GTS Software Remote Desktop Services RemoteApp client requirements and hosting environment details CONTENTS Introduction... 2 Client requirements... 2 RD Web Access... 2 Distributed RDP or MSI packages... 2 Windows 7 Start Menu... 3 Printing... 3 Web Single Sign-On (Web SSO)... 3 Hosting and Data Centre Infrastructure... 4 Data Center Specifics... 4 Data Center Power... 4 Physical security for safeguarding your site and data... 4 Environmental control features for maximum reliability... 4 Redundant systems... 4 Industry Standard... 4 Network Connectivity... 5 GTS Remote Desktop Services environment... 5 Data Backup... 5 Remote Applications and data security... 5 GTS Software Pty Ltd ABN 82 809 059 038 PO Box 654 Mt Eliza VIC 3930 Australia Tel: (613) 9708-8988 Fax: (613) 9708-8622 info@gtssoftware.com.au www.gtssoftware.com.au GtsRemoteDesktopServices-ClientRequirements- HostingInfrastrusture-Rev04.doc Rev 04 2012/11/08
Introduction GTS has adopted the latest Microsoft Remote Desktop Services technologies to provide on-line remote access to its CMS and Quest software applications. With Remote Desktop Services (RDS), GTS aims to provide access to its suite of software applications from virtually any location, to any Windows device, from the Internet. Remote Desktop Protocol (RDP) over HTTPS is used to establish a secure, encrypted connection between remote users on the Internet and GTS remote servers running Remote Desktop Services. All connections are established via a RDS gateway which transmits data through a Secure Sockets Layer (SSL) tunnel that enables authorized users to connect from any computer with an Internet connection. This approach provides connections to GTS RDS from within a corporate network via the Internet across firewalls and without having to set up virtual private network (VPN) connections. Programs are accessed remotely but appear as if they are running on the end user s local computer and are integrated with the client's desktop, i.e. own resizable window, can be dragged between multiple monitors, and own entry in the taskbar. These programs are called RemoteApp programs and can be accessed in several ways:- RD Web Access - Access a link to the program through the GTS Remote Desktop Services, Remote Desktop Web Access (RD Web Access) web page. Double-click a Remote Desktop Protocol (.rdp) file that has been created and distributed by GTS. Double-click a program icon on their desktop or Start menu that has been created and distributed by GTS using a Windows Installer (.msi) package. RemoteApp And Desktop Connection by using the Windows 7 Start menu Client requirements In all of the following cases, if the client machine is connected through a firewall, the only requirement is that port 443 outbound (https secure web browser port) needs to be open. The standard Remote Desktop Connection port 3389 is not required as all data is transmitted via the RDS gateway using SSL/TLS. RD Web Access To use RD Web Access, client computers must be running at least Internet Explorer 6.0 and a version of Remote Desktop Connection (RDC) that supports at least Remote Desktop Protocol (RDP) 6.1. RDC 6.1 supports Remote Desktop Protocol 6.1. RDC 6.1 is included with the following operating systems: Windows Server 2008 Windows Vista with Service Pack 1 (SP1) Windows XP with Service Pack 3 (SP3) The version of RDC in Windows 7 and Windows Server 2008 R2 supports RDP 7.0. The version of RDC that the client is using determines which features of RD Web Access are available. Additionally, the Remote Desktop Services ActiveX Client control must be enabled. The ActiveX control is included with RDC 6.1 and the version of RDC in Windows 7 and Windows Server 2008 R2. Distributed RDP or MSI packages To access RemoteApp programs that are deployed as.rdp files or as Windows Installer packages, the client computer must be running at least Remote Desktop Connection (RDC) 6.0 2 of 5
Windows 7 Start Menu RemoteApp and Desktop Connections is a new feature in Windows 7 and Windows Server 2008 R2 that builds on this by bringing RemoteApp programs to the Start menu, giving them the same launch experience as local applications. It works with a new feature of RD Web Access - the RemoteApp and Desktop Connection feed. Instead of presenting RemoteApp programs in the form of a web page, this feed presents them in a software-parsable XML document. With RemoteApp and Desktop Connections, the user subscribes to a feed of RemoteApp programs by supplying the client software with its URL. After the user has subscribed to the feed - that is, created a connection. From then on, the RemoteApp and Desktop Connections client software will make sure that the resources in this connection are placed in the user s Start menu. Printing By default, the Host server first tries to use the Remote Desktop Easy Print driver. To use Remote Desktop Easy Print, the client computer must have the following components installed: 1. Remote Desktop Connection (RDC) 6.1 Note - The RDC 6.1 client supports Remote Desktop Protocol 6.1. 2. At least Microsoft.NET Framework 3.0 Service Pack 1. Even if RDC 6.1 or above is used,.net Framework must be installed separately (included with Windows 7). If the client does not meet the above requirements, the server will need to have a printer driver matching the printer to be used correctly installed and configured. Web Single Sign-On (Web SSO) The Web Single Sign-On (Web SSO) feature provides users with the ability to enter their credentials only once during logon to GTS Remote Desktop Services Web Access (RD Web Access). After logon, users can launch RemoteApp programs that are part of the same connection in RemoteApp and Desktop Connections without any further credential prompts. To take advantage of the new Web SSO feature, the client must be running Remote Desktop Connection (RDC) 7.0. 3 of 5
Hosting and Data Centre Infrastructure All Remote Desktop Services component servers are hosted on VMware ESX & vsphere virtualization platforms and utilise Veeam Replication and Disaster Recovery. VM platform and network hosting is provided by AUSWEB using infrastructure hosted by Equinix in their Data Center located in Alexandria, Sydney. The hosting environment is continuously monitored 24 hours a day, 7 days a week, 365 days a year. Data Center Specifics Data Center Power Operating to an enhanced Tier 3 standard the Equinix data centre has diverse 33 kv feeds feeding a backup power system consisting of 22 diesel rotary UPS systems. Final distribution to customer suites is in a 2(N+1) configuration. The N+1 telecommunication rooms located at each end of the data centre are populated by most of the major Domestic and International Carriers. Equinix Sydney is one of the largest data centres in the Southern Hemisphere with over 34 MW of onsite power generation capacity. This data center features floor to ceiling height of 4.1m and floor-loading capacity of 3,400 Kg/m2 and is conveniently situated on the edge of the CBD but not on the same electricity supply. Should a commercial electrical power failure occur, Equinix provides: 2 x diverse 20 MVA feeds feeding from the National Grid Highly efficient DRUPs installation supported by up to 22 no-break Rotary Diesel UPS sets Diverse A+B+R supply, distributed via 11kV rings within the data centre On-site diesel tanks (6 x 60,000 litres) support 24 hours at full capacity with 24x7 diesel delivery Physical security for safeguarding your site and data Camera systems monitor both interior and exterior facilities around the clock. Access is limited to authorized personnel only, and strictly enforced by electronic access cards, biometric scanning, and security guards. Environmental control features for maximum reliability To reduce downtime, centers feature advanced fire suppression systems, surge suppression, specialized heat and smoke sensors, separate fire zones below the floor and above the ceiling, raised flooring for improved server environment, as well as temperature, humidity, static and airborne particle controls. Redundant systems All infrastructures utilise N+1 redundancy, including Cisco routers, Layer 2 and 3 switches, power system generator in addition to regular grid electrical power, and backbone. Each server is protected by a fire suppression system and multiple air conditioning systems (HVAC: Heating Ventilation Air Conditioning). Multiple iscsi SAN backup servers provide data storage and recovery. Industry Standard Equinix also announced that all three of its Sydney data centres SY1, SY2 and SY3, had successfully passed an external audit for compliance with ISO27001, the highest global standard for information security. This ISO certification provides further assurance that Equinix provides a high level of security, and is a pivotal standard for the support of cloud and financial services providers 4 of 5
Network Connectivity All routes are advertised across multiple upstream bandwidth providers in order to achieve routing redundancy. Network infrastructure is deployed in an N+1 configuration in order to avoid any single point of failure. GTS Remote Desktop Services environment Data Backup All user profiles, application and data files, and SQL databases are periodically backed up using third party and built-in Microsoft Windows and SQL server backup functionality. This creates a further layer of backup redundancy on top of the backup and replication provided by the virtualised hosting environment and removes dependency on hosting provider restorations. Remote Applications and data security All hosted applications are access using RemoteApp. The applications appear as if they are running on the end user s local computer and Remote Desktop access is not provided. The windows file system is locked down based on user group membership and global server settings to ensure only the relevant file system objects are exposed to the user, including file browsing from within the application. User group membership also determines:- User home folder configuration RemoteApps available to the user Database access and role functionality 5 of 5