locked
VDI or Session based RDP on Windows server 2019 with user cal RRS feed

  • Question

  • Hello,


    FYI, I am using windows server 2019 Eval version. we want to work out the setup before acquiring licenses from MS.

    All windows machines(servers, windows-10) described below are deployed as VM's on Dell server with VMware esxi.

    We have a lab where in we need to log on to Jump-Server (WINDOWS-SERVER-2019) using RDP.

    from this Jump-Server, I need to log on to 

    1. Windows-Server using RDP client on Jump-Server.
    2. Windows-10 machine using RDP client on Jump-Server

    I understand we must install RDP services in the Jump-Server & Windows server. 

    --------

    what I have at the moment is:

    Jump-Server has services:

    1. Domain Controller
    2. RD Gateway
    3. RD Web Access
    4. RD Connection Broker
    5. RD Session HOST

    Windows-Server has services:

    > RD Licensing
    > RD Session HOST.

    After configuring the Session based RDP, I'm able to get into Jump-Server.

    But when I try RDP client (inside Jump-Server) to connect to Windows-Server. I get error message "An internal error has occurred"

    Query-1: how to configure Session based RDS host on Jump-Server & Windows-Server, so that with same user could login to Windows-Server after getting into Jump-Server?

    ---------

    Configure RDP for Windows-10 VM's:

    Theoritically I understand, I should:
    Add windows-10 vm into same domain
    add this vm into RD Session Host. 

    Query-2: is this correct or do we need extra device cal AND/OR USER cal to connect via RDP client from Jump-server above?

    Thanks in Advance,

    Tuesday, April 14, 2020 6:00 AM

Answers

  • HI
    1.“I get error message "An internal error has occurred"”
    can you enter below command on both jump-server and windows-server then check if we configure NLA policy and security layer policy for them ?
    gpresult /h c:\rds.html
    if we disble NLA on windows-server ,can we remote access from jumper server to windows-server ?
    if we disble NLA and set security layter to rdp on windows-server,can we remote access from jumper server to windows-server ?
    is there vm computer which in the same network segment of windows-server can remote access  this windows-server ?

    2.are  jump-server and windows-server in the same AD domain?
    3.have you activate RDlicensing server ?
    4.are both jump-server and windows server in RDS 120 days grace period ?
    we can enter below command in command prompt(open as admin) on both jump-server and windows server then check the right-corner RDS grace period information.
    tlsbln.exe
    5."Query-2: is this correct or do we need extra device cal AND/OR USER cal to connect via RDP client from Jump-server above?"
    in general ,we configure rds per device cal mode on windows server and rds per user cal mode on jump-server ,meanwhile we need to specify RD licensing server on both  windows server and  jump-server.

    Best Regards
    Andy YOU
    Please remember to mark the replies as answers if they help.
    If you have feedback for TechNet Subscriber Support, contact tnmff@microsoft.com.

    Tuesday, April 14, 2020 2:53 PM

All replies

  • HI
    1.“I get error message "An internal error has occurred"”
    can you enter below command on both jump-server and windows-server then check if we configure NLA policy and security layer policy for them ?
    gpresult /h c:\rds.html
    if we disble NLA on windows-server ,can we remote access from jumper server to windows-server ?
    if we disble NLA and set security layter to rdp on windows-server,can we remote access from jumper server to windows-server ?
    is there vm computer which in the same network segment of windows-server can remote access  this windows-server ?

    2.are  jump-server and windows-server in the same AD domain?
    3.have you activate RDlicensing server ?
    4.are both jump-server and windows server in RDS 120 days grace period ?
    we can enter below command in command prompt(open as admin) on both jump-server and windows server then check the right-corner RDS grace period information.
    tlsbln.exe
    5."Query-2: is this correct or do we need extra device cal AND/OR USER cal to connect via RDP client from Jump-server above?"
    in general ,we configure rds per device cal mode on windows server and rds per user cal mode on jump-server ,meanwhile we need to specify RD licensing server on both  windows server and  jump-server.

    Best Regards
    Andy YOU
    Please remember to mark the replies as answers if they help.
    If you have feedback for TechNet Subscriber Support, contact tnmff@microsoft.com.

    Tuesday, April 14, 2020 2:53 PM
  • HI
    Is there any progress on your question?

    Best Regards
    Andy YOU
    Please remember to mark the replies as answers if they help.
    If you have feedback for TechNet Subscriber Support, contact tnmff@microsoft.com.

    Tuesday, April 21, 2020 1:32 AM
  • HI
    If the problem persist ,we can post a new case! thanks for your understanding.

    Best Regards
    Andy YOU
    Please remember to mark the replies as answers if they help.
    If you have feedback for TechNet Subscriber Support, contact tnmff@microsoft.com.

    Friday, May 8, 2020 1:55 AM
  • Apologies for not responding to your question. we got stuck with some priority activity & continued to use the MS servers in Eval mode.

    I am trying to execute the steps you have mentioned above, will get back to you asap.

    Sunday, July 12, 2020 5:24 AM
  • I was able to solve the problem with WEB RD gateway. now our topology has 

    1. One windows server which hosts 4 RDS roles viz

    1. Domain Controller
    2. RD Gateway
    3. RD Web Access
    4. RD Connection Broker

    2. My Jump-server & Windows server configured as separate RD Session Collection hosts pointing server in step 1 as gateway, license.

    With this I was able to solve the RDS issue I was facing. 1 user able to login to both session hosts in same domain.

    Monday, August 3, 2020 3:35 PM