It Calls

  • Subscribe to our RSS feed.
  • Twitter
  • StumbleUpon
  • Reddit
  • Facebook
  • Digg

Tuesday, 31 July 2012

Microsoft UAG DirectAccess Clients Cannot Reach and Ping your Partner/Newly Acquired Company Network

Posted on 14:52 by Unknown
Its quite often that many corporations acquire a new company or merge with another company with different domain name, subnets................etc. DirectAccess clients in one company cannot reach or ping the different resources, servers, routers..........etc in the other side (acquired/partner company). This can be solved by modifying your DNS infrastructure and UAG DirectAccess Settings as per the following steps:

  1. Configure the UAG server to have an IPV4 route to the new acquired network(s). 
  2. Make sure that the new acquired Network(s) are added to the UAG internal Networks. This can be done from the UAG Admin Menu – Network Interfaces – Define Internal network IP address range.
  3. The DNS servers used by the UAG and DirectAccess clients should be configured to resolve the acquired/Partner Domain either by having their DNS zone or by using conditional Forwarders.
  4. Configure your DirectAccess clients to use a DNS suffix search list. This list should include their current original company domain and the newly acquired domain. You may want to test it manually to ensure its working however its preferred to be done on the UAG DirectAcccess clients OU using Group policy as per attached.
  5. DNS Suffix Group Policy for DriectAccess OU in Active Directory
  6. Microsoft UAG need to be configured to ensure that the client’s NRPT (Name Resolution Policy Table) instructs the client to contact UAG for name resolution of the acquired domain. This will be done from the DirectAccess UAG configuration Step 3 (Infrastructure Servers – DNS Suffixes) as shown below
  7. UAG DirectAccess configuration step 3 Infrastructure servers
  8. Apply the new config/policy and Activate the UAG.
  9. Finally run gpupdate /force on the client to refresh the client group policy. To ensure that the policy is updated on the DirectAccess client you can run the “netsh namespace show pol”.



Read More
Posted in DirectAccess, UAG | No comments

Tuesday, 3 July 2012

RemoteApp and Web Application ICON Customization in UAG 2010 Portal

Posted on 13:22 by Unknown
UAG 2010 Portal customization is one of the key strengths in the UAG system. The Customization of UAG is based on the Custom Update concept, for more details and real life example, please check the following articles:

  • http://itcalls.blogspot.com/2012/03/uag-portal-home-page-customization-left.html
  • http://technet.microsoft.com/en-us/library/ee861168.aspx

One of the main customization issues that i faced during the last few weeks is changing the Default icons for applications and RemoteApp published applications on the portal. UAG by default is pre-loaded with several default icons for different applications however Custom apps published using the Remote Desktop Services (RDS) RemoteApp or custom Web published apps gets the default ICON which is not sometimes representing the application as per the Owner point of view. In this article i will provide two examples for ICON customization in UAG 2010 Portal.

  1. RDS RemoteApp applications, This includes three fairly simple steps:
    • You need to have your ICON file saved in PNG format, the size won't matter as the UAG will automatically re-size it according to its placement in the portal. I tried 15x15 and 32x32 and 64x64 Pixels and it worked fine for the three of them.
    • The ICON need to be saved under
      C:\Program Files\Microsoft Forefront Unified Access Gateway\von\PortalHomePage\images\AppIcons\CustomerUpdate (Provided that you installed the UAG in the default C-drive Location). The file should be saved under the application name, for example if your RemoteApp published application is named App1, then its icon should be App1.png.
    • Activate the UAG
  2. Custom Web Application, By default Custom Web application is published with the default App.gif file, to change this you have to do it in two locations:
    • The main (Home) Portal area will need a GIF icon 90x50 Pixels and it will be saved same as the RemoteApp under C:\Program Files\Microsoft Forefront Unified Access Gateway\von\PortalHomePage\images\AppIcons\CustomerUpdate (Provided that you installed the UAG in the default C-drive Location). Again Make sure to name the GIF file with the same name as per your published Application (For example App1.GIF).
    • Edit the Properties of the published Application on the UAG portal and change the ICON properties on the Portal Link TAB to reflect the new ICON
”UAG

    • The LeftExplorer Menu needs another ICON file with lower Pixel 15x15 and it should be named with the application name_ICON (For example App1_icon.GIF), similar to the above example, its saved under C:\Program Files\Microsoft Forefront Unified Access Gateway\von\PortalHomePage\images\AppIcons\CustomerUpdate (Provided that you installed the UAG in the default C-drive Location).
    • Activate the UAG

These two examples should lay the basic knowledge to customize your UAG Portal application ICONS and hopefully you will find it useful.


Read More
Posted in UAG | No comments

Thursday, 31 May 2012

Publishing Microsoft Pool VDI on UAG 2010 Portal

Posted on 13:31 by Unknown
Virtual Desktop Infrastructure is becoming a hot issue nowadays with many companies adopting this technology due to its flexibility, machines density, mobility, security, manageability and overall total cost of ownership. VDI can be either dedicated/Personal desktop assigned for specific user or pool of desktops available for all users (First come is first served); both flavors have their own benefits/drawbacks depending on your exact need and infrastructure. Microsoft allows you to publish the VDI solution on its UAG portal/Trunk however it’s not straight forward and not well explained/documented.

For an introduction to VDI components, please check the following link.

http://technet.microsoft.com/en-us/video/microsoft-virtual-desktop-infrastructure-vdi-explained.aspx

To publish your VDI Pool on UAG for External users, you need to do the following:

1.    Ensure the UAG server is fully updated and patched with latest UAG Service Pack and Rollups.


2.      From the UAG 2010 Server Copy the file ...\Microsoft Forefront Unified Access Gateway\common\conf\rd-template.txt to ...\Microsoft Forefront Unified Access Gateway\common\conf\Custom Update\rd-template.txt. This is needed to modify some RDP Parameters to make the VDI redirection work. For more information please check the attached link

 http://technet.microsoft.com/en-us/library/ff607422.aspx

For more information on the UAG Custom Update mechanism and a detailed example please check the following articles



http://technet.microsoft.com/en-us/library/ee861168.aspx#Customizing

http://itcalls.blogspot.com/2012/03/uag-portal-home-page-customization-left.html

3.    Add the below two lines to rd-template.txt and save it in Custom Update folder (mentioned in previous steps).



use redirection server name:i:1

loadbalanceinfo:s:tsv://vmresource.1.1



use redirection server name => Specifies whether a redirection server is allowed.

loadbalanceinfo => Contains the load balancing cookie used to choose the best server for the client computer. If you know your VDI Pool ID then you can change this command to be loadbalanceinfo:s:tsv://vmresource.1.PoolID



To get your VDI Pool ID, you need to connect to your Internal Connection Broker server then open the Server Manager – Roles – Remote Desktop Services – Remote Desktop Connection Manager – RD Virtualization Host servers– Pooled Virtual Desktops and then you can see all the properties including the Pool ID.

4.      From your UAG Portal/Trunk add new Application – Terminal Services– Remote Desktop (Predefined).

VDI Remote Desktop Predefined publishing rule

5.    In the Server Settings add the VDI Redirector session Host IP or Full Address and in the below space make sure to add all IP addresses or names of any system in your VDI solution (Session Broker, Gateway, Redirector, Session Host Virtualization and Virtual machines subnet). This is very critical step for the publishing rule to work fine. The Easiest thing is to add the full IP range for your VDI subnet. Then Activate your UAG.

UAG rule VDI Server settings



Note: If you already created the VDI publishing application and it wasn’t working, make sure to delete this application, apply all previous changes and then add the application again, the Custom update changes won’t work for existing published applications.





Read More
Posted in UAG | No comments

Wednesday, 30 May 2012

Microsoft MBAM Client Implementation Best Practices

Posted on 14:56 by Unknown
Microsoft BitLocker Administration and Monitoring (MBAM) is part of Microsoft Desktop Optimization Pack suite (MDOP) which contain other important and business enabling tools available for Software Assurance Customers. MBAM is used to simplify and control the Bitlocker implementation (Windows 7 Machine encryption), deployment, help desk support as well as providing rich compliance reports. In this article I would like to share some of the best practices that I passed by recently while implementing MBAM.

MBAM is implemented via Group Policies on your specified Windows 7 Laptops OU under Computer configuration - Policies - Administrative Templates - Windows Components - MDOP MBAM. This folder contain 4 main categories (check below image)

  1. Client Management
  2. Fixed Drive (Enable Password Protection)
  3. Operating System Drive (Enable PIN protection)
  4. Removable Drive
MBAM client Group Policy settings

    Normally we would enable the Client services and enforce the Fixed drive and OS drive encryption (PIN+Password). Depending on your Company policy you may enable or disable the Removable drive encryption (USB thumb drive). Under the Client Management category you can enable Hardware compatibility checking, this feature can be used to identify BitLocker-capable computers and exclude specific hardware that you don’t want encrypted. Only Laptops that are approved and turned to compatible (Hardware TAB in the MBAM admin site) will get encrypted.

    The Key steps for successful Bitlocker/MBAM client implementation are as follows:
    1. Enable TPM from the Laptop BIOS (check your Laptop Manufacturer BIOS settings)
    2. Activate the TPM from BIOS
    3. Install the MBAM client on the Laptop (32 bit or 64 bit client). Both are available in the MBAM source files.
    4. In many cases MBAM fails to take ownership of the TPM and its recommended to install this fix http://support.microsoft.com/kb/2640178
    5. By default the MBAM client will wait for 90 minutes random time delay before reporting to the MBAM server with any status, to overcome this default setting you need to add the DWORD key NoStartupDelay to the HKLM\Software\Microsoft\MBAM with value of 1 on each client. For more information about MBAM registry and Timers please check this link http://www.css-security.com/blog/mbam-real-world-information/
    6. If you enabled the Hardware Compatibility checking policy (mentioned above), the MBAM administrator need to to approve the devices to get encrypted and change their status to compatible from the MBAM admin site. There is a 24 hr check delay when you turn the machine compatible from the MBAM console. To overcome this you need to remove the following two keys from your client machines then restart the MBAM agent service
      • HKLM\software\microsoft\MBAM\HWExemptionTimer
      • HKLM\software\microsoft\MBAM\HWExemptionType

           

    MBAM Technical Documents:

    • Planning Guide: http://onlinehelp.microsoft.com/en-us/mdop/hh285653.aspx
    • Deployment Guide: http://onlinehelp.microsoft.com/en-us/mdop/hh285644.aspx
    • Operations Guide: http://onlinehelp.microsoft.com/en-us/mdop/hh285664.aspx
    • Troubleshooting MBAM: http://onlinehelp.microsoft.com/en-us/mdop/hh352745.aspx
    • MBAM Scalability and High-Availability: http://go.microsoft.com/fwlink/?LinkId=229025
    • MBAM Data Retention and Consistency Strategies: http://go.microsoft.com/fwlink/?LinkId=229052
    • Using MBAM Data Encryption With MDT: http://go.microsoft.com/fwlink/?LinkId=229053
    • MBAM Self-Help Portal: http://go.microsoft.com/fwlink/?LinkId=229054

    Microsoft BitLocker Administration and Monitoring (MBAM) Documentation Resources Download Page

    http://www.microsoft.com/download/en/details.aspx?id=27555

    MBAM Videos and Tutorials: http://technet.microsoft.com/en-us/windows/ff383366.aspx#MBAM


    Read More
    Posted in Bitlocker | No comments

    Monday, 30 April 2012

    DirectAccess IPHTTPS interface qualify over Teredo

    Posted on 14:57 by Unknown
    Its been noticed on several Direct access deployments that the Client IPHTTPS interface gets connected first over the Teredo interface although nothing is preventing the Teredo interface to get activated. Most of the clients won't prefer the IPHTTPS because of its high overhead and low performance compared to Teredo or 6to4. After some investigation and consulting Microsoft esclation engineers it turned out that its a well known issue on several clients where the Teredo and IPHTTPS race together and IPHTTPS wins at the end due to timing issues. This is elaborated in details on the following Microsoft Technet article http://technet.microsoft.com/en-us/library/ee844161(WS.10).aspx


    As per that attached below image extracted from the above mentioned article that this issue can occur and IPHTTPS will win and get qualified first.

    IPHTTPS qualify over Teredo due to timing issues

     To test whether my client is in this condition, i ran IPCONFIG /ALL on my client machine and i noticed that i have public addresses on both my Teredo and IPHTTPS interface as per attached.

    Both IPHTTPS and Teredo interface have public IP address



    To make sure you are using always Teredo you can implement one of the following workarounds:

    1. Disable IPHTTPSinterface from the Device Manager - View Hidden devices - Network adapters (unless you need IPHTTPS in locations where Teredo UDP port is blocked)
    2. After logging and connecting using the IPHTTPS, Restart the "IP Helper" Service.


    For more information about this issue please check Tom Shinder article http://blogs.technet.com/b/tomshinder/archive/2010/08/24/why-are-both-the-teredo-and-ip-https-interfaces-active.aspx

    Also its recommended to patch the UAG/Direct Access server with the latest fixes related to Direct Access, the most recent updates/fixes are as follows:

    http://support.microsoft.com/kb/2686921
    http://support.microsoft.com/kb/2633127
    http://support.microsoft.com/kb/2680464



    Read More
    Posted in DirectAccess | No comments

    Saturday, 31 March 2012

    UAG Portal Home Page Customization – Left Side Menu/Scroll Bar Example

    Posted on 05:29 by Unknown
    Microsoft UAG 2010 offers a very flexible way for customizing different pages and settings. The UAG Customization mechanism is deployed using a “CustomUpdate” Folder structure. Under the “Microsoft Forefront Unified Access Gateway” folder tree you will notice that several folders contain this “CustomUpdate” folder, in this folder the UAG admins can create their own Files and place them in the CustomUpdate folder. 

    When the UAG is activated it checks these folders first before checking the default folder. Its highly recommended to try all your customizations in this Folder “CustomUpdate” and the main reason is that if things went wrong, you can just delete these files and everything will be back to the default state before customization. Most of the Customization done for the UAG portal is done via the PortalHomePage folder as per attached screenshot.

    UAG 2010 Customization Folders


    An Example of Customization that I came across lately is the ability to increase the width of the Portal Home Page Left Side Menu. To Increase the Left Side Menu are you need to do the following:

    1. On the Forefront UAG server, open the folder Microsoft Forefront Unified Access Gateway\von\PortalHomePage
    2. Copy the file Standard.Master to the folder Microsoft Forefront Unified Access Gateway\von\PortalHomePage\CustomUpdate.
    3. Go to the Below section and modify the Width Portion <td class="midTopSideBarCell" style="width: 200px;"> then Activate the UAG and test the change.

    <td class="contentLeftSideBarCell" id="LeftSideBarCell">
                                <table cellpadding="0" cellspacing="0" class="leftSideBarTable">
                                    <tr>
                                        <td class="leftTopSideBarCell">
                                            &nbsp;</td>
                                        <%-- Folder View Title --%>
                                        <td class="midTopSideBarCell" style="width: 200px;">

    This will increase/Expand the left Side Menu however the Bottom scroll bar is not automatically sized according to the main cell, to adjust it to automatically size/fit with the main left area you will need to customize the Office.css (Thanks to Microsoft team) file as follows:

    1. On the Forefront UAG server, open the folder Microsoft Forefront Unified Access Gateway\von\PortalHomePage\App_Themes\Office\Office.css
    2. Copy the Office.css file to the \von\PortalHomePage\App_Themes\CustomUpdate\Office\Office.css
    3. Go to the below section (.SideBarContent) and modify the Width from 165px to 100% as shown below. Activate the UAG and test the change. This will automatically adjust the scroll bar to fit the left area in the portal.

    Office CSS side bar content UAG Portal Customization




    A very good reference is Technet Article of Customizing the Portal http://technet.microsoft.com/en-us/library/ff607389.aspx and Ben Ari/Rainier Amara Latest comprehensive book dedicated for UAG 2010 Customization.


    Read More
    Posted in UAG | No comments

    Monday, 19 March 2012

    Publishing IMAP/IMAPS on Microsoft UAG 2010 – UAG Support Boundary

    Posted on 05:24 by Unknown
    Recently several users with BlackBerry phones approached me seeking to access their corporate email on their phones. Microsoft UAG doesn’t support Blackberry service however a workaround to this is using the IMAP to access and download their emails on their Blackberry phones.

    Microsoft Highly recommend and Advice all UAG administrators to leave the TMG configuration (Installed by default on the UAG box) untouched. The TMG rules and configuration is controlled and configured by the UAG. The administrators should not use the TMG for publishing applications and other stuff. However there are some exceptions to this strict recommendation and its published in the UAG support Boundaries document. I also checked with Microsoft Support team and they confirmed the IMAP publishing based on this document.

    UAG Support boundaries:  http://technet.microsoft.com/en-us/library/ee522953.aspx

    As per the above mentioned document, Forefront TMG can be used to publish IMAP/IMAPS. Attached below is the section dealing with supported configuration on the TMG as per the above document.

    TMG supported configuration on UAG

    Accordingly IMAP/IMAPS can be published normally from the TMG server (On UAG Box). This will be a simple Server Publishing Rule with the following settings:

    1. Action - Allow
    2. Traffic - IMAPS Server
    3. From - Anywhere
    4. To - Type You Exchange Server IP
    5. Networks - External or DMZ (As per your setting)
    6. Schedule  - Always
    Its Highly recommended to use the IMAPS over the IMAP to ensure the traffic is encrypted.

    Read More
    Posted in UAG | No comments
    Newer Posts Older Posts Home
    Subscribe to: Posts (Atom)

    Popular Posts

    • Error 0x803100B7 Group Policy settings require the creation of a startup PIN, but a pre-boot keyboard is not available on this device
      I Purchased few weeks ago the Microsoft Surface Pro tablet, its a very nice production tablet that really enables remote users to run their ...
    • How to Publish New Certificate Revocation List (CRL) from Offline Root CA to Active Directory and Inetpub
      Its highly recommended when building your Microsoft PKI (Public Key Infrastructure) to have your Root CA offline after issuing the Enterpris...
    • Troubleshooting Direct Access Teredo connectivity on Forefront UAG 2010
      I encountered a problem on one of my installations for DirectAccess where all the clients were able to connect to DirectAccess using HTTPS o...
    • Surface 2 RT Bitlocker Recovery Key problem is fixed
      Windows Surface 2 RT comes already pre-setup with Bitlocker encryption, the user don't need to do anything to enable it or set/type a pa...
    • How to Manually Delete Old/Empty WSUS computer Group from Database
      Recently i was trying to delete/Remove one of the old computer groups under WSUS Console - Computers - All Computers. This Group was an old ...
    • DHCP Superscope Keeps reverting back after Deletion
      I passed by this experience after the deletion of a DHCP superscope where the Superscope reverts back after the DHCP server is rebooted or a...
    • How to Clean Microsoft WSUS Content Folder from Old and unneeded Products
      Microsoft WSUS administrators sometimes tend to select all given Products (Options - Products and Classifications) and by time the WSUS cont...
    • Bye Bye Microsoft UAG !
      Yesterday Microsoft Announced officially that there will be no new future full version of Microsoft UAG. Server 2012 and 2012R2 will cover s...
    • Manual add of Shares to Microsoft UAG File Access
      Microsoft UAG 2010 File Access is a nice feature to securely publish your internal shares on your UAG Portal for Internet users. To successf...
    • Two DNS Records with same IP Address. Aging and Scavenging problems with DHCP Lease duration !!
      Aging and Scavenging is very crucial and important for Active Directory Integrated zone, it should be carefully planned and configured. We r...

    Categories

    • Active Directory
    • Bitlocker
    • DirectAccess
    • Hyper-V
    • Lync
    • PKI
    • SQL
    • System Center
    • UAG
    • WSUS

    Blog Archive

    • ▼  2014 (1)
      • ▼  January (1)
        • Surface 2 RT Bitlocker Recovery Key problem is fixed
    • ►  2013 (27)
      • ►  December (5)
      • ►  November (4)
      • ►  October (2)
      • ►  September (1)
      • ►  August (4)
      • ►  July (4)
      • ►  May (1)
      • ►  April (2)
      • ►  March (3)
      • ►  February (1)
    • ►  2012 (25)
      • ►  December (2)
      • ►  November (3)
      • ►  October (3)
      • ►  September (2)
      • ►  August (2)
      • ►  July (2)
      • ►  May (2)
      • ►  April (1)
      • ►  March (3)
      • ►  February (2)
      • ►  January (3)
    • ►  2011 (5)
      • ►  December (2)
      • ►  November (3)
    Powered by Blogger.

    About Me

    Unknown
    View my complete profile