Remote Desktop and SSH via HTML5 Access
html5 access is a client less solution to access remote desktops using remote desktop protocol (rdp), or to communicate over an encrypted secure shell (ssh) session advanced html5 access solution is disabled when fips mode is turned on and is enabled when fips mode is turned off fips mode is applicable for the entire cluster configuring the html5 access feature creating a html5 access resource profile a html5 access resource profile is a profile that enables users to connect to remote desktops or to connect to internal server hosts in the clear using to communicate over an encrypted secure shell (ssh) session through a web based terminal session emulation to create a html5 access resource profile in the admin console, choose users > resource profiles > html5 access click new profile select the solution type figure html5 access resource profile from the type list, specify the session type (windows rdp or ssh or vnc) for this resource profile enter a unique name and optionally a description for the resource profile (this name becomes the default bookmark's name ) in the host field, enter the hostname, ip or user attribute of the server to which this resource profile should connect in the server port field, enter the port on which the system should connect to the server (by default, the system populates this field with port number 3389 if you select windows rdp, port number 22 if you select ssh and port number 5900 if you select vnc ) select the create an access control policy for html5 access check box to enable access to the server specified in the server port box (enabled by default) click save and continue in the roles tab, select the roles to which the resource profile applies and click add the selected roles inherit the autopolicy and bookmarks created by the resource profile if it is not already enabled, the system also automatically enables the html5 access option in the users > user roles > select role > general > overview page of the admin console for all of the roles you select click save changes (optional) in the bookmarks tab, modify the default bookmark created by the system and/or create new ones (by default, the system creates a bookmark to the server defined in the host field and displays it to all users assigned to the role specified in the roles tab ) defining bookmarks for html5 access resource profile when you create a html5 access resource profile, the system automatically creates a bookmark that links to the host that you specified in the resource profile the system enables you to modify this bookmark as well as create additional bookmarks to the same host fips enabled users can create admin/end user advanced html5 bookmarks however, advanced html5 feature is still not fips compliant to define bookmarks for html5 access resource profile in the admin console, select users > resource profiles > html5 access > resource profile name > bookmarks click the appropriate link in the bookmark column if you want to modify an existing session bookmark or, click new bookmark to create an additional session bookmark although it is generally easy to create a resource profile session bookmark through the resource profile configuration page, you can choose to create one through the user roles page as well (optional ) change the name and description of the session bookmark (by default, the system populates and names the session bookmark using the resource profile name ) the following figure depicts creating a html5 access resource profile bookmarks configuration allow users to open the bookmark in a new window by configuring the "bookmark opens new window…" option and specifying how to display the browser address bar and browser toolbar in 22 5r2 1 auto launch is introduced pass user credentials from the system to the terminal server so that users can sign onto the terminal server without having to manually enter their credentials you can do this by configuring options in the authentication single sign on area of the bookmark configuration page in 22 5r2 1 auto launch feature is introduced to automatically launch the bookmarks on user login to access advance html5 rdp via smart card, the smart card driver version at client side and rdp host should be same specify how the terminal emulation window should appear to the user during a terminal session by configuring options in the screen settings area of the bookmark configuration page allow users to access local resources such as printers and drives through the terminal session by configuring options in the resource options area of the bookmark configuration page disable audio to disable sound during the remote session enable printing to grant access to the servers specified in the resources list enable audio on console session to grant access to the servers specified in the resources list enable copy/paste to grant copy/paste capability for particular resource enable remote drive for file transfer to grant access to the servers specified in the resources list connect to the console session to grant access to the servers specified in the resources list enable audio recording to grant access to the audio recording during the remote session enable high sound quality to grant access to the high sound quality enable multiple monitors to grant access for multiple monitors connected to the client computer during the remote session enable session recording to grant access to the recording of end user sessions enable camera to grant access to the web camera enable auto resolution to enable auto resolution options available for advanced html5 solution allow users to access specific applications on the terminal server by configuring options in the remote program options area of the bookmark configuration page in addition, you can use settings in this area to define auto launch and application directory and arguments options specify the roles to which you want to display the session bookmarks if you are configuring the session bookmark through the resource profile pages, under roles all selected roles displays the session bookmark to all of the roles associated with the resource profile subset of selected roles displays the session bookmark to a subset of the roles associated with the resource profile then select roles from the all selected roles list and click add to move them to the subset of selected roles list click save changes when a user accesses a html5 rdp bookmark without sso to access backend resources, the client prompts for credentials before opening the html5 session the client does not provide options to change password creating a html5 enduser bookmark for remote desktop the following figure depicts creating a html5 enduser bookmark for remote desktop in the admin console, choose users > user roles > role > html5 access > options the administrator has the option to select the solution type as basic or advanced html for each user role basic html5 is selected by default enable the "user can add sessions" option to enable users to define their own html5 access session bookmarks when this option is enabled, the add html5 access session button appears on the html5access panel the next time a user refreshes the user console enable remote desktop launcher to enable users to access html5 access servers through the browse bar on the home page select the deny single sign on for sessions added by user option if you do not want the user add html5 access session page to include the authentication section used for single sign on this setting is disabled by default if you want to allow users to enable access to devices through the bookmarks they create, select from the following options in the allow users to enable resources defined below section user can disable audio to disable sound during the remote session user can enable remote drive for file transfer to connect the user's local drive to the terminal server, enabling the user to copy information from the terminal server to his local client directories user can enable printing to connect the user's local printers to the terminal server, enabling the user to print information from the terminal server to his local printer user can connect to the console session to connect to the console (admin) session of the rdp server user can enable audio on console session to play the audio only at the server user can enable copy/paste to enable copy from the rdp session and paste to the clipboard user can enable high sound quality to enable high sound quality user can enable audio recording to enable audio recording of the user session user can enable session recording to enable session recording of the user session user can enable multiple monitor to enable maximum of four monitors connected to the client computer for the remote desktop connection thereby providing extra desktop space user can enable camera redirection to enable web camera redirection user can enable resolution to auto adjust the width and height of the screen without the scroll bar in the right options available for advanced html5 solution with regard to an end user, if the allow user to add session is enabled, an icon appears in the end user's page to add html5 access session options are similar to admin bookmark options based on the settings an admin allows a user to change options indicated with are available for advanced html5 bookmarks if you want to allow users to enable performance flags through the bookmarks they create, select from the following options in allow users to enable performance flags defined below section user can enable wallpaper to allow users to display a wallpaper background to users user can enable theming to allow users to set windows themes in their terminal server windows user can enable font smoothing to allow users to make text smoother and easier to read this option only works on windows vista computers running rdp clients that are version 6 0 or later u ser can enable full window drag to enable users to specify the contents of the internet explorer window while they move the windows on their desktops user can enable desktop composition to allow users to make text smoother and easier to read this option only works on windows vista computers running rdp clients that are version 6 0 or later user can enable menu animations to enable users to animate the movement of menus if you want to allow users to enable access to devices through the ssh bookmarks, select from the following options in the ssh allow users to enable resources defined below section user can enable stfp to enable users to establish sftp connections user can enable copy/paste to enable copy from the session and paste to the clipboard if you want to allow users to enable access to devices through the telnet bookmarks, select from the following options in the telnet allow users to enable resources defined below section user can enable copy/paste to enable copy from the rdp session and paste to the clipboard if you want to allow users to enable access to devices through the vnc bookmarks, select from the following options in the vnc allow users to enable resources defined below section user can enable copy/paste to enable copy from the session and paste to the clipboard user can track remote cursor locally to enable rendering remote system cursor locally by the viewer user can ignore remote cursor to enable ignoring the remote cursor configuring external storage the following figure depicts external storage configuration to configure the external storage for session recordings in the admin console, navigate to users > resource profiles> html5 access > storage configuration select enable external storage enter the complete storage path to store the session recordings enter the username and password required to access the location click save changes defining sso options for the remote desktop session the following figure depicts defining sso options for the remote desktop session ( users >authentication single sign on ) to define single sign on options create remote desktop bookmark or edit an existing bookmark scroll to the authentication single sign on area of the bookmark configuration page specify username to pass to the terminal server you can enter a static username or a variable enter the \<username> variable to pass the username stored in the system's primary authentication server or use the following syntax to submit the username for the secondary authentication server \<username\@secondaryservername> or \<username\[2]> the fetch domain is provided for the admins and end user created bookmarks this option helps to fetch the domain name from the remote ad machine specify password if you want to specify a static password or specify variable password if you want to use the password stored in the system's primary or secondary authentication server to use the password from the primary authentication server, enter the \<password> variable or use the following syntax to submit the password for the secondary authentication server \<password\@secondaryservername> or \<password\[2]> click save changes defining display options for the remote desktop session when configuring remote desktop bookmark, you can specify how the terminal emulation window should appear to users during their terminal sessions to define display settings for the users' sessions create a remote desktop bookmark or edit an existing bookmark scroll to the screen settings area of the bookmark configuration page select number of bits to indicate color in the color depth drop down list the default color depth is 24bit enter the desktop screen width in the width box you can set it to minimum 800 and maximum 1920 enter the desktop screen height in the height box you can set it to minimum 600 and maximum 1080 enter the screen resolution in the dpi box click save changes defining device connections for the remote desktop session to define local resources that users can access create a remote desktop bookmark or edit an existing bookmark scroll to the resource options area of the bookmark configuration page select enable remote drive for file transfer to connect the user's local drive to the terminal server, enabling the user to copy information from the terminal server to his local client directories select enable printing to connect the user's local printers to the terminal server, enabling the user to print information from the terminal server to his local printer select disable audio to disable sound during the remote session select enable audio on console session to play the audio only at the server sound options are supported by microsoft remote desktop protocol file transfer (using the new html5/rdp feature) does not work if the disable audio option is checked if you want to allow users to enable performance flags through the bookmarks they create, select from the following options in allow users to enable performance flags defined below section user can enable wallpaper to allow users to display a wallpaper background to users user can enable theming to allow users to set windows themes in their terminal server windows user can enable font smoothing to allow users to make text smoother and easier to read this option only works on windows vista computers running rdp clients that are version 6 0 or later user can enable full window drag to enable users to specify the contents of the internet explorer window while they move the windows on their desktops user can enable desktop composition to allow users to make text smoother and easier to read this option only works on windows vista computers running rdp clients that are version 6 0 or later user can enable menu animations to enable users to animate the movement of menus click save changes for a detailed file transfer procedure, refer to the kb article file transfer on remote desktop via html5 access defining application settings for the remote desktop session when configuring remote desktop bookmark, you can specify that users can only access specific applications on the terminal server to define applications that users can access create remote desktop bookmark or edit an existing bookmark scroll to the remote program options area of the bookmark configuration page specify the program that you want to launch automatically on connection in the specify program on connection box enter the application name (applicable only for servers running windows 2008 and later) in the remote app box specify where the application's executable file resides on the terminal server in the remote app dir box (visible only when you clear launch seamless window) for example, you might enter the following directory for the microsoft word application c \program files\microsoft office\office10\winword exe specify the arguments for the application in the remote app args box you can use session variables such as \<username> and \<password> in the remote app args box for example, when specifying an application path, you might want to include the \<username> variable to personalize the location for example c \documents and settings\\\<username>\my documents click save changes windows requires a special notation for the names of remote applications the names of remote applications must be prefixed with two vertical bars for example, if you have created a remote application on your server for notepad exe and have assigned it the name "notepad", you would set this parameter to "||notepad" defining vnc bookmarks for html5 access resource profile when you create a html5 access resource profile with vnc session type, the system automatically creates a bookmark that links to the host that you specified in the resource profile the system enables you to modify this bookmark as well as create additional bookmarks to the same host to define bookmarks for html5 access resource profile in the admin console, select users > resource profiles > html5 access > resource profile name > bookmarks click the appropriate link in the bookmark column if you want to modify an existing session bookmark or, click new bookmark to create an additional session bookmark (optional ) change the name and description of the session bookmark (by default, the system populates and names the session bookmark using the resource profile name ) the following figure depicts creating an html5 access resource profile bookmarks configuration allow users to open the bookmark in a new window by configuring the "bookmark opens new window…" option and specifying how to display the browser address bar and browser toolbar in the authentication single sign on section specify username to pass to the terminal server you can enter a static username or a variable enter the \<username> variable to pass the username stored in the system's primary authentication server or use the following syntax to submit the username for the secondary authentication server \<username\@secondaryservername> or \<username\[2]> specify password if you want to specify a static password or specify variable password if you want to use the password stored in the system's primary or secondary authentication server to use the password from the primary authentication server, enter the \<password> variable or use the following syntax to submit the password for the secondary authentication server \<password\@secondaryservername> or \<password\[2]> in the vnc settings section select number of bits to indicate color in the color depth drop down list select enable copy/paste option to grant copy/paste capability for particular resource select track remote cursor locally option to render remote system cursor locally by the viewer from the encoding drop down list, select the appropriate method for encoding the remote screen image specify the roles to which you want to display the session bookmarks if you are configuring the session bookmark through the resource profile pages, under roles all selected roles displays the session bookmark to all of the roles associated with the resource profile subset of selected roles displays the session bookmark to a subset of the roles associated with he resource profile then select roles from the all selected roles list and click add to move them to the subset of selected roles list click save changes when a user accesses a html5 vnc bookmark without sso to access backend resources, the client prompts for credentials before opening the html5 session remote desktop user experience when you enable the remote desktops via html5 access for a user role, the end user needs to specify the resource that the user wants to access and enter credentials for the resource users can access remote desktop resources using the following methods urls from other web sites in most cases, users access session bookmarks directly from the end user console if you do not want to require users to sign into the end user console to find and access remote desktop links, you can create urls on other web sites that point to session bookmarks that you have already created ivanti connect secure browse bar in addition to enabling users to link to remote desktop links through bookmarks and urls, you can also enable them to access these resources through the system browse bar on windows systems users can access microsoft terminal services or remote desktop sessions by entering hrdp\ //hostname in the browse box server address by entering the remote desktop ip address or hostname, users can launch a remote desktop connection to any accessible server ssh user experience the html5 access feature supports the following applications and protocols network protocols supported network protocols include ssh terminal settings supported terminal settings include vt100, vt320, and derivatives and screen buffers security supported security mechanisms include web/client security using ssl and host security (such as ssh if desired) you can create secure terminal session bookmarks that appear on the welcome page for users mapped to a specific role a terminal session bookmark defines terminal session information for ssh sessions that users may launch these sessions give users access to a variety of networked devices, networking devices, and other legacy applications, that utilize terminal sessions the system supports ssh versions v1 and v2 and uses the following ssh versions openssh 5 2, openssh 2 9 9p1, ssh protocols 1 5/2 0, and openssl 0x0090607f for detailed ssh configuration, refer to ssh monitoring html5 sessions the current html5 sessions information is provided in dashboard and the trend graph this information helps administrator to view the cpu usage and take necessary action to provide better remote access experience for the users the connection type is logged as html5 to enable html5 graph select system > status > overview in the select list of graphs list, enable the html5 connections option by default, this option is enabled the html5 connections graph shows the traffic on the html5 rdp, html5 ssh, and html5 telnet connections select system > status > virtual desktop sessions the active virtual desktops sessions page lists the active user sessions and the connection types select system > log monitoring > user access > log to view the html5 sessions log launching custom page via html5 access an end user can launch either basic html5 session or advanced html5 session end users can connect to a target server by entering the following in the browser bar https //\<pcs fqdn>/dana/html5acc/html5urllaunch cgi?type=launcher\&host=\<targetmachineip>\&port=3389& stype=0\&width=600\&height=480\&dpi=96\&security=tls\&enable wallpaper=true\&enable full windowdrag=true& username=admin\&password=pcs123\&enable drive=false\&enable printing=true\&disable audio=true\&client name=\<any string> to allow end users to use rdplauncher, navigate to users > user roles > role name > general > overview and select the html5 access option navigate to users > user roles > role name > html5 access > options and do the following select enable remote desktop launcher select necessary resources which user wants to access select necessary performance flags which user wants to access if the user is not logged in to ics, it will prompt for ics login and then prompt for target server credentials as shown in the screenshot below upon providing necessary details, it will open the html5 session the following figure depicts additional authentication in the target server the parameter can be validated from the rdp client task manager > users > client name parameters that can be configured via query parameters are disable audio (true/false) enable drive (true/false) enable printing (true/false) console (true/false) console audio (true/false) enable wallpaper (true/false) enable theming (true/false) enable font smoothing (true/false) enable full window drag (true/false) enable desktop composition (true/false) enable menu animations (true/false) color depth(8/16/24) security (rdp, nla, tls and any) server layout(en us qwerty, de de qwertz,fr fr azerty, it it qwerty, sv se qwerty, failsafe) color scheme (black white, white black, gray black, green black) font name (courier, monospace etc ) font size width height dpi host port stype (eg 0=rdp, 1=ssh and 2 = telnet) ignore cert (true) client name
