43
Administration Guide HOB X11Gate Software version: 2.1 Issue: November 2014

HOB X11Gate Administration Guide · PDF fileThis guide is designed to provide system administrators with detailed information ... 4.4 HOB Portal Options ... CentOS Release 6.5

Embed Size (px)

Citation preview

Page 1: HOB X11Gate Administration Guide · PDF fileThis guide is designed to provide system administrators with detailed information ... 4.4 HOB Portal Options ... CentOS Release 6.5

Administration Guide

HOB X11Gate

Software version: 2.1

Issue: November 2014

Page 2: HOB X11Gate Administration Guide · PDF fileThis guide is designed to provide system administrators with detailed information ... 4.4 HOB Portal Options ... CentOS Release 6.5

HOB X11Gate Software and Documentation - Legal Notice

Contact: HOB GmbH & Co. KGSchwadermuehlstr. 390556 CadolzburgRepresented by: Klaus Brandstätter, Zoran AdamovicPhone: + 49 9103 715 0Fax: + 49 9103 715 271E-mail: [email protected]

Register of Companies: Entered in the Registry of Companies, Registry Court: Amtsgericht Fürth, Registration Number: HRA 5180Tax ID: Sales Tax Identification Number according to Section 27a Sales Tax Act: DE 132 747 002Responsible for content according to Section 55 Paragraph 2 Interstate Broadcasting Agreement: Klaus Brandstätter, Zoran Adamovic, Schwadermuehlstr. 3, 90556 Cadolzburg.

Disclaimer

All rights are reserved. Reproduction of editorial or pictorial contents without express permission is prohibited. HOB X11Gate software and documentation have been tested and reviewed. Nevertheless, HOB will not be liable for any loss or damage whatsoever arising from the use of any information or particulars in, or any error in, or omission from this document. All information in this document is subject to change without notice, and does not represent a commitment on the part of HOB.

Liability for content

The contents of this publication were created with great care and diligence. While we keep it as up-to-date as practicable, we cannot take any responsibility for the accuracy and completeness of the contents of this publication. As a service provider we are responsible for our own content in this publication under the general laws according to Section 7 paragraph 1 of the TMG. According to Chapters 8 to 10 of the TMG we are not obliged as a service provider to monitor transmitted or stored information not created by us, or to investigate circumstances that indicate illegal activity. Obligations to remove or block the use of information under the general laws remain unaffected. Liability is only possible however from the date of a specific infringement being made known to us. Upon notification of such violations, the content will be removed immediately.

Liability for links

This publication may contain links to external websites over which we have no control. Therefore we cannot accept any responsibility for their content. The respective provider or operator of the website pages to which there are links is always responsible for the content of the linked pages. The linked sites were checked at the time of linking for possible violations of the law. At the time the link was created in this publication, no illegal or harmful contents had been identified. A continuous and on-going examination of the linked pages is unreasonable without concrete evidence of a violation. Upon notification of any violations, such links will be removed immediately.

Copyright

The contents and works on these pages created by the author are subject to German copyright law. Reproducing, copying, modifying, adapting, distributing or any kind of exploiting of this material outside the realms of copyright require the prior written consent of the respective author or creator. The downloading of, and making copies of, these materials is only permitted for private, non-commercial use. Where contents of this publication have not been created by the author, the copyright of the third parties responsible for these contents shall be upheld. In particular any contents created by a third party are marked as such. If you become aware of any copyright infringement within this publication, we kindly ask to be provided with this information. Upon notification of any such violation, the concerned content will be removed immediately.

Trademarks

Microsoft Windows is a trademark of Microsoft Corporation.

Mac OS and Apple are trademarks of Apple Inc., registered in the U.S. and other countries.

All other product names, company names and service names may be trademarks, registered trademarks or service marks of their respective corporations or owners, even if they are not specifically marked as such.

Issued: November 25, 2014

2 Connectivity Solutions by HOB

Page 3: HOB X11Gate Administration Guide · PDF fileThis guide is designed to provide system administrators with detailed information ... 4.4 HOB Portal Options ... CentOS Release 6.5

Purpose of this Guide

This guide is designed to provide system administrators with detailed information concerning HOB X11Gate and to help them decide where and when this product can be most effectively deployed in their enterprise network.

This documentation contains descriptions of numerous possible scenarios and explains required conditions. The procedures for configuring the individual software components are documented in detail with step-by-step instructions.

Symbols and Conventions

This guide uses certain conventions and abbreviations which are explained here:

References to program commands, options and buttons are printed in Bold, for example: select the command Open.

Cross-references to section headings and figures with numbers are marked in color as follows: Section 5 Information and Support.

File names and text to be entered by the user are printed in Courier New. This input is – unless otherwise mentioned - case sensitive.

In this documentation, HOB-specific terminology is abbreviated as follows:

This symbol indicates useful tips that can make your work easier.

This symbol indicates additional informative text.

This symbol indicates an important tip or procedure that may have far-reaching effects. Please consider carefully the consequences of any changes and settings you make here.

HOB-specific Terminology Abbreviation

HOB WebSecureProxy HOB WSP

HOBLink Java Windows Terminal HOBLink JWT

HOB Remote Desktop Virtual Private Network HOB RD VPN

Connectivity Solutions by HOB 3

Page 4: HOB X11Gate Administration Guide · PDF fileThis guide is designed to provide system administrators with detailed information ... 4.4 HOB Portal Options ... CentOS Release 6.5

4 Connectivity Solutions by HOB

Page 5: HOB X11Gate Administration Guide · PDF fileThis guide is designed to provide system administrators with detailed information ... 4.4 HOB Portal Options ... CentOS Release 6.5

Contents

1 Introducing HOB X11Gate 7

1.1 Features of HOB X11Gate ............................................................................. 7

1.2 Connecting HOB X11Gate to your Network ................................................... 8

2 System Requirements 9

2.1 Server System................................................................................................ 9

2.2 Client System ............................................................................................... 10

3 Installing HOB X11Gate 11

3.1 Uninstalling HOB X11Gate........................................................................... 17

4 Configuring HOB X11Gate 19

4.1 X11Gate Portal ............................................................................................. 19

4.2 Management Portal ...................................................................................... 27

4.3 License Portal............................................................................................... 29

4.4 HOB Portal Options...................................................................................... 29

5 Configuring HOBLink JWT 31

6 Combining HOB X11Gate with HOB RD VPN 33

6.1 Configuring a HOBLink JWT Session........................................................... 33

6.2 Configuring WebSecureProxy ...................................................................... 35

7 Configuring the Remote Desktop Connection 39

8 Other HOB X11Gate Features 41

8.1 Disconnected Session and Session Reconnect ........................................... 41

8.2 Other Options ............................................................................................... 41

9 Information and Support 43

Security Solutions by HOB 5

Page 6: HOB X11Gate Administration Guide · PDF fileThis guide is designed to provide system administrators with detailed information ... 4.4 HOB Portal Options ... CentOS Release 6.5

6 Security Solutions by HOB

Page 7: HOB X11Gate Administration Guide · PDF fileThis guide is designed to provide system administrators with detailed information ... 4.4 HOB Portal Options ... CentOS Release 6.5

HOB X11Gate Introducing HOB X11Gate

1 Introducing HOB X11GateHOB X11Gate provides access to applications residing on UNIX/Linux servers from a Windows Terminal Server Client (TSC) such as HOBLink JWT, running on any platform. Thus, you can access both UNIX servers and Windows Terminal Servers (WTS) with just one client software.

X11 SSH could also be used for remote access to UNIX servers yet its performance is poor and it is therefore hardly used in practice. Using HOBLink JWT instead provides a higher level of performance than the X11 protocol and perfectly complements the HOB X11Gate, which uses the TSC protocol.

In order to understand how HOB X11Gate works, it is important to know that every HOB X11Gate session incorporates two major components:

towards the client, the first component simulates a WTS using the TSC protocol

towards the UNIX servers, the second component acts as an X11 server

Figure 1: Components of HOB X11Gate

1.1 Features of HOB X11Gate

HOB X11Gate includes the following features:

Multi-user remote access to Linux/Unix servers

Multi-session capability

Central administration and configuration

International keyboard support

Reconnect disconnected sessions

RDP encryption up to 128 bits

More security features in combination with HOB RD VPN

Security Solutions by HOB 7

Page 8: HOB X11Gate Administration Guide · PDF fileThis guide is designed to provide system administrators with detailed information ... 4.4 HOB Portal Options ... CentOS Release 6.5

Introducing HOB X11Gate HOB X11Gate

1.2 Connecting HOB X11Gate to your Network

There are two communication scenarios that are possible for HOB X11Gate.

1. HOB X11Gate is installed on the Linux/Unix server and users can access the server from their workstations, provided HOBLink JWT or Microsoft Terminal Services Client is installed:

Figure 2: Diagram of Direct Communication

2. The workstation remotely accesses the servers via HOB WebSecureProxy (HOB WSP) and HOB X11Gate.

The X11 protocol does not provide SSL encryption for remote connections. In order to make use of SSL security for remote connections, HOB recommends installing HOB RD VPN in the DMZ in conjunction with a central HOB X11Gate setup in the corporate network. HOB WSP is included in the scope of delivery of HOB RD VPN and it provides features such as 128-bit SSL encryption, user identification and authentication.

Figure 3: Diagram of Communication over the HOB RD VPN WebSecureProxy

This scenario is only appropriate for fast Internet connections via DSL and not for connections via modem or ISDN.

8 Security Solutions by HOB

Page 9: HOB X11Gate Administration Guide · PDF fileThis guide is designed to provide system administrators with detailed information ... 4.4 HOB Portal Options ... CentOS Release 6.5

HOB X11Gate System Requirements

2 System RequirementsThe following requirements are necessary for HOB X11Gate.

2.1 Server System

The server side must have one of the following supported 64 bit Linux/Unix distributions as OS:

SUSE Linux Enterprise Server 11

CentOS Release 6.5

Ubuntu 12.04 LTS

Red Hat Enterprise Linux Server 6.5

Installation with a Java Virtual Machine:

JVM Version 1.7 (or later)

Hardware requirements:

Processor with minimum 1 GHz

At least 1 GB RAM

250 MB free hard disk memory

Required libraries for all Linux operating systems:

libssh2.so (version 1.2.9 onwards)

libssl.so.10

libcrypto.so.10

librt.so.1

libdl.so.2

libstdc++.so.6

libm.so.6

libgcc_s.so.1

libc.so.6

libz.so.1

Please note that Gnome3 is not supported.

Security Solutions by HOB 9

Page 10: HOB X11Gate Administration Guide · PDF fileThis guide is designed to provide system administrators with detailed information ... 4.4 HOB Portal Options ... CentOS Release 6.5

System Requirements HOB X11Gate

2.2 Client System

HOBLink JWT or Microsoft Terminal Services Client software needs to be installed on the client side.

Hardware Requirements:

PC with a Pentium processorMinimum: 1 GHz Intel Pentium processor with 1 GB RAM

10 Security Solutions by HOB

Page 11: HOB X11Gate Administration Guide · PDF fileThis guide is designed to provide system administrators with detailed information ... 4.4 HOB Portal Options ... CentOS Release 6.5

HOB X11Gate Installing HOB X11Gate

3 Installing HOB X11Gate

1. If installing from a CD/DVD, insert the HOB X11Gate DVD into the CD-ROM/DVD-ROM drive.

2. The HOB X11Gate start page opens in the browser. If the DVD start image does not automatically appear, open the file start.htm in the root directory of the DVD. Select Download installer for Linux (64 bit) to start the download process.

3. Save the file and then open it. The installer opens.

Figure 4: InstallAnywhere

4. Select Next to continue.

Root privileges are required in order to install HOB X11Gate.

Security Solutions by HOB 11

Page 12: HOB X11Gate Administration Guide · PDF fileThis guide is designed to provide system administrators with detailed information ... 4.4 HOB Portal Options ... CentOS Release 6.5

Installing HOB X11Gate HOB X11Gate

Figure 5: License Agreement

5. Read and accept the license agreement and then select Next to continue.

Figure 6: Choose Install Folder

6. Choose the install folder and then select Next.

12 Security Solutions by HOB

Page 13: HOB X11Gate Administration Guide · PDF fileThis guide is designed to provide system administrators with detailed information ... 4.4 HOB Portal Options ... CentOS Release 6.5

HOB X11Gate Installing HOB X11Gate

Figure 7: Customize Installation

7. Enter the ports and then select Next to continue.

8. Your system is now checked for Java Version 1.7 or later. If you do not have the correct version installed, the following screen appears.

Figure 8: Missing Java Error

9. You can cancel and exit the installation or you can select Yes to move to the next step.

The default port for the RDP connection is 3389. This can be changed in the configuration portal or manually in the configuration file x11gate.xml.

If you decide to continue the installation anyway, you will need to manually install Java Version 1.7 or later following installation otherwise the Administration Portal will not function properly.

Security Solutions by HOB 13

Page 14: HOB X11Gate Administration Guide · PDF fileThis guide is designed to provide system administrators with detailed information ... 4.4 HOB Portal Options ... CentOS Release 6.5

Installing HOB X11Gate HOB X11Gate

Figure 9: Pre-installation Summary

10. Review the pre-installation summary and then select Install. HOB X11Gate will start installing.

Figure 10: Installing

14 Security Solutions by HOB

Page 15: HOB X11Gate Administration Guide · PDF fileThis guide is designed to provide system administrators with detailed information ... 4.4 HOB Portal Options ... CentOS Release 6.5

HOB X11Gate Installing HOB X11Gate

11. Enter the Serial Number and License Key. This information should be included in the Install CD/DVD or provided to you by HOB Support.

Figure 11: Enter Serial Number and License Key

12. The following screen displays further installation information. Select Next to continue.

Figure 12: Further Information

Security Solutions by HOB 15

Page 16: HOB X11Gate Administration Guide · PDF fileThis guide is designed to provide system administrators with detailed information ... 4.4 HOB Portal Options ... CentOS Release 6.5

Installing HOB X11Gate HOB X11Gate

13. Following installation, you have the option to configure scripts.

Figure 13: Configuring Scripts

14. Choose to start HOB X11Gate now or to register it as a service and then select Next.

Figure 14: Install Complete (Final)

15. Select Done to close the installer and then exit the web browser.

16 Security Solutions by HOB

Page 17: HOB X11Gate Administration Guide · PDF fileThis guide is designed to provide system administrators with detailed information ... 4.4 HOB Portal Options ... CentOS Release 6.5

HOB X11Gate Installing HOB X11Gate

3.1 Uninstalling HOB X11Gate

HOB X11Gate can be uninstalled via running the uninstall script located under <installdir>/Uninstall HOB X11Gate/Uninstall HOB X11Gate.

1. Run shUninstall_X11Gate2. The uninstaller opens.

Figure 15: Introduction

2. Select Uninstall to continue. The uninstallation begins.

Figure 16: Uninstalling

The uninstallation process is now complete.

Security Solutions by HOB 17

Page 18: HOB X11Gate Administration Guide · PDF fileThis guide is designed to provide system administrators with detailed information ... 4.4 HOB Portal Options ... CentOS Release 6.5

Installing HOB X11Gate HOB X11Gate

Figure 17: Uninstall Complete

3. Select Done to close the uninstaller.

You may need to restart your system in order to complete the uninstallation process. After restarting, you can delete remaining folders for a complete uninstallation.

18 Security Solutions by HOB

Page 19: HOB X11Gate Administration Guide · PDF fileThis guide is designed to provide system administrators with detailed information ... 4.4 HOB Portal Options ... CentOS Release 6.5

HOB X11Gate Configuring HOB X11Gate

4 Configuring HOB X11GateHOB X11Gate can be configured remotely via a web browser. Follow these steps:

1. Open a web browser and enter the IP address and port of HOB X11Gate to be configured (for example, http://linux.mycompany.com:8080)in the address field.

2. Use the default user credentials:

User Name: x11admin

Password: x11admin

The HOB Portal of the HOB X11Gate Administration appears.

The HOB X11Gate Administration consists of three portals:

X11Gate Portal – see Section 4.1 X11Gate Portal below.

Management Portal – see Section 4.2 Management Portal on page 27.

License Portal – see Section 4.3 License Portal on page 29.

4.1 X11Gate Portal

In the X11Gate Portal, you can manage sessions, view detailed session information, view logs and set up HOB X11Gate using Kanji configurations.

Figure 18: X11Gate Portal

For security reasons, we recommend immediately changing the password for the administrator with which you have just logged on. See Section 4.4 HOB Portal Options on page 29.

Security Solutions by HOB 19

Page 20: HOB X11Gate Administration Guide · PDF fileThis guide is designed to provide system administrators with detailed information ... 4.4 HOB Portal Options ... CentOS Release 6.5

Configuring HOB X11Gate HOB X11Gate

The X11Gate Portal consists of 4 portlets:

X11Gate Session Manager – see Section 4.1.1 X11Gate Session Manager below.

X11Gate Log Viewer – see Section 4.1.2 X11Gate Log Viewer on page 21.

Kanji Portlet – see Section 4.1.3 Kanji Portlet on page 22.

X11Gate Settings Reloader – see X11Gate Settings Reloader on page 26.

4.1.1 X11Gate Session Manager

Figure 19: X11Gate Session Manager

The options in the top right of the portlet allow you to view the portlet or a help for it, edit it (only in the Kanji portlet, see Section 4.1.3 Kanji Portlet on page 22) or minimize/maximize the portlet.

Session state – which session types are to be displayed in the list (Active, Disconnected or Terminated).

Update speed – how often the list is refreshed. This can be 1, 2, 5 or 10 seconds or Paused. The list can also be refreshed manually by clicking the Refresh button to the right. The Play/Pause button toggles between active and inactive refresh.

Show entries – how many sessions are shown in the list.

Search – searches for currently viewable sessions.

20 Security Solutions by HOB

Page 21: HOB X11Gate Administration Guide · PDF fileThis guide is designed to provide system administrators with detailed information ... 4.4 HOB Portal Options ... CentOS Release 6.5

HOB X11Gate Configuring HOB X11Gate

Click a session in the X11Gate Session Manager (see Figure 19 on page 20) to view detailed information about it.

Figure 20: Session Information

Select the Checkbox at the top to remove highlighting from the session information bar. Click the Refresh symbol to retrieve the newest information for the session. Here you can also disconnect or terminate a session by using the buttons at the bottom of the screen. Click OK when finished to close the window.

4.1.2 X11Gate Log Viewer

Figure 21: X11Gate Log Viewer

Here you have the following options:

Log file – there are two types of log files to choose from: the X11Gate log file and the clipboard log file. Click Download to download the logfiles.

Load – determines the number of log messages to be loaded.

Security Solutions by HOB 21

Page 22: HOB X11Gate Administration Guide · PDF fileThis guide is designed to provide system administrators with detailed information ... 4.4 HOB Portal Options ... CentOS Release 6.5

Configuring HOB X11Gate HOB X11Gate

Start from entry – specifies from where in the log file (the line number) to start loading.

Filter – filter log entries according to keywords. Select Clear to clear the log or Load to load the entire log.

Lock scrolling – activates/deactivates scrolling in the log.

4.1.3 Kanji Portlet

Figure 22: Kanji Portlet

Here you can see the base path. Select the Define paths for Kanji and XML files link. The following information is displayed.

Figure 23: Kanji Settings

Select Add to add a path to the list. The following dialog appears.

Figure 24: Add Path

Enter the path for the Kanji and XML files. Then select OK. The Kanji portlet now shows the path (see Figure 25 on page 23). The default path is /opt/HOB/x11gate2/bin.

22 Security Solutions by HOB

Page 23: HOB X11Gate Administration Guide · PDF fileThis guide is designed to provide system administrators with detailed information ... 4.4 HOB Portal Options ... CentOS Release 6.5

HOB X11Gate Configuring HOB X11Gate

Figure 25: Kanji Configuration

Click Configure to access the Kanji configuration.

Figure 26: Connection

Configuration node – there are 5 nodes:

Connection – see Connection on page 24.

SSH – see SSH on page 24.

Internals – see Internals on page 25.

Application service – see Application Service on page 25.

Whitelist – see Whitelist on page 26.

Security Solutions by HOB 23

Page 24: HOB X11Gate Administration Guide · PDF fileThis guide is designed to provide system administrators with detailed information ... 4.4 HOB Portal Options ... CentOS Release 6.5

Configuring HOB X11Gate HOB X11Gate

Connection

RDP port – enter the number of the port to be used for the connection.

Disconnection timeout – enter the number of minutes to be waited before disconnected sessions are timed out.

Display refresh rate – enter the rate at which the display is to be refreshed.

Startup application – enter the application to be opened when the session is started.

Startup display ID – enter an ID for the startup display.

At the top of every Kanji configuration screen there are 5 buttons:

SSH

Select SSH from the dropdown list on the Connection screen (see Figure 26 on page 23). The following screen is displayed:

Figure 27: SSH

Here you can decide whether or not SSH messages should be logged to the console, i.e. displayed in the X11Gate Log Viewer (see Figure 21 on page 21). This could be useful, for example, in the event of problems with the user authentication. By default, these messages do not need to be logged.

Save – saves the configuration.

Save anyway – saves the information for the HOB Portal anyway even if it is invalid.

Reset – resets the settings to the default configuration settings.

Clear – completely clears all changes made to the configuration.

Validate – checks whether or not the information entered for the HOB Portal is valid.

24 Security Solutions by HOB

Page 25: HOB X11Gate Administration Guide · PDF fileThis guide is designed to provide system administrators with detailed information ... 4.4 HOB Portal Options ... CentOS Release 6.5

HOB X11Gate Configuring HOB X11Gate

Internals

Select Internals from the dropdown list on the Connection screen (see Figure 26 on page 23).

Figure 28: Internals

Here you can set the following:

Logfiles maximum size – set the maximum size for logfiles.

House keeping interval – set the time interval between internal operations such as cleaning memory resources, terminating timed out sessions, etc.

Clipboard selection type – set the clipboard selection type (Primary or Clipboard).

Application Service

Select Application service from the dropdown list on the Connection screen.

Figure 29: Application Service

Here you set the port where the X11Gate Portal and the X11Gate communicate. The default is 9900.

Security Solutions by HOB 25

Page 26: HOB X11Gate Administration Guide · PDF fileThis guide is designed to provide system administrators with detailed information ... 4.4 HOB Portal Options ... CentOS Release 6.5

Configuring HOB X11Gate HOB X11Gate

Whitelist

Select Whitelist from the dropdown list on the Connection screen (see Figure 26 on page 23).

Figure 30: Whitelist

This is a list of the users that have access to the X11Gate. Select New to add new users, groups or domains to the list, select Clone to copy an entry in the list or Remove to delete an entry in the list.

Entry

Select and entry in the list and the name of the entry and the type of the entry will be displayed in the Name and Type fields.

4.1.4 X11Gate Settings Reloader

Figure 31: X11Gate Settings Reloader

Click the Reload Settings button to reload the setting after any changes have been made.

It is necessary to reload the settings after any changes have been made for them to be applied to the current configuration.

26 Security Solutions by HOB

Page 27: HOB X11Gate Administration Guide · PDF fileThis guide is designed to provide system administrators with detailed information ... 4.4 HOB Portal Options ... CentOS Release 6.5

HOB X11Gate Configuring HOB X11Gate

4.2 Management Portal

In the Management Portal you can create and view graphs, settings and close sessions or the HOB X11Gate itself.

Figure 32: Management Portal

The Management Portal consists of two portlets:

X11Gate Graph Viewer – see X11Gate Graph Viewer on page 28.

X11Gate Management – see X11Gate Management on page 28.

Security Solutions by HOB 27

Page 28: HOB X11Gate Administration Guide · PDF fileThis guide is designed to provide system administrators with detailed information ... 4.4 HOB Portal Options ... CentOS Release 6.5

Configuring HOB X11Gate HOB X11Gate

X11Gate Graph Viewer

Select Add Graph on the Management Portal screen (see Figure 32 on page 27) and then enter a title, select a function and then click Add graph to create a graph. Here you can create a graph displaying active sessions, disconnected sessions, terminated sessions or total data sent.

Figure 33: Graph Example

Here you can set a refresh rate, show markers and fill the colored area.

X11Gate Management

On the Management Portal screen (see Figure 32 on page 27), you have an overview of the ports in use, the RPC version and license validity. You can use the Refresh button on the left to update this information.

On the right you have two options:

X11Gate Controls

Here you can close all sessions and not accept further connections or keep accepting connections or you can shut down the X11Gate entirely.

X11Gate Settings

Here you have the option Reload Settings, which updates and settings changes you have made in the different portals. Settings are not saved/applied until Reload Settings has been selected.

28 Security Solutions by HOB

Page 29: HOB X11Gate Administration Guide · PDF fileThis guide is designed to provide system administrators with detailed information ... 4.4 HOB Portal Options ... CentOS Release 6.5

HOB X11Gate Configuring HOB X11Gate

4.3 License Portal

In the License Portal, you can manage any licenses you have.

Figure 34: License Portal

In the top half of the X11Gate License Management portlet, the Serial number, Key and Status of the license are displayed.

You can enter in a new serial number and a new key at the bottom of the screen. After entering the information, select Renew License to renew your license.

4.4 HOB Portal Options

You can access additional options for the HOB Portal by selecting the symbol in the top right corner. Here you have the following options:

Open the console

Change your password

Log off

As it is important that you immediately change your password after first accessing the HOB Portal, select Change password to display the following screen.

Figure 35: Change Password

Security Solutions by HOB 29

Page 30: HOB X11Gate Administration Guide · PDF fileThis guide is designed to provide system administrators with detailed information ... 4.4 HOB Portal Options ... CentOS Release 6.5

Configuring HOB X11Gate HOB X11Gate

Enter your current password, your new password and then confirm the new password. Select Save to complete the change.

30 Security Solutions by HOB

Page 31: HOB X11Gate Administration Guide · PDF fileThis guide is designed to provide system administrators with detailed information ... 4.4 HOB Portal Options ... CentOS Release 6.5

HOB X11Gate Configuring HOBLink JWT

5 Configuring HOBLink JWTNow that the installation and configuration are complete on the Linux/Unix server, the connection to the client must be configured. The configuration of HOBLink JWT is described in this section; however, Microsoft RDP client software can also be used. In this case, refer to the client software with regards to configuration but use the settings described below. Once complete, HOBLink JWT can connect to the Linux/Unix server to display the desktop.

1. Go to the Start menu, the Apps view and open HOBLink JWT Session Center (if you are using Windows 8, for example).

2. Right-click a session and select Edit....

3. Select the Connection scheme.

Figure 36: Connection Scheme

4. For Connection type, select Direct.

5. Deselect the Choose RD server at runtime checkbox. This ensures that the Linux/Unix server running HOB X11Gate is selected as the desired server.

6. For RD server, enter the IP address or the DNS name of the X Server to be connected to (e.g. Companyserver1).

7. For Port, enter the number of the port to be used (default: 3389). If you have entered a different port number in the HOB X11Gate configuration (see Section 4 Configuring HOB X11Gate on page 19), then that port number must be entered here.

8. Click OK to apply the settings.

The connection is now configured, and HOBLink JWT can now connect to the Linux/Unix server.

Security Solutions by HOB 31

Page 32: HOB X11Gate Administration Guide · PDF fileThis guide is designed to provide system administrators with detailed information ... 4.4 HOB Portal Options ... CentOS Release 6.5

Configuring HOBLink JWT HOB X11Gate

32 Security Solutions by HOB

Page 33: HOB X11Gate Administration Guide · PDF fileThis guide is designed to provide system administrators with detailed information ... 4.4 HOB Portal Options ... CentOS Release 6.5

HOB X11Gate Combining HOB X11Gate with HOB RD VPN

6 Combining HOB X11Gate with HOB RD VPNHOB X11Gate can be combined with HOB RD VPN to offer a high performance solution for secure remote access to the applications and data on the Linux/Unix server.

The steps described in the following sections enable RDP communication to take place between the two computers. For this, the HOB WebSecureProxy (HOB WSP) component of HOB RD VPN is used. This is the secure system proxy that transmits and receives data between the machines in the network.

No extra configuration of HOB X11Gate is required to set it up to communicate with HOB RD VPN. Please refer to Section 4 Configuring HOB X11Gate on page 19 for all necessary configuration information.

6.1 Configuring a HOBLink JWT Session

The first step is to configure the client-side software so that it recognizes the new machine (the Linux/Unix server) that it is connected to. For explanation purposes, HOBLink JWT is described here.

Configuring the Connection with HOB RD VPN

1. Start a browser, go to HOB RD VPN Administration viahttps:// rdvpn.example.com and log on with a Domain Administration account.

2. Open HOB EA Administration (the administration component of HOB RD VPN). For information regarding where to find the HOB EA Administration, please see the HOB RD VPN Administration Guide.

3. Select the element of the hierarchy that you want to create a connection for (users, groups, etc.) and select Sessions > HOBLink J-Term/JWT > Configure. You can also right-click the an element and then select Configure > Sessions > HOBLink J-Term/JWT.

Security Solutions by HOB 33

Page 34: HOB X11Gate Administration Guide · PDF fileThis guide is designed to provide system administrators with detailed information ... 4.4 HOB Portal Options ... CentOS Release 6.5

Combining HOB X11Gate with HOB RD VPN HOB X11Gate

Figure 37: Opening HOBLink JWT Session Configuration in HOB RD VPN

4. The HOBLink JWT Administration screen is displayed. Select Schemes > Connection.

Figure 38: HOBLink JWT Administration – Connection Scheme

5. Click New to configure a new connection.

6. Enter an appropriate Scheme Name for the connection to HOB X11Gate, such as X11Gate. This should be a name consistent with the sessions you will perform once the program is fully configured.

34 Security Solutions by HOB

Page 35: HOB X11Gate Administration Guide · PDF fileThis guide is designed to provide system administrators with detailed information ... 4.4 HOB Portal Options ... CentOS Release 6.5

HOB X11Gate Combining HOB X11Gate with HOB RD VPN

7. Under Connection Type, select Direct. This sets up the client to communicate directly with the server and not go through other proxies.

8. Disable the Choose Terminal Server at runtime checkbox.This ensures that the Linux/Unix server running HOB X11Gate is selected as the desired server.

9. Under Terminal Server, enter the IP address or the host name of the Linux/Unix server to be connected to (e.g. Companyserver1). All servers have names in these two forms by which they are identified on the network, so either can be used here.

10. Under Port, enter the number of the port to be used for the connection. The default is 3389. If you have entered a different port number in the HOB X11Gate configuration (see Section 4 Configuring HOB X11Gate on page 19(, then that port number must be entered here.

11. In the WSP Server in case of HOB RD VPN configuration section, enter a server name you would like to connect to next to Server Name and keep the Prompt user when connecting checkbox unchecked.

12. The Proxy configuration should be configured only if your network requires http proxies in order to connect to the Linux/Unix server.

13. Click Close to apply the settings and close HOBLink JWT Session Editor.

The connection is now configured and HOBLink JWT can now connect to the Linux/Unix server.

6.2 Configuring WebSecureProxy

When using HOB X11Gate with HOB RD VPN, HOB WebSecureProxy needs to be configured to allow X11 communications. Proceed as follows:

1. Start a browser, go to HOB RD VPN Administration viahttps://rdvpn.example.com:10000 and log on with the Global Administration account.

2. Start the HOB EA Administration and open the HOB WebSecureProxy configuration.

Note that example in the browser address above needs to be replaced with the name of the server where HOB RD VPN is installed.

Security Solutions by HOB 35

Page 36: HOB X11Gate Administration Guide · PDF fileThis guide is designed to provide system administrators with detailed information ... 4.4 HOB Portal Options ... CentOS Release 6.5

Combining HOB X11Gate with HOB RD VPN HOB X11Gate

Figure 39: HOB RD VPN WebSecureProxy Configuration

3. Select Outgoing Connections > RDP Targets > Add to add a server to the server list.

Figure 40: Server Configuration in HOB RD VPN WebSecureProxy

4. In the Name field, enter a name (e.g. X11Gate). At this point, any appropriate name may be used. Click Add to display the HOB WSP Configuration screen.

36 Security Solutions by HOB

Page 37: HOB X11Gate Administration Guide · PDF fileThis guide is designed to provide system administrators with detailed information ... 4.4 HOB Portal Options ... CentOS Release 6.5

HOB X11Gate Combining HOB X11Gate with HOB RD VPN

Figure 41: HOB WSP Configuration

5. The Mode must be 1:1 Proxy Gateway. This sets up direct communication to the server.

6. Under Predefined protocol, select RDP Windows Terminal Server. This is a default protocol created to ensure that HOBLink JWT connects correctly to HOB X11Gate.

7. Under Host IP Address, enter either the IP address or host name of the Linux/Unix server to be connected to (e.g. Companyserver1).

8. Under Host port, enter the port number used for the connection to the Linux/Unix server (default: 3389). If you have entered a different port number in the HOB X11Gate configuration (see Section 4 Configuring HOB X11Gate on page 19), then that port number must be entered here.

9. Click File > Save from the main menu and close the HOB WebSecureProxy configuration.

There is no need to restart HOB RD VPN. The changes will take effect automatically. How long this will take depends on the power of your HOB RD VPN computer and the configuration.

Security Solutions by HOB 37

Page 38: HOB X11Gate Administration Guide · PDF fileThis guide is designed to provide system administrators with detailed information ... 4.4 HOB Portal Options ... CentOS Release 6.5

Combining HOB X11Gate with HOB RD VPN HOB X11Gate

38 Security Solutions by HOB

Page 39: HOB X11Gate Administration Guide · PDF fileThis guide is designed to provide system administrators with detailed information ... 4.4 HOB Portal Options ... CentOS Release 6.5

HOB X11Gate Configuring the Remote Desktop Connection

7 Configuring the Remote Desktop ConnectionIf using a standard RDP connection, the following configuration settings will be required. Microsoft Remote Desktop configuration is used as an example.

1. Select Start > Apps view > under Windows Accessories > Remote Desktop Connection.

Figure 42: Microsoft Remote Desktop Connection

2. Click Show Options to display further options.

Figure 43: Logon Tab

3. Select the Advanced tab and make sure that either Connect and don’t warn me or Warn me (default) is configured.

Security Solutions by HOB 39

Page 40: HOB X11Gate Administration Guide · PDF fileThis guide is designed to provide system administrators with detailed information ... 4.4 HOB Portal Options ... CentOS Release 6.5

Configuring the Remote Desktop Connection HOB X11Gate

Figure 44: Advanced Tab

4. Go back to the General tab (see Figure 43 on page 39) and enter the IP address or the host name of the Linux/Unix server in the Computer field.

5. Enter the User name of the Linux.

6. Enable the Allow me to save credentials check box. This is necessary as the system requires these credentials (User name and Password) and without these saved, the connection will fail.

7. Click Connect to establish the connection.

40 Security Solutions by HOB

Page 41: HOB X11Gate Administration Guide · PDF fileThis guide is designed to provide system administrators with detailed information ... 4.4 HOB Portal Options ... CentOS Release 6.5

HOB X11Gate Other HOB X11Gate Features

8 Other HOB X11Gate FeaturesHOB X11Gate also offers the following features.

8.1 Disconnected Session and Session Reconnect

If you disconnect, the session will be in a disconnected state. That means that the user can reconnect to the session and continue to work with it.

If a user reconnects in disconnected state to HOB X11Gate and, provided a disconnected session under the same user name and password exists, the session is reconnected automatically to the last disconnected session.

8.2 Other Options

HOB X11Gate offers the following options for the command line.

8.2.1 Command Line Options

The following usage message is displayed when you type execute x11gate from a terminal with the -help option:

HOB X11Gate 2.1 (671)Copyright (C) 2013, HOB GmbH & Co. KG. All rights reserved.

usage: x11gate [-c <settings file path>][-t <X11Gate port>][-d <start display ID>][-prodkey <serial no> <cd key>][-help]

8.2.2 Scripts Provided

The following scripts are provided in order to launch HOB X11Gate and the X11Gate Portal (see Section 4.1 X11Gate Portal on page 19) or to run them as a service, some modifications could be necessary to adapt them to your particular system.

You can view and/or reset disconnected sessions in the X11Gate Session Manager (see Section 4.1.1 X11Gate Session Manager on page 20) of the HOB X11Gate Administration.

-c forces HOB X11Gate to use the settings file specified by the parameter.

-t forces HOB X11Gate to use the port specified in the command line.

-d forces HOB X11Gate to assign the specified number as the display ID for the first session connected.

-prodkey changes the license key of HOB X11Gate. This parameter should not be used in combination with others.

Note: this procedure can also be done through the Management Portal (see Section 4.2 Management Portal on page 27).

-help displays the usage parameters for HOB X11Gate.

Security Solutions by HOB 41

Page 42: HOB X11Gate Administration Guide · PDF fileThis guide is designed to provide system administrators with detailed information ... 4.4 HOB Portal Options ... CentOS Release 6.5

Other HOB X11Gate Features HOB X11Gate

run_hobx11gate.shThis script can be used to launch HOB X11Gate and the X11Gate Portal manually.

x11gate.conf and x11gate_webservices.confThese scripts are added automatically if the system supports Upstart to the /etc/init folder and if you choose during installation time to run HOB X11Gate as a service; if this was not the case, you can add them manually to the aforementioned folder.

x11gate and x11gate_webservicesThese scripts are added automatically if the system supports only SystemV to the /etc/init.d folder and if you choose during installation time to run HOB X11Gate as a service; if this was not the case, you can add them manually to the aforementioned folder.

8.2.3 Configuring the Java Path following Installation

If, during installation, there was no valid version of a Java Runtime Environment as specified in Section 2 System Requirements on page 9 and you chose to continue with the installation and to configure it later, this is possible by adding the path to the configuration of the web server included within the HOB X11Gate installation.

This can be done uncommenting the following line in<installdir>/webservices/bin/setenv.sh, and adding the route to the suitable Java folder:

# export JAVA_HOME=/custom/route/to/jre1.7.xxx

As an example, if the root folder of the JRE (or JDK) is in/usr/bin/jre1.7.0_60, the previous line should be:

export JAVA_HOME=/usr/bin/jre1.7.0_60

42 Security Solutions by HOB

Page 43: HOB X11Gate Administration Guide · PDF fileThis guide is designed to provide system administrators with detailed information ... 4.4 HOB Portal Options ... CentOS Release 6.5

HOB X11Gate Information and Support

9 Information and SupportIf you would like further information about HOB X11Gate or if you need product support, please contact us at:

U.S.A. and Canada

General Enquiries:

Phone: + 1 866 914 9970

Fax: + 49 9103 715 3299

E-mail: [email protected]

Web: www.hobsoft.com

Technical Support:

Phone: + 1 866 914 9970

Fax: + 49 9103 715 3299

E-mail: [email protected]

Germany

General Enquiries:

Phone: + 49 9103 715 0

Fax: + 49 9103 715 3271

E-mail: [email protected]

Web: www.hob.de

Technical Support:

Phone: + 49 9103 715 3161

Fax: + 49 9103 715 3299

E-mail: [email protected]

Other Countries

General Enquiries:

Phone: + 49 9103 715 3103

Fax: + 49 9103 715 3299

E-mail: [email protected]

Web: www.hobsoft.com

Technical Support:

Phone: + 49 9103 715 3103

Fax: + 49 9103 715 3299

E-mail: [email protected]

Security Solutions by HOB 43