Device LinkUP + Desktop LP Guide RDP Version 2.1 January 2016
Copyright 2015 iwebgate. All Rights Reserved. No part of this publication may be reproduced, transmitted, transcribed, stored in a retrieval system, or translated into any language in any form or by any means without the written permission of iwebgate as provided by the explicit terms and conditions of our license agreement. Basic Rights of Use Thank you for choosing iwebgate. Registration of your product is required during the installation process outlined in this document. Registration of a single product entitles you to begin using the product for the specific purposes of the product. Additional licensing might be required to use additional features. For more information about iwebgate, visit us at http://www.iwebgate.com. Trademarks Microsoft, Windows, Windows NT, and Vista are registered trademarks of Microsoft Corporation. Other brand and product names are registered trademarks or trademarks of their respective holders. Statement of Conditions To ensure proper operational function and/or reliability of the product is maintained, iwebgate reserves the right to make changes to the product described within this document, via electronic means or otherwise, without notice. iwebgate does not assume any liability that may occur due to the use, or application of, the product described herein.
Table of Contents Introduction 4 1. Create a Network LinkUp 5 2. Create User for Device LinkUp 7 3. Add a Remote Connection 9 4. Enable Remote Desktop Service on Remote PC 11 4.1 Adjust Firewall Settings 15 4.2 Disable Sleep Mode 16 4.3 Remove Visual Effects 17 5. Connect Remote PC to Network LinkUp 18 5.5 Additional Setup 22 6. Download VIN Configurations 24 7. Log into Device LinkUp 29 8. Add a Remote Desktop Connection in Desktop LP 33
Introduction This guide will show how to set up a Remote Desktop Protocol (RDP) in Desktop LP through the Virtual Segmentation Platform (VSP) to be used in the mobility container, Device LinkUp. The steps for establishing RDP connection are: 1. Create a Network LinkUp 2. Create a User for Device LinkUp 3. Add a Remote Connection 4. Enable Remote Desktop Service on Remote PC 5. Connect Remote PC to Network LinkUp 6. Log into Device LinkUp 7. Add a Remote Desktop Connection in Desktop LP Requirements: Device LinkUp installed on a mobile device VIN Service www.iwebgate.com/product/downloads.html A desktop computer running Windows Professional version and capable of remote connections Administrator login credentials to the Virtual Segmentation Platform (VSP) 4
1. Create a Network LinkUp Log into the Virtual Segmentation Platform (VSP) with your administrator credentials. Click Network LinkUp on the Administration menu of the Virtual Segmentation Platform (VSP). Click Add LinkUp. 5
Name the new linkup, and choose a network subnet number (any free string of numbers). Make sure to click Save. The VSP automatically creates two nodes. To change the node s name, delete it from the list by clicking the trashcan icon before clicking Add. 6
Rename the node and click Save. Make sure to make each node Persistent. 2. Create User for Device LinkUp While logged into the VSP, click User Manager on the Administration menu. Add users to the VSP by clicking the new user icon. 7
1 2 3 4 1. Choose a username for the account. 2. Type the user s full name. 3. Provide the user s email address. This will be used for Device LinkUp s multifactor login. 4. Provide the user s email address and phone number. 8
3. Add a Remote Connection While logged into the VSP, click Desktop LP on the sidebar. Click Add Host Computer. 9
Name the new connection and choose RDP from the drop-down list. Click General to provide the name and IP information including the port and domain name for the new connection. Click Access to find the user created for Device LinkUp in Step 2. Click the user to select it. 10
Make sure to click Save. 4. Enable Remote Desktop Service on Remote PC Open Allow remote access to your computer. 11
In System Properties Remote tab, check Allow remote connections to this computer and Allow connections only from computers running Remote Desktop with Network Level Authentication (recommended). Click Select Users. 12
To add a RDP authenticated Windows user, click Add. This user may already have access granted. Type in the username before clicking Check Names. 13
Click Check Names, and click OK: The user will now be listed in the box. Click OK. 14
Save the new System Properties settings by clicking OK. 4.1 Adjust Firewall Settings On the Windows machine receiving the RDP connection, go to Windows Firewall settings in Control Panel and click Allow an app or feature through Windows Firewall. 15
Select Public for Remote Desktop. Make sure to secure the firewall again after the connection is made. 4.2 Disable Sleep Mode If the target machine goes into sleep mode, it will disconnect from the VPN. If the machine to which you are connecting with Remote Desktop is a Windows machine, navigate to Power Options in Control Panel before clicking Change powersaving settings. 16
Click Change when the computer sleeps. In the Put the computer to sleep dropdown, select Never. 4.3 Remove Visual Effects It is recommended to remove visual effects on the remote Windows to improve user experience. Using the search function or Control Panel, navigate to Adjust the appearance and performance of Windows. 17
In the Visual Effects tab, choose Adjust for best performance. 5. Connect Remote PC to Network LinkUp Choose the appropriate installer either for 64-bit Windows or 32-bit Windows from www.iwebgate.com 18
When starting the installer package, right click and choose Run as Administrator. The package may be flagged as a potential risk. Click Run anyway. When the User Account Control warning pops up, click Yes to start the installation package. 19
Click Next to install the VIN on your computer. Click the circle to accept the License Agreement terms before clicking Next. 20
As the package installs, do not close any popups that may appear on your screen. To allow incoming network connections, check Disable firewall on VIN adapters. This will result in a warning from Windows that your firewall has been disabled. However, it will only be disabled on the VIN TAP adapters, not on the real network interface. Alternately, you can leave Disable firewall on VIN adapters unchecked and manually set up the appropriate firewall rules for the VIN TAP adapter. 21
5.5 Additional Setup After installing VIN, your computer s Command Prompt will automatically open showing VIN Service stopping and VIN TAP adapters being created. Wait before continuing. While the VIN TAP adapters are being installed, a popup will appear. Check Always trust software from OpenVPN Technologies, Inc. before clicking Install. 22
After installing the VIN TAP adapters, the command prompt will show the iwebgate VIN Service restarting. A popup may appear alerting that Windows Firewall is off. The firewall has been disabled on all VIN adapters but is still enabled on the actual network interface. Checking the firewall advanced settings will confirm this. However, the firewall status will show the following: 23
6. Download VIN Configurations Log into the VSP using administrator credentials. Navigate to either VPN LP or Network LinkUp depending on which connection the appropriate node is on. Make sure the node is set to Persistent 24
Click the download icon for the appropriate node to retrieve the peer.zip file that contains: ca.pem - the CA certificates file peer.conf - peer configuration for the node vlan.key - encryption key for the VIN The peer files will download into a zip file. Open the zip file. Copy ca.pem, peer.conf and vlan.key to C:\Program Files\iWebGate\VIN\peer. 25
Click Continue when prompted for administrator permissions to copy to the peer folder. Click Copy and Replace to overwrite the existing files. 26
Restart the iwebgate VIN Service (or reboot the machine): The iwebgate VIN Service has a delayed automatic start; it will start and automatically connect to the VIN after a few minutes when the machine is rebooted. 27
When running ipconfig in a command prompt, you should see the IP address for the node bound to a VIN TAP adapter: If connected to a Network Linkup, you can ping the platform address. Otherwise, if connected to a VPN LP, you can ping any other node that is already connected to the VIN (assuming that the firewall rules on the remote host allow ICMP echo requests): 28
7. Log into Device LinkUp Navigate to iwebgate.com and select the appropriate Device LinkUp install package. After downloading Device LinkUp to your device, open the app to show the login screen. 29
Before using login credentials, you must enter the server information by tapping Change Host. Proceed by entering the host address and port number. Change to HTTPs by tapping the green triangle. After adding host details, type the user name and password created for Device LinkUp in the login fields. Select to receive the password through One-Time Password (OTP) or Time-Based One Time Password (TOTP). OTP sends a one-time use password through email or SMS. 30
Before TOTP can be used, Google Autheticator must be first downloaded from the App or Play Store. Google Authethicatior only needs to be downloladed once even if multiple devices are using Device LinkUp. Tap Send Secret Key. 31
Select the key to be sent either via email or SMS (for US numbers only). The login key comes with a QR code and Secret Key comprised of a string of numbers and letters. If the QR code is not visible in the sent email, ensure that images are not blocked. Open the Google Authethicator app and select to either scan the barcode in the email or manually enter the pin. 32
Use the 6-digit code displayed within the 30-second period to login into Device LinkUp via TOTP. When the time is almost up, the code will turn red. This means that the countdown is almost up, and the code will be changing shortly. 8. Add a Remote Desktop Connection in Desktop LP After using either TOTP or OTP to sign into Device LinkUp, tap Desktop Conn on the landing screen. 33
When Desktop LP opens, tap Add New Network. Type the Network Name, Hostname, User Name and Password into the fields and tap Save. 34
After the network is saved into Desktop LP, tap Connect. The saved connection will connect. 35
Desktop LP will connect through Device LinkUp. Tap the blue arrow to continue. The login for the RDP software will open. Use the username and password generated on the connecting machine for the remote user when remote services were enabled.. Tap Login. 36
Version 2.1 January 2016