Applies To:
Show VersionsBIG-IP APM
- 13.1.5, 13.1.4, 13.1.3, 13.1.1, 13.1.0
What are remote desktops?
Remote desktops in Access Policy Manager® allow users to access the following types of internal servers in virtual desktop sessions:
- Microsoft® Remote Desktop servers
- Citrix® servers
- VMware View Connection servers
You can configure remote desktops by name or by their internal IP addresses, and grant or deny users the ability to set up their own favorites.
What is Microsoft remote desktop?
Using an Access Policy Manager® (APM®) RDP type remote desktop, clients can access a server that runs Microsoft Remote Desktop Services. Microsoft Remote Desktop servers run the Microsoft Remote Desktop Protocol (RDP) server. RDP is a protocol that provides a graphical interface to another computer on a network.
To provide Microsoft RDP connections natively, APM provides these alternatives.
- Java Client
- APM provides a Java Client option in the remote desktop configuration. The option supports native connections for Windows, Mac, and Linux clients. When this option is selected, a user on any compatible platform is presented with a simple Java Client interface to the Microsoft RDP server with reduced visual display features.
- APM as a gateway for RDP clients
- With proper BIG-IP® system configuration, Microsoft RDP clients can use APM as a gateway. The configuration supports Microsoft RDP clients on Windows, Mac, iOS, and Android. When a user types the address or hostname of the gateway into an RDP client and specifies a particularly configured virtual server for it, APM authorizes the client. When the client requests connections to resources on backend servers, APM authorizes the access.
For support information, refer to BIG-IP APM Client Compatibility Matrix on AskF5™ at http://support.f5.com/.
What is Citrix remote desktop?
Citrix® remote desktops are supported by Citrix XenApp™ and ICA clients. With Access Policy Manager® you can configure clients to access servers using Citrix terminal services. You provide a location from which a client can download and install a Citrix client for a Citrix ICA connection.
About ACLs to control access from remote desktop resources
When you create a remote desktop resource, Access Policy Manager® (APM®) automatically creates an allow ACL for the IP addresses and ports specified in the resource. To disallow access to any other IP addresses and ports, you must create ACLs that deny access to them and assign the ACLs in the per-session policy. F5 recommends that you create an ACL that rejects access to all connections and put it last in the ACL order.
Configuring an ACL to reject all connections
Task summary for remote desktops
To set up remote desktops, perform the procedures in the task list.
Task list
Configuring a resource for Citrix remote desktops
Configuring a resource for RDP remote desktop session host
Configuring a resource for RDP remote desktop web access
Configuring an access policy to include a remote desktop
Sample access policies for Native RDP client and APM webtop
These sample access policies are a reference for configuring RDP for APM webtop, a standalone client, or both.