RDP connection redirection
-
RDP connection redirection is supported only when SSO is enabled and is supported in both single Gateway and Stateless or Dual Gateway mode along with enforcement (SmartAccess).
-
RDP Proxy feature is supported only with token-based redirection supporting IP cookies. IP-based routing tokens “msts=” are handed back by the Windows session broker or Connection broker when the Use IP Address Redirection functionality is disabled.
-
You can disable the Use IP Address Redirection setting to enable token-based redirection in the following location.
Computer Configuration > Policies > Administrative Templates > Windows Components > Remote Desktop Services > Remote Desktop Session Host > RD Connection Broker. -
Disable the Use IP Address Redirection setting on the RDSH machines and not the connection broker machine.
-
Dedicated redirectors for RDP Proxy connection can be configured.
Prerequisites
-
Create an RDP server profile to enable the 3389 listener on the NetScaler Gateway virtual server. If the machine that you want to RDP is not a member of any RDS connection broker infrastructure, then you do not need the 3389 listener.
-
Enable RDP connection redirection on the NetScaler Gateway appliance to support RDP Proxy in the presence of a connection broker.
Deploy RDP Proxy in the presence of a connection broker
-
With RD session host servers participating in RD connection broker load-balancing.
-
In the presence of the RDP load balancing feature.
Configure RDP Proxy in the presence of a connection broker by using the CLI
add rdpserverprofile <Name> -psk <string> -rdpRedirection ( ENABLE | DISABLE )
add rdpserverprofile serverProfileName -psk “secretString” -rdpRedirection ENABLE
Configure RDP connection redirection by using the NetScaler GUI
-
Navigate to NetScaler Gateway > Policies > RDP.
-
Right-click RDP to Enable or Disable the RDP redirection functionality.