Peripheral NAT between Security Server and Connection Manager - View 4.6

Hi all

I'm trying to deploy a view environment 4.6 - with a view Security Server in the DMZ.

The DMZ is a NAT entirely would be and isolated network (single firewall, configuration 3-leg-GB-2000 is the model of the firewall).


At this point, just trying to get RDP to work with this configuration.

The firewall configuration is as follows:

-Security server IP - 10.1.1.49/24

-The alias created to view connection server - 10.1.1.100 (NAT IP)

-Tunnel NAT (with port 8009 and 4001) created between the server connection view and real IP 10.2.2.229 server connection alias

-The alias created for the view Desktop - 10.1.1.101 (NAT IP)

-Tunnel NAT (with port 3389) created between Desktop and view real IP Destop 10.2.2.239 view alias

I can RDP directly since the Security server to the desktop (via the 'alias' 10.1.1.101 IP) view correctly.

I can connect successfully from the internal network (via IP real office 10.2.2.239).

When I try to connect via the server of security (from the outside) I get the connection for the initial connection manager, and I choose the pool to connect to. However I'm unable to start a desktop session. The error I get is "the office is currently not available.

In the event logs on the Manager server connection that I see that the real IP (10.2.2.239) is used to connect to the desktop view - which will not work in this scenario (the 10.1.1.101 alias should be used).

Has anyone deployed a server of security seen in this scenario?

Thanks in advance!

Not sure if it works or not, but there is a GPO that changes the rules to connect using the DNS name.  Is the name DNS returns the correct value, you must connect as?

Tags: VMware

Similar Questions

  • Security Server cannot connect to the replica to connect to the server


    Hello

    I want to set up two security servers. Each connected to a login server.

    The installation of the Security Server works only when I connect to the backend connection.

    Telnet using port 4001 to replicas login server does not work. (from the Security Server)

    On the login replica server firewall rules seems to be OK.

    Who can help me here?

    Jan Willem

    It certainly works. Have two security servers, each associated with a connection to the server (for example a standard and the other a replica) is a very common scenario.

    Double check the rules in your firewall if you have an external firewall between your security servers and connection. Check for the setting procedure Administrator's guide matching password etc and for matching Security Server Troubleshooting section.  Make sure that the two security servers are configured the same (no group political advertising strategies of firewall different, firewalls running on all servers etc..). Make sure that the two connection servers are configured the same.

    Let us know what it was.

    Mark

  • What is the exact difference between secure mode and diagnosis

    I am repairing a pc and have done everything I can do in terms of diagnosing the problem. The only thing she shrinks down is to start in safe mode but not in diagnosis or vga mode. It is the same even when you use another defective hard drive. It must be a hardware component on the motherboard. I deleted and all the other components. I disabled designed in bios and Device Manager. What is the difference between secure mode and diagnosis?

    Thanks in advance for any help

    It was the capacitors on the motherboard that needed to change. It works fine now.

  • Set up the RSA only for security server and not internally?

    Greetings,

    In the view Configuration > servers > Edit View connection servers > authentication, you can enable the RSA. However, I would like to use RSA for people who connect through the Security Server and not those who log internally.

    Does this mean that my only option is to add another view connection server and point the Security Server on this connection to the server on which I have activate the RSA?

    If so is not necessarily a problem, but it would mean, I have 3 servers of connection and server 1 safety for an environment of view rather small.

    Ideally, I was balancing these aswell which would mean 4 servers connection and 2 security servers. It is perhaps a little exaggerated, heh.

    Anyone know of an alternative solution?

    Thanks in advance!

    The way you describe it is the way to do it. The Security server is always associated with a connection to the server, so no way around it.

  • Replication of data between SQL Server and using Oracle11g materialized view.

    I have Sqlserver 2005 as my source and oracle11g as my target. I need fill out the target daily with change of the source data.
    to do this, we created a dblink between SQL Server and oracle and reproduced this table as a point of view, materialized in Oracle.
    problem that we get here is fast refresh option is not available.each day it will pick up all of the data source.
    is it possible to use Fast refresh in this scenario?

    Thanks in advance.

    Kind regards
    Balaram.

    You can try MS SQL replication.
    Configure transactional Standard of MS SQL and Oracle Publication subscriber http://msdn.microsoft.com/en-us/library/ms151738%28v=sql.90%29.aspx

  • See Security Server and direct connection

    I have a security server for my connections from the Internet. It works very well, accept when I activate "direct connection on the desktop. I found the following statement on this:

    If you bypass the secure connection, the client must establish a direct communication of RDP to the virtual machine desktop RDP (port 3389).

    That means I have to open 3389 (RDP) to the Internet if I want to use direct connections?

    If I disable the direct connections to get my security server doesn't work, I have to turn off on my login server. It is I understand that this means that if I reboot my connection to the server, all disconnected mode clients. Is there a way I can disable "Direct connections" to the Security Server, allowing access from the LAN?

    TIA.

    For a long time I had to face the problem then I hope I'm he transmit correctly.   Because you don't want to open 3389 to the internet, you must use indirect connections to the broker for users of security server connections.   This means that all connections made outside the LAN will be handled by the Security server.   If you need to restart the Security server that these connections were removed.   If you need to restart the broker to connect to security services server should not drop all connections, the external web page would become unavailable unless you also have internal customers using this broker for connections to how it would be mandated by the broker for connections and would be deleted.

    Simple solution is to have a dedicated connection, broker for the Security server that is configured in indirect mode and then have one or two brokers connection for internal users who are configured in direct connection mode.   As I have said for a long time I had to deal with this so please forgive me if I have nothing hidden.

    If you have found this device or any other useful post please consider the use of buttons useful/correct to award points

  • connection between sql server and java

    someone please tell me how to connect to sql server with java

    Welcome to the forums.

    The forums are a research tool very useful - by using the search box you will see near the top right.  You will find that most of the questions that ask you, which, have already been asked on the forum, so it pays to research frist - that way you get a faster response and you can find other interesting things.

    In this case, I did a quick search using SQL Server and found these threads that will probably help:

    http://supportforums.BlackBerry.com/T5/Java-development/database-connectivity-SQL-Server-2008/m-p/60...

    http://supportforums.BlackBerry.com/T5/Java-development/SQL-Server-connection-in-BB/m-p/416391#M8239...

  • LOB compression secure between the server and the client

    Hi all
    According to the doc:
    SecureFiles LOB compression is performed on the server and enables random
    reads and writes to LOB data. Compression utilities on the client, like
    utl_compress, cannot provide random access.
    I don't know about the server and the client model in compression. This means that when has a table with a column of compress instance A and instance B accesses the table, the compression is performed on the server? How to do an instance a server or client, in this context? What he means by "random access"? How can we ensure that if a server is running live?

    Best regards
    TA.

    How do with random reading and writing? What is random and write anyway?

    LOB manipulation - see DBMS_LOB. e.g. DBMS_LOB. WRITING, WRITEAPPEND, READING, etc

    You couldn't use these on something that has been compressed to the outside.

  • Security roles and workflow management groups

    People,

    There is a section on Workflow management groups and security roles in vCloud Request Manager Installation and Configuration Guide - Guide of Directors Chapter 5 and 6. I have difficulty working on the relationship between the two settings.

    My first question is around the goal of the WM default checkbox that the specific guide is used to set the default user workflow management group.

    What would a never used default WM? I mean, what would he ever substitute the other workflow management groups that you define.

    In addition, in the guide, it say cloud Blueprint Admin and Asset Manager security role is a combination of the Admin of Blueprint of cloud and the Asset Manager. Is cloud Blueprint Admin & Asset Manager being the two groups of workflow management, reasonable to assume that a security role is composed of workflow management groups?

    And when I select agent, I do not see a cloud Blueprint Admin and Asset Manager security role listed?

    Finally, is there a way to determine the exact permissions that contains a workflow management group/security role?

    Thank you

    Cormac

    The Group Management (WM) default workflow is largely an artifact of vSM based vRM.

    VSM, a group of WM is a collection of agents used to apply security and route of tasks, among other responsibilities. (For the purpose of vRM, an agent can defined as users who have access to the vRM admin interface).

    vRM mainly use WM groups as a way to deliver relevant communications to users based on their responsibilities for example vCD Admins, Asset Managers etc. vRM does not require other functions related to WM groups.

    For functional reasons, vSM requires that each officer with access to the capabilities of WM belong at least a WM group. In addition, at least one of these groups must be designated the default WM for this officer group. These functional reasons are not immediately relevant to the specific use of vRM rest however case the constraint. Suffice to say for vRM, every WM user must have a WM group by default even if this information must never be used.

    Roles and groups are separate entities. A role defines a set of privileges to access a particular functional area of the admin interface for example a role WM sets permissions to interact with the workflow. of the roles of management (CM) configuration sets permissions to review and modify records in the repository of vRM.

    A special role of WM can be associated with one or more groups WM. When this WM role is assigned to a user, that user inherits groups associated with this role, WM allowing to simplify the administration of groups. An individual user can also have other WM assigned groups to them directly, complementary to those inherited from their role of WM.

    At an abstract level, vRM defines three types of users of the admin interface:

    1 vCD Admins

    2. plan Admins

    3. managers

    However, the security of MSM model requires that each individual user must be implemented with several components. By default, vRM sets a "Asset Managers" WM Group of what assets all managers must belong. However, WM groups cannot be used to give access to the features as well, so a separate from the "Asset Managers" WM role is obliged to grant access to these features asset managers. By default, the role of "Asset Manager" WM is associated with the "Asset Managers" group such that any user who is assigned the role automatically belongs to the Group also. There is also a separate 'Asset Managers' CM role that gives asset managers they need to the repository vRM for example the possibility to add new licenses for software products.

    This model of definitions is repeated for 3 personas above with a group and several roles defined for each. When an administrator assigns a user to one of these characters they should assign the groups and roles appropriate according to the documentation. They should not need to be concerned by the distinctions between each component.

    The role of the "Plan Director Admin and Asset Manager" reflects that a user may need to be asset manager and a Director of Blueprint. Because a user can have a role to the maximum by functional area, vRM provides a compound that provides two sets of permissions. However, a user can belong to several groups WM, so it is never necessary to provide a composite group.

    The role of composite is there; just maybe not where you expect to find. Blueprint Admins do not need to access WM, so there is not a 'Blueprint' Admin or a composite WM role. Blueprint Admins do need access to configuration management so it's an "Admin blueprint" and a role of CM composite.

    The details of the user screen provides:

    • a summary of all groups to which a user belongs

    • provides a 'Détails' button to drill down on each role assigned to the user to inspect the permissions granted by this particular role

    You must be a vCD Admin to see areas of the screen.

  • Difference between vCenter server and ESX server

    Hello

    I'm new to the development of VMware. Can you please explain me how ESX server differs from the VirtualCenter Server?

    According to my knowledge, ESX server is the one on which the real images are created and deployed while VirtualCenter manages ESX (one at a time) servers. ability to manage multiple ESX servers, both 'vSphere' a.

    My understanding is correct. Kindly answer my question.

    ESX (later - ESX4) is a system of bare metal operating that you can install directly on your physical hardware. This is the hypervisor layer that helps you to run multiple virtual machines on a single piece of material. The heart of ESX is the VMkernel which does all the magic (resouce management VM.. .and much). Talk about vCenter (previously Center Virtual Server) is a management application that you can install on a separate physical computer (you can even have a virtual vCenter). Once your vCenter is allowed, you can begin to manage the ESX servers.

    There are two ways to manage ESX. One is that you can directly connect to your ESX Server with root password and manage it. Otherwise, connect the server vCenter, add the ESX Server so that your vCenter it manages.

    vCenter resembles a management station from which you can manage your multiple ESX servers.

  • data replication with ODI between SQL SERVER and ORACLE

    Hello world
    First of all, I want to migrate database SQL SERVER and ORACLE DB tables.
    And then make online (synchronous) replication from SQL SERVER to ORACLE using ODI.

    I have not used before ODI.
    How to use the ODI for this?

    1. create a master repository and connect to the "topology Manager.
    2. in the topology Manager, you must configure the following
    2.1 create a data server for the Oracle under Oracle database in the physical connection
    2.2. create a database for the SQL Server database server in SQL Server in the physical connection. To do this, the jdbc for sql server driver.
    2.3 implement the logical connection and frame
    2.4 create a workrepository in the topology manager repositories tab
    3. connect to the designer and follow these steps
    3.1 create a template for the SQL Server source and reverse (import) the datastores (tables) to the model.
    3.2 the value of the model for the target of the Oracle
    3.3 create a (mapping) interface, under the table in schema define the source and then add it to the target and bind
    3.3 on the flow tab, you must set the Modules (KMs) of knowledge to perform the load. You must have imported the KMs before creating the interface.
    3.4 in IKM put 'create table traget' to 'yes '.
    4 run the interface to load data from SQL to Oracle Server

    Thank you
    Fati

  • What is the best way and to share data between a server and a Client app?

    Hello

    I'm trying to communicate a Client-Server application.

    In fact, I already have a simple data transfer via TCP/IP. However, I don't know yet, if TCP/IP is the best (and by that I mean, better, faster, safer, etc.)

    How to do.

    What are the cons and Pros between TCP/IP, STM and shared Variable?

    Do you recommend another type of communication in addition to these 3?

    Thank you

    Matt.

    In my view, that a general question cannot have a response says.

    Then, there is no way 'the best' for sharing data between a client and a server app.

    I like to use TCP/IP, but sometimes (when data loss is not critical) I use UPD (quick and dirty).

    I generally avoid shared variables, especially on embedded devices.

    Some other times I have I like to Exchange data in a database...

    A few other times I Exchange data using file...

    Marco

  • Problem starting managed server and Node Manager

    Hello

    I created the WebLogic domain with 2 managed servers. I use Jdevevloper11.2.3 integrated WebLogic server.  I can't start the servers ManagedWebLogic. On the console, I get an error stating:

    "For the server Server1, the Node Manager associated with new_Machine_1 of the machine is not accessible."

    Nor any of the management server is started through the startManagedWebLogic.cmd. Any help on this?

    Hello

    To start the managed from the console server, you must first start the node Manager process and then you can start managed based on the console server.

    Find the link to the screenshot of how to configure Nodemanager and start the managed server.

    NODE MANAGER configuration and starting managed server from Console - weblogicexpert

    To start the managed break with start-up follow the link below Scrip.

    Starting/Stoping Weblogic Managed Server - weblogicexpert

    It may be useful

  • How to configure WebLogic Admin Server and the managed server

    Hello

    I work to configure a Weblogic admin and the managed server, but fail.
    Can I know the correct steps for the installation system?


    TX.

    Good. It might be a good idea to mark this question as answered, then.

  • Problem with El Captain (5.1.7 server) and the management of permissions

    Hello world

    I have a big problem with our Mac Mini Server (El Captain) and the server program.

    In recent weeks, the server didn't give the permissions of a folder.

    for example:

    Mr. X had permission to read and write to a folder.
    Mr Y too.

    Mr. X has create a new folder one record something in it.

    Mr Y had the permission to read or write to the folder create Mr. x. But he should have.

    Or

    Mr. X has save a file to a folder

    When he opens it again it is write protected and cannot be replaced.

    So you have to save under a different name in the same folder.

    And every time he save/close the file.

    Anyone know what could be the problem?

    Thank you

    Greetings from the Germany

    Chris

    My guess:

    A few weeks ago someone messed with the permissions on your server and made a mistake. So, you got an inappropriate list ACL (Access Control), which is rampant in the file and must be removed or fixed.

    http://www.TechRepublic.com/blog/Apple-in-the-enterprise/introduction-to-OS-x-AC cess-control-lists-ACL.

    C.

Maybe you are looking for

  • Get rid of the HP network check

    I find this piece of software is a right royal pain in the proverbial. I want to uninstall or disable it if not. My PC is a HP Pavilion dv7-6c50ei running MS Windows 7 Ultimate x 64 SP1. I was very happy with the standard messages of IE9, whenever th

  • Shared variable of subjects with the executable in real-time

    We have a PXi target running Labview time real 8.5 and we use a series of shared variables for communication between the target and the client software. The code was developed (and used) in the last 2 years, and presented no problems with the shared

  • His laptop PC and Audio problem

    Hello I have a laptop of M6 HP ENVY after I upgrade my PC, there is no sound at all. It shows no speakers or headphones are connected. IDT High Definition Audio CODEC has been disappearing. How can I reinstall it? Could you please help solve my probl

  • When you use IE8 I sometimes get a screen empty and cannot get online.

    How to track what bad connection is? Sometimes, when I open my IE8 browser, it will automatically make a connection to the internet, but sometimes it cannot, and the browser displays a blank page. I already check the internet option for the connectio

  • Pavilion dv4000 laptop-no sound

    I have HP laptop Pavilion dv 4000 and used the recovery as disk it kept shutting off after 15-20 minutes. what I think has solved the problem, but I have now no sound despite its installed soundmax.  He also says that wireless assistant is not suppor