p> <ul style="margin-top: 0in; list-style-type: disc;"> <li class="MsoNormal" style="margin: 0in 0in 10pt;"><span style="font-size: small; font-family: calibri;">One computer running Windows Server 2008 R2 Enterprise Edition (DC1), that is configured as an intranet domain controller, Domain Name System (DNS) server, Dynamic Host Configuration Protocol (DHCP) server, and an enterprise root certification authority (CA).<o:p></o:p></span></li> <li class="MsoNormal" style="margin: 0in 0in 10pt;"><span style="font-size: small; font-family: calibri;">One intranet member server running Windows Server 2008 R2 Enterprise Edition (UAG1), that is configured as a Forefront UAG SP1 RC DirectAccess, SSTP VPN and Remote Desktop Gateway server.<o:p></o:p></span></li> <li class="MsoNormal" style="margin: 0in 0in 10pt;"><span style="font-size: small; font-family: calibri;">One intranet member server running Windows Server 2008 R2 Enterprise Edition (APP1) that is configured as a general application server and network location server.<o:p></o:p></span></li> <li class="MsoNormal" style="margin: 0in 0in 10pt;"><span style="font-size: small; font-family: calibri;">One intranet member server running Windows Server 2003 SP2 (APP3) that is configured as an IPv4 only web and file server. This server is used to highlight the UAG’s NAT64/DNS64 capabilities.<o:p></o:p></span></li> <li class="MsoNormal" style="margin: 0in 0in 10pt;"><span style="font-size: small; font-family: calibri;">One standalone server running Windows Server 2008 R2 Enterprise Edition (INET1) that is configured as an Internet DNS and DHCP server.<o:p></o:p></span></li> <li class="MsoNormal" style="margin: 0in 0in 10pt;"><span style="font-size: small; font-family: calibri;">One standalone client computer running Windows 7 Ultimate Edition (NAT1), that is configured as a network address translator (NAT) device using Internet Connection Sharing.<o:p></o:p></span></li> <li class="MsoNormal" style="margin: 0in 0in 10pt;"><span style="font-size: small; font-family: calibri;">One roaming domain member client computer running Windows 7 Ultimate Edition (CLIENT1) that is configured as a DirectAccess client.<o:p></o:p></span></li> </ul> <p class="MsoNormal" style="margin: 0in 0in 10pt;"><span style="font-size: small; font-family: calibri;">The test lab consists of three subnets that simulate the following:<o:p></o:p></span></p> <ul style="margin-top: 0in; list-style-type: disc;"> <li class="MsoNormal" style="margin: 0in 0in 10pt;"><span style="font-size: small; font-family: calibri;">A home network named Homenet (192.168.137.0/24) connected to the Internet subnet by NAT1.<o:p></o:p></span></li> <li class="MsoNormal" style="margin: 0in 0in 10pt;"><span style="font-size: small; font-family: calibri;">The Internet subnet (131.107.0.0/24).<o:p></o:p></span></li> <li class="MsoNormal" style="margin: 0in 0in 10pt;"><span style="font-size: small; font-family: calibri;">The Corpnet subnet (10.0.0.0/24) separated from the Internet by the Forefront UAG DirectAccess server.<o:p></o:p></span></li> </ul> <p class="MsoNormal" style="margin: 0in 0in 10pt;"><span style="font-size: small; font-family: calibri;">Computers on each subnet connect using either a physical or virtual hub or switch, as shown in the following figure.<o:p></o:p></span></p> <p class="MsoNormal" style="margin: 0in 0in 10pt;"><v:shape type="#_x0000_t75" id="_x0000_i1025" style="width: 466.5pt; height: 312pt;"><v:imagedata src="file:///C:\Users\tomsh\AppData\Local\Temp\msohtmlclip1\01\clip_image002.emz"><span style="font-family: calibri; font-size: small;"></span></v:imagedata></v:shape><o:p></o:p></p> <h1 style="margin: 24pt 0in 0pt;"><a name="Configuration_component_requirements"></a><a name="_Toc277586243"></a><a name="_Toc267915212"><span style="font-family: cambria; color: #365f91;">Configuration component requirements</span></a><o:p></o:p></h1> <p class="MsoNormal" style="margin: 0in 0in 10pt;"><span style="font-size: small; font-family: calibri;">The following components are required for configuring Forefront UAG DirectAccess in the test lab:<o:p></o:p></span></p> <ul style="margin-top: 0in; list-style-type: disc;"> <li class="MsoNormal" style="margin: 0in 0in 10pt;"><span style="font-size: small; font-family: calibri;">The product disc or files for Windows Server 2008 R2 Enterprise Edition.<o:p></o:p></span></li> <li class="MsoNormal" style="margin: 0in 0in 10pt;"><span style="font-size: small; font-family: calibri;">The product disc or files for Windows Server 2003 Enterprise SP2<o:p></o:p></span></li> <li class="MsoNormal" style="margin: 0in 0in 10pt;"><span style="font-size: small; font-family: calibri;">The product disc or files for of Windows 7 Ultimate.<o:p></o:p></span></li> <li class="MsoNormal" style="margin: 0in 0in 10pt;"><span style="font-size: small; font-family: calibri;">Five computers or virtual machines that meet the minimum hardware requirements for Windows Server 2008 R2 Enterprise; two of these computers has two network adapters installed (UAG1).<o:p></o:p></span></li> <li class="MsoNormal" style="margin: 0in 0in 10pt;"><span style="font-size: small; font-family: calibri;">One computer or virtual machine that meets the minimum hardware requirements for Windows Server 2003 SP2<o:p></o:p></span></li> <li class="MsoNormal" style="margin: 0in 0in 10pt;"><span style="font-size: small; font-family: calibri;">Two computers or virtual machines that meet the minimum hardware requirements for Windows 7 Ultimate; one of these computers has two network adapters installed (NAT1).<o:p></o:p></span></li> <li class="MsoNormal" style="margin: 0in 0in 10pt;"><span style="font-size: small; font-family: calibri;">The product disc or a downloaded version of Microsoft Forefront Unified Access Gateway (UAG) SP1 RC.<o:p></o:p></span></li> </ul> <p class="MsoNormal" style="margin: 0in 0in 10pt;"><span style="font-size: small; font-family: calibri;">This Test Lab Guide demonstrates a combined UAG SP1 RC DirectAccess and SSTP deployment. <o:p></o:p></span></p> <p class="AlertLabel" style="margin: 6pt 0in 0pt;"><span><v:shape o:spid="_x0000_i1028" type="#_x0000_t75" id="Picture_x0020_9" style="width: 18pt; height: 12pt; visibility: visible;"><v:imagedata src="file:///C:\Users\tomsh\AppData\Local\Temp\msohtmlclip1\01\clip_image004.gif"><span style="font-family: calibri; font-size: small;"></span></v:imagedata></v:shape></span><strong><span style="font-size: small; font-family: calibri;">Important <o:p></o:p></span></strong></p> <p class="AlertText" style="margin: 0in 0.25in 10pt;"><span style="font-size: small; font-family: calibri;">The following instructions are for configuring a test lab using the minimum number of computers. Individual computers are needed to separate the services provided on the network and to clearly show the desired functionality. It is important to remember that this configuration is neither designed to reflect best practices nor does it reflect a desired or recommended configuration for a production network. The configuration, including IP addresses and all other configuration parameters, is designed only to work on a separate test lab network.<o:p></o:p></span></p> <p class="AlertText" style="margin: 0in 0.25in 10pt;"><span style="font-family: calibri; font-size: small;">Attempting to adapt this test lab configuration to a pilot or production deployment can result in configuration or functionality issues. To ensure proper configuration and operation of UAG DirectAccess and SSTP, please refer to the </span><a href="http://technet.microsoft.com/en-us/library/dd857320.aspx"><span style="line-height: 115%; font-size: 10pt; font-family: calibri; color: #0000ff;">Forefront UAG DirectAccess Deployment Guide</span></a><span style="font-size: small; font-family: calibri;"> for the steps to configure the UAG DirectAccess server and supporting infrastructure servers.<o:p></o:p></span></p> <h1 style="margin: 24pt 0in 0pt;"><a name="Steps_for_configuring_the_test_lab"></a><a name="_Toc277586244"><span style="font-family: cambria; color: #365f91;">Steps for configuring the test lab</span></a><o:p></o:p></h1> <p class="MsoNormal" style="margin: 0in 0in 10pt;"><span style="font-size: small; font-family: calibri;">The following sections describe how to configure UAG1 as a DirectAccess, SSTP VPN and Remote Desktop Gateway server. After UAG1 is configured, this guide provides steps for demonstrating the DirectAccess, SSTP VPN and Remote Desktop Server functionality for CLIENT1 when it is connected to the Homenet subnet.<o:p></o:p></span></p> <p class="AlertLabel" style="margin: 6pt 0in 0pt;"><span><v:shape type="#_x0000_t75" id="_x0000_i1027" style="width: 18pt; height: 12pt; visibility: visible;"><v:imagedata src="file:///C:\Users\tomsh\AppData\Local\Temp\msohtmlclip1\01\clip_image005.gif"><span style="font-family: calibri; font-size: small;"></span></v:imagedata></v:shape></span><strong><span style="font-size: small; font-family: calibri;">Note <o:p></o:p></span></strong></p> <p class="AlertText" style="margin: 0in 0.25in 10pt;"><span style="font-family: calibri; font-size: small;">You must be logged on as a member of the Domain Admins group or a member of the Administrators group on each computer to complete the tasks described in this guide. If you cannot complete a task while you are logged on with an account that is a member of the Administrators group, try performing the task while you are logged on with an account that is a member of the Domain Admins group. For all tasks described in this document you can use the <strong>CONTOSO\User1</strong> account created when you went through the steps in the UAG DirectAccess </span><a href="http://go.microsoft.com/fwlink/?LinkId=204993"><span style="line-height: 115%; font-size: 10pt; font-family: calibri;">Test Lab Guide: Demonstrate UAG SP1 RC DirectAccess</span></a><span style="font-family: calibri; font-size: small;">.<o:p></o:p></span></p> <p class="MsoNormal" style="margin: 0in 0in 10pt;"><span style="font-family: calibri; font-size: small;">The following procedures are performed to enable and allow you to test the UAG SP1 RC DCA:<o:p></o:p></span></p> <p class="MsoListParagraphCxSpFirst" style="line-height: 115%; text-indent: -0.25in; margin: 0in 0in 10pt 0.5in;"><span style="font-family: symbol;"><span style="font-size: small;">·</span><span style="font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; font-family: 'times new roman'; font-size: 7pt;"> </span></span><span style="font-size: small; font-family: calibri;"><strong>Step 1: Complete the Demonstrate UAG SP1 RC DirectAccess with SSTP Test Lab Guide – </strong>The first step is to complete all the steps in the </span><a href="http://go.microsoft.com/fwlink/?LinkId=206283"><span style="line-height: 115%; font-size: 10pt; font-family: calibri;">Test Lab Guide: Demonstrate Forefront UAG SP1 RC DirectAccess with Secure Socket Tunneling Protocol (SSTP)</span></a><span style="font-family: calibri; font-size: small;">.<o:p></o:p></span></p> <p class="MsoListParagraphCxSpMiddle" style="line-height: 115%; text-indent: -0.25in; margin: 0in 0in 10pt 0.5in;"><span style="font-family: symbol;"><span style="font-size: small;">·</span><span style="font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; font-family: 'times new roman'; font-size: 7pt;"> </span></span><span style="font-family: calibri; font-size: small;"><strong>Step 2: Install and Configure the RDS Session Host on APP1</strong>. In order to test UAG1 publishing of Remote Desktops and RemoteApps we need an RDS Session Host server on the corpnet subnet. In this step you will install the RDS Session Host Role on APP1.<o:p></o:p></span></p> <p class="MsoListParagraphCxSpMiddle" style="line-height: 115%; text-indent: -0.25in; margin: 0in 0in 10pt 0.5in;"><span style="font-family: symbol;"><span style="font-size: small;">·</span><span style="font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; font-family: 'times new roman'; font-size: 7pt;"> </span></span><span style="font-family: calibri; font-size: small;"><strong>Step 3: Generate the RemoteApp Configuration File on APP1</strong>. You will publish a RemoteApp on UAG1. In order to publish the RemoteApp, you need to generate a RemoteApp configuration file on APP1. In this step you will generate the RemoteApp configuration file and copy it to UAG1.<o:p></o:p></span></p> <p class="MsoListParagraphCxSpMiddle" style="line-height: 115%; text-indent: -0.25in; margin: 0in 0in 10pt 0.5in;"><span style="font-family: symbol;"><span style="font-size: small;">·</span><span style="font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; font-family: 'times new roman'; font-size: 7pt;"> </span></span><span style="font-family: calibri; font-size: small;"><strong>Step 4: Publish Remote Desktops on UAG1</strong>. To publish Remote Desktops you need to add the Remote Desktops Application to the portal. In this step you will add the Remote Desktop applications to the UAG1 portal page.<o:p></o:p></span></p> <p class="MsoListParagraphCxSpMiddle" style="line-height: 115%; text-indent: -0.25in; margin: 0in 0in 10pt 0.5in;"><span style="font-family: symbol;"><span style="font-size: small;">·</span><span style="font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; font-family: 'times new roman'; font-size: 7pt;"> </span></span><span style="font-family: calibri; font-size: small;"><strong>Step 5: Publish RemoteApps on UAG1</strong>. To publish RemoteApps you need to add the RemoteApps application to the portal. In this step you will add the RemoteApps application to the portal page. <o:p></o:p></span></p> <p class="MsoListParagraphCxSpMiddle" style="line-height: 115%; text-indent: -0.25in; margin: 0in 0in 10pt 0.5in;"><span style="font-family: symbol;"><span style="font-size: small;">·</span><span style="font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; font-family: 'times new roman'; font-size: 7pt;"> </span></span><span style="font-family: calibri; font-size: small;"><strong>Step 6</strong>: <strong>Test DirectAccess, SSTP and Remote Desktop Connectivity from CLIENT1</strong>. After the portal configuration is completed, you can test connectivity to resources through the UAG portal. In this step you will confirm DirectAccess and SSTP connectivity, and test Remote Desktop and RemoteApp connectivity through the portal.<o:p></o:p></span></p> <p class="MsoListParagraphCxSpLast" style="line-height: 115%; text-indent: -0.25in; margin: 0in 0in 10pt 0.5in;"><span style="font-family: symbol;"><span style="font-size: small;">·</span><span style="font-style: normal; font-variant: normal; font-weight: normal; line-height: normal; font-family: 'times new roman'; font-size: 7pt;"> </span></span><span style="font-size: small; font-family: calibri;"><strong>Step 7:</strong> <strong>Snapshot the configuration</strong>. After completing the Test Lab, take a snapshot of the working UAG DirectAccess, SSTP and Remote Desktop Gateway Test Lab so that you can return to it later to test additional scenarios.<o:p></o:p></span></p> <p class="AlertLabel" style="margin: 6pt 0in 0pt;"><span><v:shape o:spid="_x0000_i1026" type="#_x0000_t75" id="Picture_x0020_7" style="width: 18pt; height: 12pt; visibility: visible;"><v:imagedata src="file:///C:\Users\tomsh\AppData\Local\Temp\msohtmlclip1\01\clip_image005.gif"><span style="font-family: calibri; font-size: small;"></span></v:imagedata></v:shape></span><strong><span style="font-size: small; font-family: calibri;">Note <o:p></o:p></span></strong></p> <p class="AlertText" style="margin: 0in 0.25in 10pt;"><span style="font-size: small; font-family: calibri;">You will notice that there are several steps that begin with an asterisk (*). The * indicates that the step requires that you move to a computer or virtual machine that is different from the computer or virtual machine you were at when you completed the previous step. <o:p></o:p></span></p> <h2 style="margin: 10pt 0in 0pt;"><a name="STEP_1_Complete_the_Demonstrate_UAG_SP1_RC_DirectAccess_with_SSTP_Test_Lab_Guide"></a><a name="_Toc277586245"><span style="font-family: cambria; font-size: medium; color: #4f81bd;">STEP 1: Complete the Demonstrate UAG SP1 RC DirectAccess with SSTP Test Lab Guide</span></a><span style="font-size: medium; color: #4f81bd; font-family: cambria;"> <o:p></o:p></span></h2> <p class="AlertText" style="margin: 0in 0.25in 10pt 0in;"><span style="font-family: calibri; font-size: small;">The first step is to complete all the steps in the </span><a href="http://go.microsoft.com/fwlink/?LinkId=206283"><span style="line-height: 115%; font-size: 10pt; font-family: calibri;">Test Lab Guide: Demonstrate Forefront UAG SP1 RC DirectAccess with Secure Socket Tunneling Protocol (SSTP)</span></a><span style="font-size: small; font-family: calibri;">. After completing the steps in that Test Lab Guide you will have the core infrastructure required to complete this Test Lab Guide on how to configure UAG DirectAccess with SSTP and RDG.<span> </span>If you have already completed the steps in that Test Lab Guide and saved a snapshot or disk image of the Test Lab, you can restore the snapshot or image and begin with the next step.<o:p></o:p></span></p> <h2 style="margin: 10pt 0in 0pt;"><a name="STEP_2_Install_and_Configure_the_RDS_Session_Host_on_APP1"></a><a name="_Toc277586246"></a><a name="_Toc265500029"><span style="font-family: cambria; font-size: medium; color: #4f81bd;">STEP 2: </span></a><span style="font-size: medium; color: #4f81bd; font-family: cambria;"><span>Install and Configure the RDS Session Host on APP1</span><o:p></o:p></span></h2> <p class="MsoNormal" style="margin: 0in 0in 10pt;"><span style="font-size: small; font-family: calibri;">In order to test UAG1 publishing of Remote Desktops and RemoteApps we need an RDS Session Host server on the corpnet subnet. In this step you will install and configure the RDS Session Host Role on APP1. <o:p></o:p></span></p> <p class="MsoNormal" style="margin: 0in 0in 10pt;"><strong><span style="font-size: small; font-family: calibri;">Install the RDS Session Host on APP1:<o:p></o:p></span></strong></p> <ol style="margin-top: 0in; list-style-type: decimal;"> <li class="MsoNormal" style="margin: 0in 0in 10pt;"><span style="font-size: small; font-family: calibri;">At the APP1 computer or virtual machine, log on as CORP\User1. Open the <strong>Server Manager</strong>. In the left pane of the <strong>Server Manager</strong> console, click the <strong>Roles</strong> node. In the right pane of the console, click <strong>Add Roles</strong>. <o:p></o:p></span></li> <li class="MsoNormal" style="margin: 0in 0in 10pt;"><span style="font-size: small; font-family: calibri;">On the <strong>Before You Begin</strong> page, click <strong>Next</strong>.<o:p></o:p></span></li> <li class="MsoNormal" style="margin: 0in 0in 10pt;"><span style="font-size: small; font-family: calibri;">On the <strong>Select Server Roles</strong> page, select <strong>Remote Desktop Services</strong> and click <strong>Next</strong>.<o:p></o:p></span></li> <li class="MsoNormal" style="margin: 0in 0in 10pt;"><span style="font-size: small; font-family: calibri;">On the <strong>Introduction to Remote Desktop Services</strong> page, click <strong>Next</strong>. <o:p></o:p></span></li> <li class="MsoNormal" style="margin: 0in 0in 10pt;"><span style="font-size: small; font-family: calibri;">On the <strong>Role Services</strong> page, select <strong>Remote Desktop Session Host</strong> and click <strong>Next</strong>.<o:p></o:p></span></li> <li class="MsoNormal" style="margin: 0in 0in 10pt;"><span style="font-size: small; font-family: calibri;">On the <strong>Application Compatibility </strong>page, click <strong>Next</strong>.<o:p></o:p></span></li> <li class="MsoNormal" style="margin: 0in 0in 10pt;"><span style="font-size: small; font-family: calibri;">On the <strong>Authentication Method</strong> page, select <strong>Require Network Level Authentication</strong> and click <strong>Next</strong>.<o:p></o:p></span></li> <li class="MsoNormal" style="margin: 0in 0in 10pt;"><span style="font-size: small; font-family: calibri;">On the <strong>Licensing Mode</strong> page, select <strong>Configure later</strong> and click <strong>Next</strong>.<o:p></o:p></span></li> <li class="MsoNormal" style="margin: 0in 0in 10pt;"><span style="font-size: small; font-family: calibri;">On the <strong>User Groups</strong> page, confirm <strong>Administrators</strong> is in the <strong>User or User Groups</strong> list and click <strong>Next</strong>.<o:p></o:p></span></li> <li class="MsoNormal" style="margin: 0in 0in 10pt;"><span style="font-size: small; font-family: calibri;">On the <strong>Client Experience</strong> page, put a checkmark in the <strong>Audio and video playback</strong>, <strong>Audio recording redirection</strong>, and <strong>Desktop composition (provides the user interface elements of Windows Aero)</strong> checkboxes and click <strong>Next</strong>. <o:p></o:p></span></li> <li class="MsoNormal" style="margin: 0in 0in 10pt;"><span style="font-size: small; font-family: calibri;">On the <strong>Confirmation</strong> page, click <strong>Install</strong>. When you see the message <strong>Restart Pending</strong>, click <strong>Close. </strong>In the <strong>Add Roles Wizard</strong> dialog box, click <strong>Yes</strong>. The machine will restart to complete installation. Log on as CORP\User1. After you log on the installation will continue. On the <strong>Results</strong> page, click <strong>Close</strong>.<o:p></o:p></span></li> </ol> <p class="MsoNormal" style="margin: 0in 0in 10pt;"><span style="font-size: small; font-family: calibri;"><strong>Configure the RDS Session Host on APP1:</strong><o:p></o:p></span></p> <ol style="margin-top: 0in; list-style-type: decimal;"> <li class="MsoNormal" style="margin: 0in 0in 10pt;"><span style="font-size: small; font-family: calibri;">Click <strong>Start</strong> and point to <strong>Administrative Tools</strong>. Point to <strong>Remote Desktop Services</strong> and click <strong>Remote Desktop Session Host Configuration</strong>. <o:p></o:p></span></li> <li class="MsoNormal" style="margin: 0in 0in 10pt;"><span style="font-size: small; font-family: calibri;">In the <strong>Remote Desktop Session Host Configuration</strong> console, in the right pane of the console, right click <strong>RDP-Tcp</strong> and click <strong>Properties</strong>.<o:p></o:p></span></li> <li class="MsoNormal" style="margin: 0in 0in 10pt;"><span style="font-size: small; font-family: calibri;">In the <strong>RDP-Tcp Properties</strong> dialog box, on the <strong>General</strong> tab, click the <strong>Select</strong> button. In the <strong>Windows Security</strong> dialog box, click <strong>APP1.corp.contoso.com</strong> and click <strong>OK</strong>. In the <strong>RDP-Tcp Properties</strong> dialog box, click <strong>OK</strong>. <o:p></o:p></span></li> <li class="MsoNormal" style="margin: 0in 0in 10pt;"><span style="font-size: small; font-family: calibri;">Close the <strong>Remote Desktop Session Host Configuration </strong>console. <o:p></o:p></span></li> </ol> <h2 style="margin: 10pt 0in 0pt;"><a name="STEP_3_Generate_the_RemoteApp_Configuration_File_on_APP1"></a><a name="_Toc277586247"></a><a name="_Toc265500030"><span style="font-family: cambria; font-size: medium; color: #4f81bd;">STEP 3: </span></a><span style="font-size: medium; color: #4f81bd; font-family: cambria;"><span>Generate the RemoteApp Configuration File on APP1</span><o:p></o:p></span></h2> <p class="MsoNormal" style="margin: 0in 0in 10pt;"><span style="font-size: small; font-family: calibri;">You will publish a RemoteApp on UAG1. In order to publish the RemoteApp, you need to generate a RemoteApp configuration file on APP1. In this step you will generate the RemoteApp configuration file and copy it to UAG1. <o:p></o:p></span></p> <ol style="margin-top: 0in; list-style-type: decimal;"> <li class="MsoNormal" style="margin: 0in 0in 10pt;"><span style="font-size: small; font-family: calibri;">Click <strong>Start</strong> and point to <strong>Administrative Tools</strong>. Point to <strong>Remote Desktop Services</strong> and click <strong>RemoteApp Manager</strong>. <o:p></o:p></span></li> <li class="MsoNormal" style="margin: 0in 0in 10pt;"><span style="font-size: small; font-family: calibri;">In the <strong>RemoteApp Manager</strong> console, in the <strong>Actions</strong> pane, click <strong>Add RemoteApp Program</strong>. <o:p></o:p></span></li> <li class="MsoNormal" style="margin: 0in 0in 10pt;"><span style="font-size: small; font-family: calibri;">On the <strong>Welcome to the RemoteApp Wizard</strong> page, click <strong>Next</strong>.<o:p></o:p></span></li> <li class="MsoNormal" style="margin: 0in 0in 10pt;"><span style="font-size: small; font-family: calibri;">On the <strong>Choose programs to add to the RemoteApp Programs list</strong> page, select <strong>WordPad</strong> and click <strong>Next</strong>.<o:p></o:p></span></li> <li class="MsoNormal" style="margin: 0in 0in 10pt;"><span style="font-size: small; font-family: calibri;">On the <strong>Review Settings</strong> page, click <strong>Finish</strong>. <o:p></o:p></span></li> <li class="MsoNormal" style="margin: 0in 0in 10pt;"><span style="font-size: small; font-family: calibri;">In the <strong>Actions</strong> pane, click <strong>Export RemoteApp Settings</strong>.<o:p></o:p></span></li> <li class="MsoNormal" style="margin: 0in 0in 10pt;"><span style="font-size: small; font-family: calibri;">In the <strong>Export RemoteApp Settings </strong>dialog box, select <strong>Export the RemoteApp Programs list and settings to a file</strong> and click <strong>OK</strong>. <o:p></o:p></span></li> <li class="MsoNormal" style="margin: 0in 0in 10pt;"><span style="font-size: small; font-family: calibri;">In the <strong>Save As</strong> dialog box, in the <strong>File name</strong> text box, enter <strong>WordPadRemoteApp</strong> and save the file to the <strong>C:\Files</strong> folder. <span> </span>In the <strong>RemoteApp Manager</strong> dialog box click <strong>OK</strong>. Close the <strong>RemoteApp Manager</strong> console. <o:p></o:p></span></li> <li class="MsoNormal" style="margin: 0in 0in 10pt;"><span style="font-family: calibri; font-size: small;">*Log on to the UAG1 computer or virtual machine as CORP\User1. Click <strong>Start</strong> and in the Search box enter </span><a href="file://app1/Files"><strong><span style="line-height: 115%; font-size: 10pt; font-family: calibri; color: #0000ff;">\\APP1\Files</span></strong></a><span style="font-size: small; font-family: calibri;"> and press ENTER. Copy the <strong>WordPadRemoteApp.tspub</strong> file to the desktop on UAG1. Close the Windows Explorer window.<o:p></o:p></span></li> </ol> <h2 style="margin: 10pt 0in 0pt;"><a name="STEP_4_Publish_Remote_Desktops_on_UAG1"></a><a name="_Toc277586248"></a><a name="_Toc265500033"><span style="font-family: cambria; font-size: medium; color: #4f81bd;">STEP 4: </span></a><span style="font-size: medium; color: #4f81bd; font-family: cambria;"><span>Publish Remote Desktops on UAG1</span><o:p></o:p></span></h2> <p class="MsoNormal" style="margin: 0in 0in 10pt;"><span style="font-size: small; font-family: calibri;">To publish Remote Desktops you need to add the Remote Desktops Application to the portal. In this step you will add the Remote Desktop application to the UAG1 portal page.<o:p></o:p></span></p> <ol style="margin-top: 0in; list-style-type: decimal;"> <li class="MsoNormal" style="margin: 0in 0in 10pt;"><span style="font-size: small; font-family: calibri;">At the UAG1 computer or virtual machine, click <strong>Start</strong> and then click <strong>All Programs</strong>. Click <strong>Microsoft Forefront UAG</strong> and then click <strong>Forefront UAG Management</strong>. In the <strong>User Account Control</strong> dialog box, click <strong>Yes</strong>. <o:p></o:p></span></li> <li class="MsoNormal" style="margin: 0in 0in 10pt;"><span style="font-size: small; font-family: calibri;">In the left pane of the <strong>Microsoft forefront Unified Access Gateway Management</strong> console, expand <strong>HTTPS Connections</strong> and click on <strong>HTTPSTrunk</strong>. In the right pane of the console, in the <strong>Applications</strong> section, click <strong>Add</strong>. <o:p></o:p></span></li> <li class="MsoNormal" style="margin: 0in 0in 10pt;"><span style="font-size: small; font-family: calibri;">On the <strong>Welcome to the Add Application Wizard</strong> page, click <strong>Next</strong>.<o:p></o:p></span></li> <li class="MsoNormal" style="margin: 0in 0in 10pt;"><span style="font-size: small; font-family: calibri;">On the <strong>Step 1 – Select Application</strong> page, select the <strong>Terminal Services (TS)/Remote Desktop Services (RDS)</strong> option. From the drop down box, select <strong>Remote Desktop (Predefined)</strong>. Click <strong>Next</strong>. <o:p></o:p></span></li> <li class="MsoNormal" style="margin: 0in 0in 10pt;"><span style="font-size: small; font-family: calibri;">On the <strong>Step 2 – Configuration Application </strong>page, in the <strong>Application name</strong> text box, enter <strong>Predefined Remote Desktop</strong>. Click <strong>Next</strong>. <o:p></o:p></span></li> <li class="MsoNormal" style="margin: 0in 0in 10pt;"><span style="font-size: small; font-family: calibri;">On the <strong>Step 3 – Select Endpoint Policies</strong> page, from the <strong>Access policy</strong> drop down list, select <strong>Always</strong>. We select <strong>Always</strong> in this lab because the default policy requires that the client system have antivirus software installed in order to launch the application. CLIENT1 does not have antivirus software installed, so we need to select the Always option for the Test lab. Click <strong>Next</strong>. <o:p></o:p></span></li> <li class="MsoNormal" style="margin: 0in 0in 10pt;"><span style="font-size: small; font-family: calibri;">On the <strong>Step 4 – Configure Server Settings</strong> page, in the <strong>UAG SP1 RC Session Host (IP address or FQDN)</strong> text box, enter <strong>app1.corp.contoso.com</strong>. Click <strong>Next</strong>. <o:p></o:p></span></li> <li class="MsoNormal" style="margin: 0in 0in 10pt;"><span style="font-size: small; font-family: calibri;">On the <strong>Step 5 – Configure Client Settings</strong> page, accept the default settings and click <strong>Next</strong>.<o:p></o:p></span></li> <li class="MsoNormal" style="margin: 0in 0in 10pt;"><span style="font-size: small; font-family: calibri;">On the <strong>Step 6 – Portal Link</strong> page, accept the default settings and click <strong>Next</strong>.<o:p></o:p></span></li> <li class="MsoNormal" style="margin: 0in 0in 10pt;"><span style="font-size: small; font-family: calibri;">On the <strong>Step 7 – Authorization</strong> page, accept the default settings and click <strong>Next</strong>. <o:p></o:p></span></li> <li class="MsoNormal" style="margin: 0in 0in 10pt;"><span style="font-size: small; font-family: calibri;">On the <strong>Completing the Add Application Wizard </strong>page, click <strong>Finish</strong>. <o:p></o:p></span></li> </ol> <h2 style="margin: 10pt 0in 0pt;"><a name="STEP_5_Publish_RemoteApps_on_UAG1"></a><a name="_Toc277586249"></a><a name="_Toc265500035"><span style="font-family: cambria; font-size: medium; color: #4f81bd;">STEP 5: </span></a><span style="font-size: medium; color: #4f81bd; font-family: cambria;"><span>Publish RemoteApps on UAG1</span><o:p></o:p></span></h2> <p class="MsoNormal" style="margin: 0in 0in 10pt;"><span style="font-size: small; font-family: calibri;">To publish RemoteApps you need to add the RemoteApps application to the portal. In this step you will add the RemoteApps application to the portal page.<o:p></o:p></span></p> <ol style="margin-top: 0in; list-style-type: decimal;"> <li class="MsoNormal" style="margin: 0in 0in 10pt;"><span style="font-size: small; font-family: calibri;">In the right pane of the <strong>Microsoft Forefront Unified Access Gateway Management</strong> console, in the <strong>Applications</strong> section, click the <strong>Add</strong> button.<o:p></o:p></span></li> <li class="MsoNormal" style="margin: 0in 0in 10pt;"><span style="font-size: small; font-family: calibri;">On the <strong>Welcome to the Add Application Wizard</strong> page, click <strong>Next</strong>.<o:p></o:p></span></li> <li class="MsoNormal" style="margin: 0in 0in 10pt;"><span style="font-size: small; font-family: calibri;">On the <strong>Step 1 – Select Application</strong> page, select the <strong>Terminal Services (TS)/Remote Desktop Services (RDS)</strong> option. From the drop down box, select <strong>RemoteApp</strong>. Click <strong>Next</strong>.<o:p></o:p></span></li> <li class="MsoNormal" style="margin: 0in 0in 10pt;"><span style="font-size: small; font-family: calibri;">On the <strong>Step 2 – Configuration Application</strong> page, in the <strong>Application name</strong> text box, enter <strong>Remote WordPad</strong>. Click <strong>Next</strong>.<o:p></o:p></span></li> <li class="MsoNormal" style="margin: 0in 0in 10pt;"><span style="font-size: small; font-family: calibri;">On the <strong>Step 3 – Select Endpoint Policies </strong>page, from the <strong>Access policy</strong> drop down box, select <strong>Always</strong>. Click <strong>Next</strong>.<o:p></o:p></span></li> <li class="MsoNormal" style="margin: 0in 0in 10pt;"><span style="font-size: small; font-family: calibri;">On the <strong>Step 4 – Import RemoteApp Programs</strong> page, click the <strong>Browse</strong> button. Navigate to the Desktop and open the <strong>WordPadRemoteApp.tspub</strong> file. In the <strong>UAG SP1 RC Session Host (IP address or FQDN)</strong> text box, confirm that it says <strong>APP1.corp.contoso.com</strong>. Click <strong>Next</strong>.<o:p></o:p></span></li> <li class="MsoNormal" style="margin: 0in 0in 10pt;"><span style="font-family: calibri; font-size: small;">On the <strong>Step 5 – Select Publishing Type</strong> page, in the <strong>Available RemoteApps</strong> section, select </span><strong><br /> <span style="font-family: calibri; font-size: small;">WordPad</span></strong><span style="font-size: small; font-family: calibri;"> and click the right-pointing double-arrow. This moves the <strong>WordPad</strong> application to the <strong>Published RemoteApps</strong> section. Click <strong>Next</strong>.<o:p></o:p></span></li> <li class="MsoNormal" style="margin: 0in 0in 10pt;"><span style="font-size: small; font-family: calibri;">On the <strong>Step – 6 Configure Client Settings</strong> page, accept the default settings and click <strong>Next</strong>.<o:p></o:p></span></li> <li class="MsoNormal" style="margin: 0in 0in 10pt;"><span style="font-size: small; font-family: calibri;">On the <strong>Step – 7 Portal Link</strong> page, accept the default settings and click <strong>Next</strong>.<o:p></o:p></span></li> <li class="MsoNormal" style="margin: 0in 0in 10pt;"><span style="font-size: small; font-family: calibri;">On the <strong>Step 8 – Authorization</strong> page, accept the default settings and click <strong>Next</strong>.<o:p></o:p></span></li> <li class="MsoNormal" style="margin: 0in 0in 10pt;"><span style="font-size: small; font-family: calibri;">On the <strong>Completing the Add Application Wizard</strong> page, click <strong>Finish</strong>.<o:p></o:p></span></li> <li class="MsoNormal" style="margin: 0in 0in 10pt;"><span style="font-size: small; font-family: calibri;">Click the <strong>File </strong>menu and click <strong>Activate</strong>.<o:p></o:p></span></li> <li class="MsoNormal" style="margin: 0in 0in 10pt;"><span style="font-size: small; font-family: calibri;">On the <strong>Activate Configuration</strong> page, click the <strong>Activate </strong>button.<o:p></o:p></span></li> <li class="MsoNormal" style="margin: 0in 0in 10pt;"><span style="font-size: small; font-family: calibri;">Click <strong>Finish</strong> on the <strong>Activation completed successfully </strong>page.<o:p></o:p></span></li> </ol> <h2 style="margin: 10pt 0in 0pt;"><a name="STEP_6_Test_DirectAccess_SSTP_and_Remote_Desktop_Connectivity_from_CLIENT1"></a><a name="_Toc277586250"><span style="font-family: cambria; font-size: medium; color: #4f81bd;">STEP 6: Test DirectAccess, SSTP and Remote Desktop Connectivity from CLIENT1</span></a><o:p></o:p></h2> <p class="MsoNormal" style="margin: 0in 0in 10pt;"><span style="font-size: small; font-family: calibri;">After the portal configuration is completed, you can test connectivity to resources through the UAG portal. In this step you will confirm DirectAccess and SSTP connectivity, and then test Remote Desktop and RemoteApp connectivity through the portal<span>.<o:p></o:p></span></span></p> <p class="MsoNormal" style="margin: 0in 0in 10pt;"><strong><span style="font-size: small; font-family: calibri;">Confirm DirectAccess Connectivity to the Corpnet subnet:<o:p></o:p></span></strong></p> <ol style="margin-top: 0in; list-style-type: decimal;"> <li class="MsoNormal" style="margin: 0in 0in 10pt;"><span style="font-size: small; font-family: calibri;">*Move the CLIENT1 computer or virtual machine to the Homenet subnet. Log on to CLIENT1 as CORP\User1. <o:p></o:p></span></li> <li class="MsoNormal" style="margin: 0in 0in 10pt;"><span style="font-size: small; font-family: calibri;">Open an elevated command prompt. In the command prompt window, enter <strong>ping dc1</strong> and press ENTER. You should see four responses from DC1. This indicates that the IPv6 transition technology that connects CLIENT1 to UAG1 is working correctly.<o:p></o:p></span></li> <li class="MsoNormal" style="margin: 0in 0in 10pt;"><span style="font-size: small; font-family: calibri;">In the command prompt window, enter <strong>net view </strong></span><a href="file://dc1/"><strong><span style="line-height: 115%; font-size: 10pt; font-family: calibri; color: #0000ff;">\\dc1</span></strong></a><span style="font-size: small; font-family: calibri;"> and press ENTER. You should see a list of shares on DC1. This indicates that the infrastructure tunnel is working correctly.<o:p></o:p></span></li> <li class="MsoNormal" style="margin: 0in 0in 10pt;"><span style="font-size: small; font-family: calibri;">In the command prompt window, enter <strong>net view </strong></span><a href="file://app1/"><strong><span style="line-height: 115%; font-size: 10pt; font-family: calibri; color: #0000ff;">\\app1</span></strong></a><span style="font-size: small; font-family: calibri;"> and press ENTER. You should see a list of shares on APP1. This indicates that the intranet tunnel is working correctly.<o:p></o:p></span></li> <li class="MsoNormal" style="margin: 0in 0in 10pt;"><span style="font-size: small; font-family: calibri;">You have demonstrated that DirectAccess connectivity is successful over both the intranet and infrastructure tunnels. Close the command prompt window.<o:p></o:p></span></li> </ol> <p class="MsoNormal" style="margin: 0in 0in 10pt;"><strong><span style="font-size: small; font-family: calibri;">Confirm SSTP Connectivity to the Corpnet subnet:<o:p></o:p></span></strong></p> <ol style="margin-top: 0in; list-style-type: decimal;"> <li class="MsoNormal" style="margin: 0in 0in 10pt;"><span style="font-family: calibri; font-size: small;">On the CLIENT1 computer or virtual machine, open Internet Explorer. In Internet Explorer, in the address bar, enter </span><a href="https://uag1.contoso.com/"><strong><span style="line-height: 115%; font-size: 10pt; font-family: calibri; color: #0000ff;">https://uag1.contoso.com</span></strong></a><span style="font-size: small; font-family: calibri;"> and press ENTER. Click the information bar that informs you that the <strong>Website wants to run the following add-on: Microsoft Remote Desktop Services Web Access Con…” from “Microsoft Corporation:… </strong>click <strong>Run Add-on</strong>. In the <strong>Internet Explorer – Security Warning</strong> dialog box that asks <strong>Do you want to run this ActiveX control?</strong> click <strong>Run</strong>. <span> </span><o:p></o:p></span></li> <li class="MsoNormal" style="margin: 0in 0in 10pt;"><span style="font-size: small; font-family: calibri;">Enter the username and password for CORP\User1 in the <strong>Application and Network Access Portal</strong> page. If the page times out and you see a message that says <strong>The logon process cannot be completed. User credentials were not submitted within the time limit</strong>, click the <strong>Back</strong> link and log on as CORP\User1.<o:p></o:p></span></li> <li class="MsoNormal" style="margin: 0in 0in 10pt;"><span style="font-size: small; font-family: calibri;">In the right pane of the portal page, click <strong>SSTP VPN</strong>. After you see the balloon in the system notification area that says that network connectivity is started, open an elevated command prompt.<o:p></o:p></span></li> <li class="MsoNormal" style="margin: 0in 0in 10pt;"><span style="font-size: small; font-family: calibri;">In the command prompt window, enter <strong>ping APP3</strong> and press ENTER. You should see four responses from the IPv4 address of APP3. This indicates that DirectAccess has been disabled and the IPv4 SSTP connection to the Corpnet subnet is active. Close the elevated command prompt window.<o:p></o:p></span></li> <li class="MsoNormal" style="margin: 0in 0in 10pt;"><span style="font-size: small; font-family: calibri;">Right click the <strong>Remote Network Access</strong> icon in the system notification area and click <strong>Disconnect remote Network Access</strong> command. You will see a balloon in the system notification area that says that the connection is ended. <o:p></o:p></span></li> </ol> <p class="MsoNormal" style="margin: 0in 0in 10pt;"><strong><span style="font-size: small; font-family: calibri;">Confirm Remote Desktop Connectivity to the Corpnet subnet:<o:p></o:p></span></strong></p> <ol style="margin-top: 0in; list-style-type: decimal;"> <li class="MsoNormal" style="margin: 0in 0in 10pt;"><span style="font-size: small; font-family: calibri;">In the right pane of the portal page, click the <strong>Predefined Remote Desktop </strong>link. If the <strong>Message from webpage</strong> dialog box appears, click <strong>OK</strong>. If the Information bar appears saying that the website wants to run <strong>Remote Desktop Services ActiveX Client</strong>, click the information bar and click <strong>Run Add-on</strong>. In the <strong>Internet Explorer – Security Warning</strong> dialog box, click <strong>Run</strong>. <span> </span><o:p></o:p></span></li> <li class="MsoNormal" style="margin: 0in 0in 10pt;"><span style="font-size: small; font-family: calibri;">Click the <strong>Predefined Remote Desktop</strong> link in the right pane of the portal page. In the <strong>Remote Desktop Connection</strong> dialog box, click <strong>Connect</strong>. In the <strong>Windows Security </strong>dialog box, enter credentials for CORP\User1. .<o:p></o:p></span></li> <li class="MsoNormal" style="margin: 0in 0in 10pt;"><span style="font-size: small; font-family: calibri;">The Desktop now appears in the RDC client window. Close the RDC window. In the <strong>Remote Desktop Connection</strong> dialog box, click <strong>OK</strong>. <o:p></o:p></span></li> </ol> <p class="MsoNormal" style="margin: 0in 0in 10pt;"><strong><span style="font-size: small; font-family: calibri;">Confirm RemoteApp Connectivity to the Corpnet subnet:<o:p></o:p></span></strong></p> <ol style="margin-top: 0in; list-style-type: decimal;"> <li class="MsoNormal" style="margin: 0in 0in 10pt;"><span style="font-size: small; font-family: calibri;">In the right pane of the portal, click the <strong>WordPad</strong> link. <o:p></o:p></span></li> <li class="MsoNormal" style="margin: 0in 0in 10pt;"><span style="font-size: small; font-family: calibri;">In the <strong>RemoteApp</strong> dialog box, click <strong>Connect</strong>.<o:p></o:p></span></li> <li class="MsoNormal" style="margin: 0in 0in 10pt;"><span style="font-size: small; font-family: calibri;">In the <strong>Document – WordPad</strong> window, enter <strong>This is a RemoteApp document</strong>. Click the <strong>Save</strong> icon in the Title Bar, and save the document to the desktop with the name <strong>My RemoteApp Doc. </strong>Close the <strong>WordPad</strong> window.<o:p></o:p></span></li> <li class="MsoNormal" style="margin: 0in 0in 10pt;"><span style="font-size: small; font-family: calibri;">Click the <strong>Log Off</strong> button in the upper right corner of the portal page. Close Internet Explorer.<o:p></o:p></span></li> </ol> <h2 style="margin: 10pt 0in 0pt;"><a name="STEP_7_Snapshot_the_Configuration"></a><a name="_Toc277586251"></a><a name="_Toc268018645"><span style="font-family: cambria; font-size: medium; color: #4f81bd;">STEP 7: Snapshot the Configuration</span></a><o:p></o:p></h2> <p class="MsoNormal" style="margin: 0in 0in 10pt;"><span style="font-size: small; font-family: calibri;">This completes the UAG SP1 RC DirectAccess with SSTP and Remote Desktop Gateway test lab. To save this configuration so that you can quickly return to a working UAG SP1 RC DirectAccess with SSTP and Remote Desktop Gateway configuration from which you can test other DirectAccess modular TLGs, TLG extensions, or for your own experimentation and learning, do the following:<span><o:p></o:p></span></span></p> <ol style="margin-top: 0in; list-style-type: decimal;"> <li class="MsoNormal" style="margin: 0in 0in 10pt;"><span style="font-size: small; font-family: calibri;">On all physical computers or virtual machines in the test lab, close all windows and then perform a graceful shutdown. <o:p></o:p></span></li> <li class="MsoNormal" style="margin: 0in 0in 10pt;"><span style="font-size: small; font-family: calibri;">If your lab is based on virtual machines, save a snapshot of each virtual machine and name the snapshots <strong>TLG UAG DirectAccess SP1RC SSTP+RDG</strong>. If your lab uses physical computers, create disk images to save the DirectAccess test lab configuration.<o:p></o:p></span></li> </ol> <h1 style="margin: 24pt 0in 0pt;"><a name="Additional_Resources"></a><a name="_Toc277586252"></a><a name="_Toc267913054"></a><a name="_Toc267556283"><span style="font-family: cambria; color: #365f91;">Additional Resources</span></a><o:p></o:p></h1> <p class="MsoNormal" style="margin: 0in 0in 10pt;"><span style="font-family: calibri; font-size: small;">For more information on UAG and SSTP, see </span><a href="http://technet.microsoft.com/en-us/library/dd861404.aspx"><span style="line-height: 115%; font-size: 10pt; font-family: calibri; color: #0000ff;">Setting up Remote Network Access</span></a><span style="font-size: small; font-family: calibri;">.<o:p></o:p></span></p> <p class="MsoNormal" style="margin: 0in 0in 10pt;"><span style="font-family: calibri; font-size: small;">For more information on UAG and Remote Desktop Gateway, see </span><a href="http://technet.microsoft.com/en-us/library/dd861391.aspx"><span style="line-height: 115%; font-size: 10pt; font-family: calibri;">Remote Desktop Services publishing solution guide</span></a><span style="font-size: small; font-family: calibri;">.<o:p></o:p></span></p> <p class="MsoNormal" style="margin: 0in 0in 10pt;"><span style="font-family: calibri; font-size: small;">For procedures to configure the Base Configuration test lab on which this document is based, see the </span><a href="http://go.microsoft.com/fwlink/?LinkId=198140"><span style="line-height: 115%; font-family: calibri; font-size: small; color: #0000ff;">Test Lab Guide: Base Configuration</span></a><span style="font-size: small; font-family: calibri;">.<o:p></o:p></span></p> <p class="MsoNormal" style="margin: 0in 0in 10pt;"><span style="font-family: calibri; font-size: small;">For procedures to configure UAG SP1 RC DirectAccess on which this document is based, see the </span><a href="http://go.microsoft.com/fwlink/?LinkId=204993"><span style="line-height: 115%; font-size: 10pt; font-family: calibri;">Test Lab Guide: Demonstrate Forefront UAG SP1 RC DirectAccess</span></a><span style="font-size: small; font-family: calibri;">.<o:p></o:p></span></p> <p class="MsoNormal" style="margin: 0in 0in 10pt;"><span style="font-family: calibri; font-size: small;">For procedures to configure UAG SP1 RC DirectAccess on which this document is based, see </span><a href="http://www.microsoft.com/downloads/en/details.aspx?FamilyID=ff377cea-2f37-471f-b3e8-2993bc1744ac"><span lang="EN" style="line-height: 115%; font-size: 10pt; font-family: calibri;">Test Lab Guide: Demonstrate Forefront UAG SP1 RC DirectAccess with Secure Socket Tunneling Protocol (SSTP)</span></a><span style="font-size: small; font-family: calibri;"><span lang="EN"> </span><span lang="EN"> </span><o:p></o:p></span></p> <p class="MsoNormal" style="margin: 0in 0in 10pt;"><span style="font-family: calibri; font-size: small;">For a comprehensive list of Test Lab Guides, please see </span><a href="http://social.technet.microsoft.com/wiki/contents/articles/test-lab-guides.aspx"><span style="line-height: 115%; font-size: 10pt; font-family: calibri;">Test Lab Guides</span></a><span style="font-size: small; font-family: calibri;">.<o:p></o:p></span></p> <p class="MsoNormal" style="margin: 0in 0in 10pt;"><span style="font-family: calibri; font-size: small;">For a list of UAG DirectAccess related Test Lab Guides, please see </span><a href="http://social.technet.microsoft.com/wiki/contents/articles/uag-directaccess-test-lab-guide-portal-page.aspx"><span style="line-height: 115%; font-size: 10pt; font-family: calibri;">UAG DirectAccess Test Lab Guide Portal Page</span></a><o:p></o:p></p> <p class="MsoNormal" style="margin: 0in 0in 10pt;"><span style="font-family: calibri; font-size: small;">For the design and configuration of your pilot or production deployment of DirectAccess, see the </span><a href="http://technet.microsoft.com/en-us/library/ee406191.aspx"><span style="line-height: 115%; font-family: calibri; font-size: small; color: #0000ff;">Forefront UAG DirectAccess design guide</span></a><span style="font-family: calibri; font-size: small;"> and the </span><a href="http://technet.microsoft.com/en-us/library/dd857320.aspx"><span style="line-height: 115%; font-family: calibri; font-size: small; color: #0000ff;">Forefront UAG DirectAccess deployment guide</span></a><span style="font-size: small; font-family: calibri;">. <strong><o:p></o:p></strong></span></p> <p class="MsoNormal" style="margin: 0in 0in 10pt;"><span style="font-family: calibri; font-size: small;">For information about troubleshooting DirectAccess, see the </span><a href="http://go.microsoft.com/fwlink/?LinkId=165904"><span style="line-height: 115%; font-family: calibri; font-size: small; color: #0000ff;">DirectAccess Troubleshooting Guide</span></a><span style="font-size: small; font-family: calibri;">.<o:p></o:p></span></p> <p class="MsoNormal" style="margin: 0in 0in 10pt;"><span style="font-family: calibri; font-size: small;">For information on troubleshooting UAG DirectAccess in a Test Lab, see </span><a href="http://www.microsoft.com/downloads/en/details.aspx?displaylang=en&FamilyID=d2e460c8-b4bf-4fda-9f86-ecc4b7add5d1"><span style="line-height: 115%; font-size: 10pt; font-family: calibri; color: #0000ff;">Test Lab Guide: Troubleshooting UAG DirectAccess</span></a><span style="font-size: small; font-family: calibri;">.<strong> <o:p></o:p></strong></span></p> <p class="MsoNormal" style="margin: 0in 0in 10pt;"><span style="font-family: calibri; font-size: small;">For more information about DirectAccess, see the </span><a href="http://www.microsoft.com/servers/directaccess.mspx"><span style="line-height: 115%; font-family: calibri; font-size: small; color: #0000ff;">DirectAccess Getting Started Web page</span></a><span style="font-family: calibri; font-size: small;"> and the </span><a href="http://technet.microsoft.com/en-us/network/dd420463.aspx"><span style="line-height: 115%; font-family: calibri; font-size: small;">DirectAccess TechNet Web page</span></a><span style="font-size: small; font-family: calibri;">.</span></p> <p> </p> <p>========================================================</p> <p><strong>Tom Shinder <br /> </strong><a href="mailto:tomsh@microsoft.com"><strong>tomsh@microsoft.com</strong></a><strong> <br /> Knowledge Engineer, Microsoft DAIP iX/Forefront iX <br /> UAG Direct Access/Anywhere Access Group (AAG) <br /> The “Edge Man” blog (DA all the time): </strong><a href="http://blogs.technet.com/tomshinder/default.aspx"><strong>http://blogs.technet.com/tomshinder/default.aspx</strong></a><strong> <br /> Follow me on Twitter: </strong><a href="http://twitter.com/tshinder"><strong>http://twitter.com/tshinder</strong></a><strong> <br /> Facebook: </strong><a href="http://www.facebook.com/tshinder"><strong>http://www.facebook.com/tshinder</strong></a></p>
Comment
Tags
Please add 2 and 4 and type the answer here: