{"id":3208,"date":"2016-08-26T11:31:00","date_gmt":"2016-08-26T14:31:00","guid":{"rendered":"http:\/\/www.radians.com.ar\/blog\/?p=3208"},"modified":"2018-01-16T16:00:39","modified_gmt":"2018-01-16T19:00:39","slug":"como-instalar-terminal-services-en-nuestra-arquitectura-de-directory-services-howto","status":"publish","type":"post","link":"https:\/\/www.radians.com.ar\/blog\/?p=3208","title":{"rendered":"Como instalar Terminal Services en nuestra Arquitectura de Directory Services [HowTo]"},"content":{"rendered":"<p align=\"justify\">He recibido varias consultas sobre Terminal Services con servidores Windows Server 2008&#160; R2 y como lo podemos utilizar en nuestra arquitectura de Directory Services. Por lo que estoy reescribiendo esta nota,&#160; si bien ya lo hablamos en otras oportunidades la idea es de refrescar los conocieminetos y realizar el paso a paso de la configurarion de este feature. Proximamente haremos lo mismo pero con Windows Server 2012 R2 o con Windows Server 2016. Espero que les sirva de ayuda, Saludos. Roberto Di Lello.<\/p>\n<p align=\"justify\">Lo que queremos configurar es lo siguiente, aqui tienen una imagen del entorno completo es la siguiente:<\/p>\n<h5><a href=\"http:\/\/www.radians.com.ar\/Articulos\/Images\/TerminalServerenWindowsServer2008LabsPar_BCD0\/VirtualLab.jpg\"><img loading=\"lazy\" decoding=\"async\" style=\"border-left-width: 0px; border-right-width: 0px; border-bottom-width: 0px; border-top-width: 0px\" border=\"0\" alt=\"VirtualLab\" src=\"http:\/\/www.radians.com.ar\/Articulos\/Images\/TerminalServerenWindowsServer2008LabsPar_BCD0\/VirtualLab_thumb.jpg\" width=\"444\" height=\"323\" \/><\/a><\/h5>\n<p>Como es muy largo el procedimiento lo escribir\u00e9 en partes.<\/p>\n<p>1. Dentro de la consola <strong><em>Server Manager<\/em><\/strong> seleccionamos <strong><em>Add Role<\/em><\/strong>.<\/p>\n<p><a href=\"http:\/\/www.radians.com.ar\/Articulos\/Images\/TerminalServerenWindowsServer2008LabsPar_BCD0\/TS01.jpg\"><img loading=\"lazy\" decoding=\"async\" style=\"border-left-width: 0px; border-right-width: 0px; border-bottom-width: 0px; border-top-width: 0px\" border=\"0\" alt=\"TS01\" src=\"http:\/\/www.radians.com.ar\/Articulos\/Images\/TerminalServerenWindowsServer2008LabsPar_BCD0\/TS01_thumb.jpg\" width=\"444\" height=\"217\" \/><\/a><\/p>\n<p>2. De la lista de roles disponibles seleccionamos <strong><em>Terminal Server<\/em><\/strong> y hacemos un clic en <strong><em>Next<\/em><\/strong>.<\/p>\n<p><a href=\"http:\/\/www.radians.com.ar\/Articulos\/Images\/TerminalServerenWindowsServer2008LabsPar_BCD0\/TS02.jpg\"><img loading=\"lazy\" decoding=\"async\" style=\"border-left-width: 0px; border-right-width: 0px; border-bottom-width: 0px; border-top-width: 0px\" border=\"0\" alt=\"TS02\" src=\"http:\/\/www.radians.com.ar\/Articulos\/Images\/TerminalServerenWindowsServer2008LabsPar_BCD0\/TS02_thumb.jpg\" width=\"444\" height=\"334\" \/><\/a><\/p>\n<p>3. Hacemos un clic en <strong><em>Next<\/em><\/strong> de la pantalla donde nos da una breve introduccion de lo que es <strong><em>Terminal Services<\/em><\/strong>.<\/p>\n<p>Terminal Services nos provee la posibilidad de habilitar a los usuarios utilizar programas instalados en un terminal server o acceder al escritorio de windows desde la red corporativa o desde internet.<\/p>\n<p><a href=\"http:\/\/www.radians.com.ar\/Articulos\/Images\/TerminalServerenWindowsServer2008LabsPar_BCD0\/TS03.jpg\"><img loading=\"lazy\" decoding=\"async\" style=\"border-left-width: 0px; border-right-width: 0px; border-bottom-width: 0px; border-top-width: 0px\" border=\"0\" alt=\"TS03\" src=\"http:\/\/www.radians.com.ar\/Articulos\/Images\/TerminalServerenWindowsServer2008LabsPar_BCD0\/TS03_thumb.jpg\" width=\"444\" height=\"334\" \/><\/a><\/p>\n<p>4. Ahora seleccionamos los roles<\/p>\n<p><strong><em>Terminal Server<\/em><\/strong>, habilita acceder a programas por terminal o al desktop. Los usuarios pueden conectarse a una terminal ejecutar programas, guardar archivos y utilizar servicios de red a travez del server.    <br \/><strong><em>TS Licensing<\/em><\/strong>: nos permite administrar las licencias de los clientes (CALs) y ver su disponibilidad.    <br \/><strong><em>TS Gateway<\/em><\/strong>: permite a los usuarios autorizados conectarse a los servidores terminal y a los remote desktops de la red corporativa desde internet.<\/p>\n<p>Recordemos que este rol requiere instalar el <em><strong>IIS (Web Server y Management Tools), Network Policy and Access Services, RPX over HTTP Procy, Windows Process Activation Services (Process Model y Configuration APIs)<\/strong><\/em><\/p>\n<p><a href=\"http:\/\/www.radians.com.ar\/Articulos\/Images\/TerminalServerenWindowsServer2008LabsPar_BCD0\/TS06.jpg\"><img loading=\"lazy\" decoding=\"async\" style=\"border-left-width: 0px; border-right-width: 0px; border-bottom-width: 0px; border-top-width: 0px\" border=\"0\" alt=\"TS06\" src=\"http:\/\/www.radians.com.ar\/Articulos\/Images\/TerminalServerenWindowsServer2008LabsPar_BCD0\/TS06_thumb.jpg\" width=\"444\" height=\"334\" \/><\/a><\/p>\n<p><a href=\"http:\/\/www.radians.com.ar\/Articulos\/Images\/TerminalServerenWindowsServer2008LabsPar_BCD0\/TS07.jpg\"><img loading=\"lazy\" decoding=\"async\" style=\"border-left-width: 0px; border-right-width: 0px; border-bottom-width: 0px; border-top-width: 0px\" border=\"0\" alt=\"TS07\" src=\"http:\/\/www.radians.com.ar\/Articulos\/Images\/TerminalServerenWindowsServer2008LabsPar_BCD0\/TS07_thumb.jpg\" width=\"444\" height=\"334\" \/><\/a><\/p>\n<p>5.&#160; Hacemos un clic en <strong><em>Next<\/em><\/strong>, a la ventana donde nos explica el tema de compatibilidad de aplicaciones.<img loading=\"lazy\" decoding=\"async\" style=\"border-left-width: 0px; border-right-width: 0px; border-bottom-width: 0px; border-top-width: 0px\" border=\"0\" alt=\"TS08\" src=\"http:\/\/www.radians.com.ar\/Articulos\/Images\/TerminalServerenWindowsServer2008LabsPar_BCD0\/TS08_thumb.jpg\" width=\"444\" height=\"334\" \/><\/p>\n<p>6. Ahora especificamos el m\u00e9todo de autenticaci\u00f3n. B\u00e1sicamente esto indica que tipo de cliente permitiremos, si la ultima versi\u00f3n de RDP o las anteriores. Hacemos un clic en <strong><em>Next<\/em><\/strong>.<\/p>\n<p><a href=\"http:\/\/www.radians.com.ar\/Articulos\/Images\/TerminalServerenWindowsServer2008LabsPar_BCD0\/TS09.jpg\"><img loading=\"lazy\" decoding=\"async\" style=\"border-left-width: 0px; border-right-width: 0px; border-bottom-width: 0px; border-top-width: 0px\" border=\"0\" alt=\"TS09\" src=\"http:\/\/www.radians.com.ar\/Articulos\/Images\/TerminalServerenWindowsServer2008LabsPar_BCD0\/TS09_thumb.jpg\" width=\"444\" height=\"334\" \/><\/a><\/p>\n<p>7. Ahora debemos seleccionar el tipo de licenciamiento que vamos a utilizar, si es <strong><em>Per Device<\/em><\/strong> o <strong><em>Per User<\/em><\/strong> o si deseamos configurarlo despues. Hacemos un clic en <strong><em>Next<\/em><\/strong>.<\/p>\n<p><a href=\"http:\/\/www.radians.com.ar\/Articulos\/Images\/TerminalServerenWindowsServer2008LabsPar_BCD0\/TS10.jpg\"><img loading=\"lazy\" decoding=\"async\" style=\"border-left-width: 0px; border-right-width: 0px; border-bottom-width: 0px; border-top-width: 0px\" border=\"0\" alt=\"TS10\" src=\"http:\/\/www.radians.com.ar\/Articulos\/Images\/TerminalServerenWindowsServer2008LabsPar_BCD0\/TS10_thumb.jpg\" width=\"444\" height=\"334\" \/><\/a><\/p>\n<p>8. Seleccionamos al grupo o a los grupos a los cuales vamos a permitirles acceder v\u00eda remota, y hacemos un clic en <strong><em>Next<\/em><\/strong>.<\/p>\n<p><a href=\"http:\/\/www.radians.com.ar\/Articulos\/Images\/TerminalServerenWindowsServer2008LabsPar_BCD0\/TS11.jpg\"><img loading=\"lazy\" decoding=\"async\" style=\"border-left-width: 0px; border-right-width: 0px; border-bottom-width: 0px; border-top-width: 0px\" border=\"0\" alt=\"TS11\" src=\"http:\/\/www.radians.com.ar\/Articulos\/Images\/TerminalServerenWindowsServer2008LabsPar_BCD0\/TS11_thumb.jpg\" width=\"444\" height=\"334\" \/><\/a><\/p>\n<p>9. Como seleccionamos el rol<strong><em> TS Lincensing<\/em><\/strong>, debemos seleccionar a que scope aplica, en nuestro caso seleccionamos <strong><em>The Domain<\/em><\/strong> y hacemos clic en <strong><em>Next<\/em><\/strong>.<\/p>\n<p><a href=\"http:\/\/www.radians.com.ar\/Articulos\/Images\/TerminalServerenWindowsServer2008LabsPar_BCD0\/TS12.jpg\"><img loading=\"lazy\" decoding=\"async\" style=\"border-left-width: 0px; border-right-width: 0px; border-bottom-width: 0px; border-top-width: 0px\" border=\"0\" alt=\"TS12\" src=\"http:\/\/www.radians.com.ar\/Articulos\/Images\/TerminalServerenWindowsServer2008LabsPar_BCD0\/TS12_thumb.jpg\" width=\"444\" height=\"334\" \/><\/a><\/p>\n<p>10. Seleccionamos <strong><em>Create a self-signed certificate for SSL encryption<\/em><\/strong>, y hacemos un clic en Next.<\/p>\n<p><a href=\"http:\/\/www.radians.com.ar\/Articulos\/Images\/TerminalServerenWindowsServer2008LabsPar_BCD0\/TS14.jpg\"><img loading=\"lazy\" decoding=\"async\" style=\"border-left-width: 0px; border-right-width: 0px; border-bottom-width: 0px; border-top-width: 0px\" border=\"0\" alt=\"TS14\" src=\"http:\/\/www.radians.com.ar\/Articulos\/Images\/TerminalServerenWindowsServer2008LabsPar_BCD0\/TS14_thumb.jpg\" width=\"444\" height=\"334\" \/><\/a><\/p>\n<p>11. Ahora debemos indicar si la pol\u00edtica de autorizaci\u00f3n ya que hemos seleccionado el rol <strong><em>TS Gateway<\/em><\/strong>, seleccionamos <strong><em>NOW<\/em><\/strong> y presionamos el bot\u00f3n <strong><em>Next<\/em><\/strong>.<\/p>\n<p><a href=\"http:\/\/www.radians.com.ar\/Articulos\/Images\/TerminalServerenWindowsServer2008LabsPar_BCD0\/TS15.jpg\"><img loading=\"lazy\" decoding=\"async\" style=\"border-left-width: 0px; border-right-width: 0px; border-bottom-width: 0px; border-top-width: 0px\" border=\"0\" alt=\"TS15\" src=\"http:\/\/www.radians.com.ar\/Articulos\/Images\/TerminalServerenWindowsServer2008LabsPar_BCD0\/TS15_thumb.jpg\" width=\"444\" height=\"334\" \/><\/a><\/p>\n<p>12. Seleccionamos el o los grupos que tienen acceso a trav\u00e9s de este rol, y hacemos clic en <em><strong>Next<\/strong>.<\/em><\/p>\n<p><a href=\"http:\/\/www.radians.com.ar\/Articulos\/Images\/TerminalServerenWindowsServer2008LabsPar_BCD0\/TS16.jpg\"><img loading=\"lazy\" decoding=\"async\" style=\"border-left-width: 0px; border-right-width: 0px; border-bottom-width: 0px; border-top-width: 0px\" border=\"0\" alt=\"TS16\" src=\"http:\/\/www.radians.com.ar\/Articulos\/Images\/TerminalServerenWindowsServer2008LabsPar_BCD0\/TS16_thumb.jpg\" width=\"444\" height=\"334\" \/><\/a><\/p>\n<p>13. Ingresamos un nombre para el TS_CAP y seleccionamos el m\u00e9todo de autenticaci\u00f3n. Luego hacemos clic en <strong><em>Next<\/em><\/strong>.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" style=\"border-left-width: 0px; border-right-width: 0px; border-bottom-width: 0px; border-top-width: 0px\" border=\"0\" alt=\"TS17\" src=\"http:\/\/www.radians.com.ar\/Articulos\/Images\/TerminalServerenWindowsServer2008LabsPar_BCD0\/TS17_thumb.jpg\" width=\"444\" height=\"334\" \/><\/p>\n<p>14. Debemos Ingresar el nombre para el <strong>TS RAP<\/strong>, y si es necesario configurar las restricciones adicionales. En nuestro caso seleccionamos <strong><em>Allow users to connect to any computer on the network, <\/em><\/strong>luego hacemos clic en <em>Next<\/em>.<\/p>\n<p><a href=\"http:\/\/www.radians.com.ar\/Articulos\/Images\/TerminalServerenWindowsServer2008LabsPar_BCD0\/TS19.jpg\"><img loading=\"lazy\" decoding=\"async\" style=\"border-left-width: 0px; border-right-width: 0px; border-bottom-width: 0px; border-top-width: 0px\" border=\"0\" alt=\"TS19\" src=\"http:\/\/www.radians.com.ar\/Articulos\/Images\/TerminalServerenWindowsServer2008LabsPar_BCD0\/TS19_thumb.jpg\" width=\"444\" height=\"334\" \/><\/a><\/p>\n<p>Bueno, esto es todo por hoy, les recomiendo que hagan un <em><strong>save state<\/strong><\/em> de las VMs y seguiremos la pr\u00f3xima semana.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>He recibido varias consultas sobre Terminal Services con servidores Windows Server 2008&#160; R2 y como&#8230;<\/p>\n","protected":false},"author":1,"featured_media":4291,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_monsterinsights_skip_tracking":false,"_monsterinsights_sitenote_active":false,"_monsterinsights_sitenote_note":"","_monsterinsights_sitenote_category":0,"footnotes":""},"categories":[325],"tags":[217,227],"class_list":["post-3208","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-directory-services","tag-ad-domain-services","tag-terminal-services"],"_links":{"self":[{"href":"https:\/\/www.radians.com.ar\/blog\/index.php?rest_route=\/wp\/v2\/posts\/3208","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.radians.com.ar\/blog\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.radians.com.ar\/blog\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.radians.com.ar\/blog\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.radians.com.ar\/blog\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=3208"}],"version-history":[{"count":1,"href":"https:\/\/www.radians.com.ar\/blog\/index.php?rest_route=\/wp\/v2\/posts\/3208\/revisions"}],"predecessor-version":[{"id":3209,"href":"https:\/\/www.radians.com.ar\/blog\/index.php?rest_route=\/wp\/v2\/posts\/3208\/revisions\/3209"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.radians.com.ar\/blog\/index.php?rest_route=\/wp\/v2\/media\/4291"}],"wp:attachment":[{"href":"https:\/\/www.radians.com.ar\/blog\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=3208"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.radians.com.ar\/blog\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=3208"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.radians.com.ar\/blog\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=3208"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}