OIS. Update on Windows 7 at CERN & Remote Desktop Gateway. Operating Systems & Information Services CERN IT-OIS



Similar documents
Installation and Connection Guide to the simulation environment GLOBAL VISION

Global Knowledge MEA Remote Labs. Remote Lab Access Procedure

Terminal Server Software and Hardware Requirements. Terminal Server. Software and Hardware Requirements. Datacolor Match Pigment Datacolor Tools

IN STA LLIN G A VA LA N C HE REMOTE C O N TROL 4. 1

VMware Virtual Desktop Infrastructure (VDI) - The Best Strategy for Managing Desktop Environments Mike Coleman, VMware (mcoleman@vmware.

Dragon Medical Enterprise Network Edition Technical Note: Requirements for DMENE Networks with virtual servers

1 HARDWARE AND SOFTWARE REQUIREMENTS FOR HAL E-BANK SYSTEM

AdminToys Suite. Installation & Setup Guide

Chapter 5: Operating Systems Part 1

LabStats 5 System Requirements

Delphi+ System Requirements

Personal Computer Standard. National Infrastructure Group. National Infrastructure Group, ehealth Leads, ehealth Architecture and Design.

NEWSTAR ENTERPRISE and NEWSTAR Sales System Requirements

Server Installation Procedure - Load Balanced Environment

Sage Grant Management System Requirements

NetLeverage UK ThinPoint Solution Overview Version 2 Copyright 2012 NetLeverage UK

OBSERVEIT DEPLOYMENT SIZING GUIDE

Owner of the content within this article is Written by Marc Grote

Evento Assyrus Microsoft 2009

Remote Desktop Gateway. Accessing a Campus Managed Device (Windows Only) from home.

The Best RDP One-to-many Computing Solution. Start

HSLAB Print Logger 5 Installation Guide

Hardware/Software Guidelines

How To Use Exchange Reporter Plus On A Microsoft Mailbox On A Windows (Windows) On A Server Or Ipa (Windows 7) On An Ubuntu 7.6 (Windows 8) On Your Pc Or

Delphi 2015 SP1-AP1 System Requirements

Remote Application Server Version 14. Last updated:

Determining Your Computer Resources

INUVIKA OPEN VIRTUAL DESKTOP FOUNDATION SERVER

Remote Application Server Version 14. Last updated:

CITRIX 1Y0-A14 EXAM QUESTIONS & ANSWERS

Installing and Configuring Windows Server Module Overview 14/05/2013. Lesson 1: Planning Windows Server 2008 Installation.

Preparing the Windows version of the software for use

Receptionist-Small Business Administrator guide

Installation and Deployment

PC-Duo Web Console Installation Guide

Minimum System Requirements

Release Version 4.1 The 2X Software Server Based Computing Guide

Guide to Installing BBL Crystal MIND on Windows 7

Installation Notes for Outpost Network Security (ONS) version 3.2

Installation Guide For Exchange Reporter Plus

A Comparison of VMware and {Virtual Server}

Applications Life-cycle Management

System Requirements for Microsoft Dynamics NAV 2009

CBE Architectural Overview and System Requirements

Getting Started Guide. Version 4.3

Software Installation Requirements

Requirements Collax Security Gateway Collax Business Server or Collax Platform Server including Collax SSL VPN module

How To Understand The Architecture Of An Ulteo Virtual Desktop Server Farm

SAP Business One Hardware Requirements Guide

Central Management System

1 Introduction to Microsoft Enterprise Desktop Virtualization (MED-V) Terminology Key Capabilities... 4

Designing a Windows Server 2008 Applications Infrastructure

APNT#1209 Using GP-Pro EX in Windows 7 XP Mode. Introduction. Prerequisites. Licensing and availability of XP Mode

Professional and Enterprise Edition. Hardware Requirements

Major upgrade versions. To see which features each version of Windows 7 has, go to Microsoft's Compare Windows page.

4cast Server Specification and Installation

MS-50292: Administering and Maintaining Windows 7. Course Objectives. Required Exam(s) Price. Duration. Methods of Delivery.

Larger, active workgroups (or workgroups with large databases) must use one of the full editions of SQL Server.

Virtual Desktop Infrastructure Planning Overview

Configuring and Troubleshooting Windows Server 2008 Application Infrastructure

Securing Windows Remote Desktop with CopSSH

Installing and Configuring vcenter Multi-Hypervisor Manager

Remote Deposit Capture Installation Guide

Server Software Installation Guide

Media Exchange really puts the power in the hands of our creative users, enabling them to collaborate globally regardless of location and file size.

Figure 1: RotemNet Main Screen

How To Install Sedar On A Workstation

1. Server Microsoft FEP Instalation

Table of Contents Introduction and System Requirements 9 Installing VMware Server 35

How to install EMIS Web on your home computer. Prerequisites

REDCENTRIC INFRASTRUCTURE AS A SERVICE SERVICE DEFINITION

Administering and Maintaining Windows 7 Course 50292C; 5 Days, Instructor-led

Using Speccy to Report on Your Computer Components

Audit4 Installation Requirements

msuite5 & mdesign Installation Prerequisites

Outline SSS Microsoft Windows Server 2008 Hyper-V Virtualization

Release Version 3 The 2X Software Server Based Computing Guide

Windows Server 2008 R2 Remote Desktop Services

Course Outline. ttttttt

Virtualised MikroTik

Brainlab Node TM Technical Specifications

Pearl Echo Installation Checklist

Enterprise Manager. Version 6.2. Installation Guide

e-config Data Migration Guidelines Version 1.1 Author: e-config Team Owner: e-config Team

Delphi System Requirements

Lexia Network Installation Instructions

Enterprise Solution for Remote Desktop Services System Administration Server Management Server Management (Continued)...

inforouter V8.0 Server & Client Requirements

RemoteApp Publishing on AWS

MAPILab Reports for Hardware and Software Inventory Installation Guide. Document version 1.0

JapanCert 専 門 IT 認 証 試 験 問 題 集 提 供 者

Chapter 6 Configuring the SSL VPN Tunnel Client and Port Forwarding

Oracle Insurance General Agent Hardware and Software Requirements. Version 8.0

Managing Ports and System Services using BT NetProtect Plus firewall

Media Server Installation & Administration Guide

Windows 7. Qing Liu Michael Stevens

State of Wisconsin. Virtual Private Network (VPN) Service Offering Definition (SOD)

Gateway Portal Load Balancing

Upgrading Client Security and Policy Manager in 4 easy steps

RightNow November 09 Workstation Specifications

Transcription:

Operating Systems & Information Services Update on Windows 7 at CERN & Remote Desktop Gateway CERN IT-OIS Tim Bell, Michal Kwiatek, Michal Budzowski, Andreas Wagner HEPiX Fall 2010 Workshop 4th November 2010, Cornell University

Outline Update on Windows 7 at CERN NICE Windows 7 since April 2010 Evolution of install base Roadmap for phase-out of Vista, XP, Office 2003 Remote Desktop Gateway In use at CERN since 2009 2

Windows 7 at CERN NICE is the CERN management framework for Windows machines providing software upgrades and inventory. Windows 7 pilot project was started at CERN in December 2009 Official Windows 7 support started on 31st March 2010 NICE Windows 7 training tutorials for users in June 2010 Default OS for new desktop machines: 32-bit version of Windows 7 NICE Windows 7 available on 11 standard laptops and 9 desktops models all HW models for which Vista was previously available (available at CERN from 2006 up to now) Windows 7 available for installation on all hardware (which satisfies min HW reqs) Also support for 64-bit Windows 7 on suitable hardware 3

Hardware requirements For Windows 7 32-bit: Microsoft CERN Recommendations (*) *) Memory 1 GB 2 GB (**) Disk Size 16 GB 60 GB (***) CPU 1 GHz 2 GHz (*) Equal or less than for Vista (**) 1 GB memory is enough if Windows 7 is configured without the AERO user interface (***) 60 GB disk space for typical set of CERN supported applications HEPiX Spring 10

Hardware requirements For Windows 7 64-bit: Microsoft CERN Recommendations Memory 2 GB 4 GB (*) Disk Size 20 GB 60 GB CPU 1 GHz 2 GHz (*) Main motivation of installing a 64-bit OS is to support higher memory configurations HEPiX Spring 10

Windows 7 at CERN Active Windows Desktop Population at CERN: 2007-2010 7000 6000 5000 4000 3000 Windows XP Windows 7 Windows Vista 2000 1000 0 6

Windows 7 at CERN 7

Windows 7 at CERN Windows 7: 32 & 64 Bit Install Base CERN- 2010 1400 1200 1000 800 600 400 Total Windows 7 Windows 7 32 bit Windows 7 64 bit 200 0 8

Retirement Roadmap Phase-out of Windows XP, Windows Vista, Office 2003 Target is migration to Windows 7 and Office 2010 Vendor support Microsoft will stop security updates for Windows XP in April 2014 Windows 8 can be expected in 2012 CERN planning Long term identification of best opportunity for upgrades in coordination with LHC schedule Some investment to replace old PCs may be required 9

Evolution of HW - W7 Readiness Analysis of the life time of the hardware, where Windows 7 is not supported 1200 Assumption: max 5-year hardware turnover 1000 800 600 Total 400 200 0 2010 2011 2012 2013 2014 2015 2016 10

Machines with less than 1GB OIS Evolution of HW - Memory 800 Hardware boxes having less than 1GB RAM Centrally managed 700 600 500 400 300 200 100 0 Less than 1GB Predicted Date 11

Proposal for Windows Vista 2010 Q4 Contact current Vista users to encourage migration to Windows 7 Remove installation menu option for Vista 2011 Q2 Keep it on demand in case it is really needed Stop general support of Windows Vista at CERN: ~20 Catia engineering PCs maintained until Catia on Windows 7 No hardware upgrades required for Vista to Windows 7 migration 12

Proposal for Windows XP 2011 Q1 Stop installation of XP on new hardware: but keep it available for old hardware IT Training Tutorials for Windows 7 + Office 2010 2011 Q3 Contact XP users to encourage migration 2012 Q4 Stop support of Windows XP at CERN Today, 950 machines have less than 2GB memory or old motherboards Assuming 5 year lifecycle, all retired by 2012 13

Proposal for Office 2003 2010 Q4 Information campaign to 1000 PCs running Office 2003 to upgrade 2011 Q1 IT Training Tutorials on Office 2007 and 2010 2011 Q3 User interface changes Stop support for Office 2003 Force upgrade to Office 2007 >1GB RAM is required 100 PCs which would are also not sufficient for Windows 7 14

XP/Vista Phase-out Roadmap Date XP Vista Office 2003 2010 Q4 Information to users 2011 Q1 Stop new installs Information to users Stop new installs Information to users 2011 Q2 Stop support Upgrade training 2011 Q3 Mailing to users Stop support 2011 Q4 2012 Q1 2012 Q2 2012 Q3 2012 Q4 Stop support 15

Outline Update on Windows 7 at CERN NICE Windows 7 since April 2010 Evolution of Install base Roadmap for phase-out of Vista, XP, Office 2003 Remote Desktop Gateway In use at CERN since 2009 16

Remote Desktop Gateway Motivation Windows users need a secure way to access their desktops across firewalls Was in place at CERN to provide secure way to work from home in case it would have been needed in wake of H1N1 pandemic in 2009. Previous options: SSH Tunneling Double-hop via a terminal server 17

Remote Desktop Gateway TS Gateway 1(2) Remote Desktop Gateway was introduced with Windows Server 2008 R2 enables authorized remote users to connect to resources on an internal corporate or private network Gateway server to route connections Is more secured way to provide connections from Internet. Uses port 443 instead of 3389 HTTPS-based protocol NLB Load balanced cluster in use at CERN 18

Remote Desktop Gateway TS Gateway 2(2) RD Gateway features: Active directory controlled user access Connection Authorization Policies What credentials are authorized to connect TS Gateway Where are connections coming from Resource Authorization Policies Where are you allowed to connect Who is allowed to connect 19

RDG Architecture Encrypted connection on port 443 Security in depth AD-based ACLs on the TS Gateway No need to open port 3389 on the firewal RDC 6.1 (RD) client TS Gateway HTTP/S RDP over connection HTTP/S established to TS Gateway to TSG RDP 3389 to host External network Internal Network 20

RDG CERN Web interface Web application that allows to: configures RD Gateway permissions to allow connection configures the target PC to allow incoming connection for specified users prepares RDC connection file 21

RD Gateway Usage Usage & Statistics ~450 registered computers In average about 50 active connections via CERN RD gateway Remote Desktop Gateway - Registered Computers 500 450 400 350 300 250 200 150 100 50 0-50 Computers 22

Questions?