cancel
Showing results for 
Search instead for 
Did you mean: 

Need some help with WSAM

hutchingsp_
Contributor

Need some help with WSAM

I'm evaluating one of these and I'm just getting to grips with the basics.

I've managed to get our Intranet sites published, as well as some Windows File Shares and access to Citrix Metaframe, and now I want to do the following:

We have people who would want to use RDP to connect to their work PC. Rather than define each PC I'm assuming the simplest way to do this would be to create a WSAM policy to allow access to our LAN IP range on Port 3389?

I've done this under Resource Profiles and assigned a role, and when I login to the SA as a domain user I now have the option to launch WSAM.

Problem is that I launch it, it sits in the System Tray, but shows as disconnected?

Under "Client Applications" I've defined mstsc.exe as the application, and 10.0.0.0/255.0.0.0:3389 as the resource under "SAM Access Control".

Under "WSAM Destinations" I have 10.0.0.0/255.0.0.0:*

I think this is a schoolboy error, and next week I'm hoping to get an hour or so of webex with the folks we work with for this kind of kit, but for now it's just me an an 1100 page Juniper manual Smile
3 REPLIES 3
firewall72_
Frequent Contributor

Re: Need some help with WSAM

Hi,

We've always used the built-in Terminal Services bookmarks. You can allow users to add there own as well. This would provide access to your Terminal Servers, as well as any PC they need access to. We've used this approach for a few years now and haven't come across any issues. Whenever possible, I stay away from WSAM and JSAM.

-John

hutchingsp_
Contributor

Re: Need some help with WSAM

Fantastic!!! I've got this working, but to check I have it working in the correct/most secure way, here's what I did:

Went to the role I've created, and under Terminal Service/Options set the "User can add sessions" option.

I then went to Resource Profiles and created a Terminal Services rule to allow access to our LAN subnet, and allocated it to the role.

When I logon as a domain user I can now create a shortcut to any server/PC I like Smiley Happy

Only downside is it doesn't appear I can do this for the odd Linux/OS X client we may have? What would be the best way to do this?

Sorry if I appear to not be RTFM, but it's a huge manual and I'm finding it a bit chicken and egg in that it seems more suited to explaining something once you know what the option is, than finding the option you need to do what you want.

firewall72_
Frequent Contributor

Re: Need some help with WSAM

Hi,

I'm glad you got it working. With regards to Linux and Mac OS, I've been testing Proper RDPJava. I've pasted a link below that should help. If you have any issues, let me know. Good luck.

http://forums.juniper.net/jnet/search?submitted=true&q=Proper+Java+RDP

-John