Remote Access Portal
From UntangleWiki
Remote Access Portal
|
|
About Remote Access Portal
The Remote Access Portal provides a web portal for end-users to easily access internal network resources (if you're an Administrator, consider using PC Remote instead):
- Web servers (Intranet)
- Web mail
- File servers (network shares)
- Desktops
- Quarantined email
The Remote Access Portal is a client-less SSL VPN that provides a secure remote access from anywhere to a company's intranet through a regular web browser. Remote Access Portal is a great choice for remote access to desktops, web-based applications including email, and file sharing.
The portal home page is divided into two sections as shown in Example Portal Home Page:
- Bookmarks. Shows users bookmarks to resources.
- Applications. Shows a list of applications available to users. Portal Applications are web applications available to portal users. Currently, Network File Browser is the only available application.
When bookmark management is enabled, users can add and delete their own bookmarks using the plus and minus buttons. The maximize window button, enables users to increase the size of the current application. The home button returns the user to the home page, and the logout button, logs the user out of the portal.
Setting Up Remote Access Portal
Remote Access Portal offers many features to customize portals. However, in under 5 minutes you can set up a basic portal that enables all employees to access network resources.
Before You Begin:
Glance at the example outlined in Creating a Remote Access Portal for Angelic Resumes, Inc.
Task Go to 1. (Optional) Map your Untangle Server's public IP address to a domain name. Enables portal users can access the Remote Access Portal using the Untangle Server's domain name, rather than the IP address.
Configuring Untangle Server To Use Dynamic DNS 2. Install and turn on the Remote Access Portal. Installing Software Products Downloaded from the Library 3. Enable remote access to the Untangle Server. Enabling Remote Access To Untangle Server 4. If your Untangle Server does not have a public IP address, port forward from a public IP. Redirecting External and Internal Traffic 5. Install a certificate so that users do not encounter certificate warnings when they connect to the Remote Access Portal. About Digital Certificates 6. Ensure that each portal user has an account on the Local LDAP Server or on the Active Directory server. About User Access and Authentication 7. If you intend to create an RDP bookmark (Deciding When To Create a RDP Bookmark or VNC Bookmark) to a remote desktop, do one of the following :
- If the remote desktop is a Windows computer, complete the preparation steps.
- If the remote desktop is a Mac enable Remote Desktop Protocol (RDP).
Windows:
(Windows) Preparing To Create RDP Bookmarks.
Mac:
Apple RDP Tutorial. Note: For Macs, you only need to enable RDP, so only perform the initial step. Remote Access Portal does the remaining work for you.8. If you intend to create a VNC bookmark (Deciding When To Create a RDP Bookmark or VNC Bookmark) to a remote desktop, download and install the VNC server. Preparing To Create VNC Bookmarks 9. If you intend to create a bookmark to a network share, ensure that the portal users that you want to access that network share have permissions to that share. Otherwise, users will be denied access to that network share when they click on the network share bookmark.
Refer to your file server's operating system documentation or your NAS device's documentation.
10. (Optional) If you intend to create a portal group, create that portal group. You need a portal group if you do not want to make all networks resources (bookmarks) available to all users.
11. Add portal users to the Remote Access Portal. Adding Portal Users 12. Create the portal bookmarks, and customize the portal's look-and-feel. 13. Log on to the Remote Access Portal, and click on the bookmarks that you created to ensure that they are working properly.
(Windows) Preparing To Create RDP Bookmarks
Perform this procedure if the remote desktop is a Windows computer. If you have a Mac, go to Apple RDP Tutorial.
Note: For Macs, you only need to enable RDP, so only perform the initial step. Remote Access Portal does the remaining working for you.
The Untangle Server supports remote desktop control through Remote Desktop Protocol (RDP). RDP enables you to use any computer’s (client) mouse and keyboard to interact with another computer (host) through the Internet and in real-time. RDP enables you to transfer files between these two computers. You can also run the host’s applications on the client computer without having software installed on the client computer. Before you create desktop bookmarks using Remote Access Portal, perform the following steps:
Task Go to 1. Determine that your operating system supports RDP. Remote Desktop Protocol (RDP). Windows XP Home and Windows 98 versions do not support RDP. Windows RDP Requirements 2. Enable remote access to your Windows PC. Enabling Remote Desktop Control To Windows PC 3. If you have a Windows firewall, configure Windows Firewall to allow access. Configuring Windows Firewall To Allow Access
Enabling Remote Access To Windows PC
Perform this procedure on the host computer. The computer at the temporary location is the client computer. The computer at the remote location is the host computer.
To enable remote desktop control:
- Ensure that you are signed in as Administrator.
- On the host computer, click Start > Control Panel, and double-click on the System icon.
- Click the Remote tab, select the Allow users to connect remotely to this computer check box, and click OK. The computer is now enabled to allow remote access.
Configuring Windows Firewall To Allow Access
Perform this procedure on the host computer. Use this procedure if you intend to use Windows Firewall on the host computer. The computer at the temporary location is the client computer. The computer at the remote location is the host computer.
To set up Windows Firewall to allow exceptions:
- On the host computer, click Start > Control Panel, and double-click on the Security Center icon.
- Under Manage security settings for, click Windows Firewall.
- If selected, clear the Don't allow exceptions check box.
- Click the Exceptions tab, and select the Remote Desktop check box.
- Click OK, and then close the Windows Security Center window. Your host computer is now set up to allow remote access.
- Close the Control Panel.
Next Step:
- Creating Portal Bookmarks and Customizing Portal Home Page
- Example: Creating an RDP Bookmark To a Desktop
Preparing To Create VNC Bookmarks
There are a number of VNC products on the market (for example, RealVNC). However, all essentially enable you to interact with a computer remotely. VNC is valuable if you want multiple users to interact with the same computer remotely.
Task Go to 1. Determine that your VNC product supports your operating system. RealVNC 2. Download the VNC Server on the computer that you want to log on to remotely. VNC Enterprise Edition 3. Install the VNC Server. 4. Configure the VNC Server.
Configuring VNC Server
The easiest way to configure the VNC Server is to specify a password and turn off encryption. This procedure assumes that you're using RealVNC, though all VNC products are very similar.
To configure VNC Server:
- Launch the VNC Server service.
- Provide a password for authentication. Users that want to log on to the desktop that runs VNC will need to type this password.
Next Step:
- Creating Portal Bookmarks and Customizing Portal Home Page
- Example: Creating a VNC Bookmark To a Desktop
Adding Portal Users
The Remote Access Portal automatically creates on-demand portal accounts for all users in the Local Directory.
To change the default setting:
- From Remote Access Portal, click on the the Global Settings tab.
- In the Login Page Features area, either enable or disable the Create Accounts On Demand From Local Directory feature.
- If the check box is selected, when a user authenticates with the Local Directory but does not have a portal account, the Untangle Server automatically creates a portal account.
- If the check box is cleared, only users with a portal account can log in, even if that user can authenticate with the Local Directory.
To add a portal user:
Before You Begin:
- Ensure that each portal user has an account on the Local LDAP Server or on the Active Directory server. To learn what happens if the account doesn't exist, go to About User Access and User Authentication.
- (Optional) Create groups. Go to Creating Portal Groups.
- From Remote Access Portal, click the Users tab.
- Click on the add (+) button to add a new entry. The Edit window appears.
- Click on the [no user id/login] button. The Portal Question window appears.
- In the Select an existing user: area, select the user to whom you want to give Remote Access Portal access, then click Update. If you have configured both Local Directory (LDAP) and Active Directory (AD), you can identify users by the tag at the end of the user’s name:
- (Active Directory). Represents users that authenticate using Active Directory.
- (Local). Represents users that authenticate using Local Directory.
- (Optional) In the Edit window, add the user to a group by selecting a group from the group drop-down list, then click Update.
- Click the Save button.
Creating Portal Groups
Groups are a convenient and optional way to organize page settings and bookmarks for a specific group. For example, if you create an Employees group, you can edit all employees' bookmarks and page settings from a single location. You can also have more than one group. For example, an Employees group and a Contractors group, providing bookmarks to different network resources
Warning: Group page settings are overridden by individual user page settings.
To create a group:
- From Remote Access Portal, click Groups tab.
- Click the add (+) button. The Edit window appears.
- Specify a descriptive name for the group, then click Update.
- Click the Save button.
Creating Portal Bookmarks and Customizing Portal Home Page
You can add bookmarks to applications or customize the look-and-feel of the portal home page for any of the following:
- A user (user settings). User Settings provide a way to create customized home pages for individual users. Go to Creating Bookmarks and Customize Home Page for Specific Users.
- A group (group settings). Group Settings provide a convenient way to make bookmarks available to a specific group of users. Go to Creating Bookmarks and Customizing Home Page for Portal Groups.
- All users (global settings). Global Settings provide a convenient way to make bookmarks available to all users' portal home pages. Go to Creating Bookmarks and Customizing Home Page for All Users.
Note: The Untangle Server applies page settings to all portal users unless overridden in the user's personal page settings or the user's group page settings.
Deciding When To Create a RDP Bookmark or VNC Bookmark
The choice whether to create an RDP bookmark or a VNC bookmark depends on two factors:
- Your operating system
| Operating System | RDP | VNC |
|---|---|---|
| Windows 98 | No | Yes |
| Windows 2000 | Yes | Yes |
| Windows XP Home | No | Yes |
| Windows Media Center | No | Yes |
| Windows XP Professional | Yes | Yes |
| Mac | Yes | Yes |
| Linux/Unix | Yes | Yes |
- Whether you need collaboration or simply remote access
| Operating System | RDP | VNC |
|---|---|---|
| Collaboration | No | Yes |
| Remote Access | Yes | Yes |
Creating Bookmarks and Customize Home Page for Specific Users
To customize home page for a specific portal user:
Before you can add bookmarks to a newly created user, you must save the newly created user. If you don't save, the Bookmarks table doesn't appear in the Edit window.
- From Remote Access Portal, click Users tab.
- Click the Edit button that corresponds to the user for whom you want to create custom page settings.
- In the Page Settings area, click the Use Custom Page Settings radio button.
- Specify the home page characteristics, then click Update.
- Click the Save button.
To create bookmarks for a specific portal user:
Before You Begin:
- If you intend to create a bookmark to a remote desktop, complete the preparation steps outlined in (Windows) Preparing To Create RDP Bookmarks.
- If you intend to create a bookmark to a network share, ensure that the portal users that you want to access that network share have permissions to that share. Otherwise, users will be denied access to that network share when they click on the network share bookmark.
- From Remote Access Portal, click Users tab.
- Click the Edit button that corresponds to the user for whom you want to create bookmarks.
- In the Bookmarks table, click the add (+). The Edit window appears.
- Provide a descriptive name for the bookmark and select an application Type from drop-down list. Then, specify the Target destination and any application properties:
- take control of desktop. Choose this mode if you do not want anyone else to log on to this desktop when you are logged on.
- show new desktop. Choose this mode if you want to log on to this desktop and also want others to log on at the same time.
- Click Update, then Save.
Virtual Network Computer (VNC) An example target is 192.168.1.10:0. The target computer must be running a VNC server. Network File Browser The target is the network file share location. For example, \\myfileserver\share. Web Proxy The target is the URL to your company's Intranet site. For example, http://internalwebserver.mycompany.com/. Remote Desktop Specify the desired screen size (800x600 is common) size of popup window, view mode so that a user can view the identical desktop, or create a new desktop. The target is the IP address or host name of the desktop that that user wants to control remotely. For example, 192.168.1.10. Tip: Use the optional command text box to specify an application to run instead of logging directly into the machine. An example command is C:\test.exe. The console settings control the actual mouse and keyboard (true) or receive a virtual terminal (false). There are two view modes:
Creating Bookmarks and Customizing Home Page for Portal Groups
To customize a home page for a specific portal group:
Before you can add bookmarks to a newly created group, you must save the newly created group. If you don't save, the Bookmarks table doesn't appear in the Edit window.
Before You Begin:
- Create and save the group. Go to Creating Portal Groups.
- From Remote Access Portal, click the Groups tab.
- Click the Edit button that corresponds to the group for whom you want to create custom page settings.
- In the Page Settings area, click the Use Custom Page Settings radio button.
- Specify the home page characteristics, then click Update.
- Click the Save button.
To create bookmarks for a specific portal group:
Before You Begin:
- Create the group. Go to Creating Portal Groups.
- If you intend to create a bookmark to a remote desktop, complete the preparation steps outlined in (Windows) Preparing To Create RDP Bookmarks.
- If you intend to create a bookmark to a network share, ensure that the portal users that you want to access that network share have permissions to that share. Otherwise, users will be denied access to that network share when they click on the network share bookmark.
- From Remote Access Portal, click the Groups tab.
- Click the Edit button that corresponds to the group for whom you want to create bookmarks.
- In the Bookmarks table, click the add (+) button. The Edit window appears.
- Provide a descriptive name for the bookmark and select an application Type from drop-down list. Then, specify the Target destination and any application properties:
- take control of desktop. Choose this mode if you do not want anyone else to log on to this desktop when you are logged on.
- show new desktop. Choose this mode if you want to log on to this desktop and also want others to log on at the same time.
- Click Update, then Save.
Virtual Network Computing (VNC) An example target is 192.168.1.10:0. The target computer must be running a VNC server. Network File Browser The target is the network file share location. For example, \\myfileserver\share. Web Proxy The target is the URL to your company's Intranet site. For example, http://internalwebserver.mycompany.com/. Remote Desktop Specify the desired size (800x600 is common) size of popup window, view mode so that a user can view the identical desktop, or create a new desktop. The target is the IP address or host name of the desktop that that user wants to control remotely. For example, 192.168.1.10. Tip: Use the optional command text box to specify an application to run instead of logging directly into the machine. An example command is C:\test.exe. The console settings control the actual mouse and keyboard (true) or receive a virtual terminal (false). There are two view modes:
Creating Bookmarks and Customizing Home Page for All Users
To customize the home page for all portal users:
- From Remote Access Portal, click Global Settings tab.
- In the Page Settings specify the home page characteristics, then click Update.
- Click the Save button.
To create bookmarks for all portal users:
Before You Begin:
- If you intend to create a bookmark to a remote desktop, complete the preparation steps outlined in (Windows) Preparing to Create RDP Bookmarks.
- If you intend to create a bookmark to a network share, ensure that the portal users that you want to access that network share have permissions to that share. Otherwise, users will be denied access to that network share when they click on the network share bookmark.
- From Remote Access Portal, click Global Settings tab.
- In the Bookmarks table, click the add (+) button. The Edit window appears.
- Provide a descriptive name for the bookmark and select an application Type from drop-down list. Then, specify the Target destination and any application properties:
- take control of desktop. Choose this mode if you do not want anyone else to log on to this desktop when you are logged on.
- show new desktop. Choose this mode if you want to log on to this desktop and also want others to log on at the same time.
- Click the Update button, then Save.
Virtual Network Computing (VNC) An example target is 192.168.1.10:0. The target computer must be running a VNC server. Network File Browser The target is the network file share location. For example, \\myfileserver\share. Web Proxy The target is the URL to your company's Intranet site. For example, http://internalwebserver.mycompany.com/. Remote Desktop Specify the desired size (800x600 is common) size of popup window, view mode so that a user can view the identical desktop, or create a new desktop. The target is the IP address or host name of the desktop that that user wants to control remotely. For example, 192.168.1.10. Tip: Use the optional command text box to specify an application to run instead of logging directly into the machine. An example command is C:\test.exe. The console settings control the actual mouse and keyboard (true) or receive a virtual terminal (false). There are two view modes:
Example: Creating a Remote Access Portal for Angelic Resumes, Inc.
The following examples represents a portal page for Angelic Resumes, Inc., a company that provides resumes services to clients throughout the San Francisco Bay Area.
- Example: Creating a Bookmark To a Network Share
- Example: Creating an RDP Bookmark To a Desktop
- Example: Creating a VNC Bookmark To a Desktop
Note: To enable portal users can access the Remote Access Portal using the Untangle Server's domain name, rather than the IP address, Angelic Resumes, Inc. mapped its Untangle Server's public IP address to a domain name as outlined in Configuring Untangle Server To Use Dynamic DNS.
Example: Creating a Bookmark To a Network Share
Angelic Resumes, Inc. needs two groups: Employees and Contractors. Each group requires access to different network resources. You must define such bookmarks under Group, not User or Global as shown in Creating Bookmarks and Customizing Portal Look-and-Feel. The following example demonstrates a Remote Access Portal with the following bookmark to a network share, and a portal page with the following customizations:
- Bookmarks. For the Contractor group, one bookmark to the Share folder on a network share named yokie.
- Page Setup. Customized page with unique text to greet the contractors that log on to the portal. The portal has Show Application List disabled to restrict contractors from browsing the network.
Example: Creating an RDP Bookmark To a Desktop
Angelic Resumes, Inc. needs all employees to have access to their individual desktops, and you must define bookmarks that are exclusive to specific users under User, not Group or Global. The following example demonstrates how to create a RDP bookmark.
Note: Desktop bookmarks can use VNC or RDP as discussed in Deciding When To Create a RDP Bookmark or VNC Bookmark.
Example: Creating a VNC Bookmark To a Desktop
Asngelic Resumes, Inc. needs all employees to have access to a desktop that the company uses to provide remote training for writers. You must define bookmarks that apply to all employees under Global, not User or Group. The following example demonstrates how to create a VNC bookmark.
Note: Desktop bookmarks can use VNC or RDP as discussed in Deciding When To Create a RDP Bookmark or VNC Bookmark.
Maintaining Remote Access Portals
Enabling All Users To Create Bookmarks
The Untangle Server applies page settings to all portal users unless overridden in the user's personal page settings or the user's group page settings.
To enable all users to create bookmarks:
- From Remote Access Portal, click Global Settings tab.
- In the Home Page Features area, select the Allow User Bookmarks check box.
- Click the Save button.
Displaying Active Portal Users
To display active portal users:
- From Remote Access Portal, click the Active Users tab.
- Use the scroll bar to view the users that are currently logged in to the Remote Access Portal.
Tip: To log off users from the Remote Access Portal, click the logout button.
Displaying Portal Users' Historical Activity
To display historical activity:
- From Remote Access Portal, click the Event Log tab.
- Click the Refresh button at the bottom of the window.
- Use the scroll bar to view the users' login events and logout events.
Setting Idle Timeout for Portal Users
For greater security, you can change the idle timeout setting. By default the Untangle Server logs off any portal user that is idle for 20 minutes or more.
To set idle timeout:
- From Remote Access Portal, click Global Settings tab.
- In the Home Page Settings area, change the Timeout (minutes) value.
- Click the Save button.
Working With Remote Access Portal Home Page
- Logging On To Remote Access Portal
- Logging On To RDP Client
- Logging On To VNC Client
- Logging On To Web Proxy
Logging On To Remote Access Portal
To log on to Remote Access Portal:
- In a browser, type https://PublicAddress/portal where PublicAddress is either the public hostname or public IP address of the Untangle Server. For example, https://10.0.0.1/portal.
- Specify your login and password. The Remote Access Portal home page displays. If you do not have a valid login, contact your administrator.
Logging On To RDP Client
For an example, go to Example: Creating a Bookmark To a Desktop.
To log on to a remote desktop:
- From Remote Access Portal home page, click the RDP bookmark. A window appears.
- Click the Launch Remote Desktop Client link. A Java client launches and connects to the remote computer, and the remote computer's operating system prompts you for a username and password.
- Type in your username and password. The remote desktop appears in a Window. From here you can access files and applications on the remote computer just as if you were in front of that remote computer.
Logging On To VNC Client
To log on to VPNC client:
- From Remote Access Portal home page, click the VNC bookmark. A window appears.
- Click the Launch button. A Java VNC application launches.
- Type the VNC server's password. You are now connected to the remote computer.
Note: VNC might not present an error if there is a misconfiguration.
Logging On To Web Proxy
To log on to Web Proxy:
- From Remote Access Portal home page, click the Web Proxy bookmark. A window displays the target site.
- Click on the maximize button in the upper right to open a new window.
About Remote Access Portal Logs
Use the following terms and definitions to understand Remote Access Portal Event Log:
timestamp The time the event took place. action The action that was taken on the traffic. Valid values are block and pass. client The client IP address of the traffic. reason for action The rule that was applied to the traffic. server The intended server IP address of the traffic.
Related Topics
Remote Access Portal FAQs
Which desktop view mode should I choose?
There are two view modes:
- steal actual desktop. Choose this mode if you do not want anyone else to log on to this desktop when you are logged on.
- show actual desktop. Choose this mode if you want to log on to this desktop and also want others to log on at the same time.
Why doesn't RDP work when I use hostname?
If you created a RDP bookmark using a hostname as outlined in Creating Bookmarks and Customizing Home Page for Portal Groups, you might not have the hostname mapped to an IP address. To map that hostname to an IP address, go to Assigning Network Computers Static IP Addresses, or configure the RDP bookmark using the IP address instead of the hostname.
Do I need to enable RDP on the remote desktop?
Yes, before you create the remote desktop bookmark you must enable RDP. These steps are outlined in (Windows) Preparing To Create RDP Bookmarks.
I created the Remote Access Portal, What do I do next?
Log on to the Remote Access Portal, and click on the bookmarks that you created to ensure that they are working properly.
- To learn how to log on, go to Working With Remote Access Portal Home Page.
- To see an example, go to Example: Creating a Remote Access Portal for Angelic Resumes, Inc.
I have configured the Remote Access Portal to RDP to my PC, how come I get a Java error?
Scenario: You are using the Remote Access Portal (RAP) and trying to Remote Desktop (RDP) to one of the PC/server.
Issues: Certain java versions do not work. If you get the java error, most likely you have a java version that is unsupported.
Fix: Use this version, others might also work, however, this version has been verified. Version 1.5.0 (build 1.5.0_16-b02) http://java.sun.com/products/archive..._16/index.html You might need to go into add/remove programs and delete your other java versions. Please note that by default, java will automatically upgrade to the latest version. Please disable this option.
Other fixes: You can use the OpenVPN and RDP with the local IP address. If you do not want to use the OpenVPN, you can create a port forward rule for the RDP (3389). [1]
Why do I receive an access error when I click on a bookmark to a network share?
The error might be related to a permissions problem. Ensure that you have permissions to access the network share. This problem is not related to the Untangle Server.
Refer to your file server's operating system documentation or your NAS device's documentation.
What network resources can users access through Remote Access Portal?
Remote Access Portal provides a web portal for users to easily access internal network resources:
- Web servers (Intranet)
- Web mail
- File servers (network shares)
- Desktops
- Quarantined email
For more information, go to Remote Access Portal.
Can I configure Remote Access Portal to log off users if their computers are idle?
Yes! Remote Access Portal has an idle timeout setting. Go to Setting Idle Timeout for Portal Users.
Why can't portal users create their own bookmarks?
Users can create their own bookmarks, but they require access. Select the Allow User Added Bookmarks check box in Global Settings > Page Setup.
Why can't I connect to my Windows workstations via Remote Desktop?
Not all Windows workstations support RDP. Please visit http://www.microsoft.com/windowsxp/using/mobility/rdfaq.mspx for more information from Microsoft regarding RDP requirements.
Can I use Remote Access Portal on both of my WAN connections?
No. Remote Access Portal will only function on your primary WAN connection.
Why can't my portal users group see its custom portal page?
That user has a custom home page. The Untangle Server applies page settings to all portal users unless overridden in the user's personal page settings or the user's group page settings.
If you created a group as specified in Remote Access Portal, then that group should see a custom page. Ensure that you did not accidentally select the Use Global Settings radio button as shown in Figure, Overriding Group Settings.
![Untangle Networks [home] Untangle Networks [home]](http://www.untangle.com/templates/untangle_networks_template_950px/public/images/logo.gif)
![Untangle Networks [home]](http://www.untangle.com/templates/untangle_networks_template_950px/images/untangle_logo.gif)




