The Ultimate Citrix Install Guide
 
PROJECT MANAGEMENT
1. Project Management Overview
2. Project Management Methodology
3. Tips for Making Meetings Effective

ANALYSIS PHASE
1. Analysis Phase Overview
2. Vision / Project Scope (Statement of Work)
3. Project Plan
4. Infrastructure Assessment
5. Proof of Concept
6. Analysis Phase Checkpoint

DESIGN PHASE
1. Design Phase Overview
2. Server Design
3. MetaFrame Access Suite Design
4. Infrastructure Design
5. Design Phase Checkpoint

IMPLEMENTATION PHASE
1. Implementation Phase Overview

2. Prepare the Network Environment

2. 1. Create Required Network Shares
2. 2. Firewall Modifications
2. 3. Throttling Port Speed and Duplex Settings
2. 4. Add Users to a Terminal Services Environment
2. 5. Create Required Citrix Specific User Groups

3. Install Operating System(s) for MetaFrame XP

3. 1. Installing Microsoft Windows 2000
3. 2. Installing Microsoft Windows Server 2003

4. MetaFrame IMA Data Store Installation & Configuration

4. 1. How to Install & Configure Microsoft SQL Server 2000
4. 2. How to Install and Configure Microsoft SQL Desktop Edition (MSDE)

5. Install MetaFrame XP Server w/ Feature Release 3

5. 1. How to Remap MetaFrame XP Server Driver Letters
5. 2. Installing MetaFrame Feature Release 3 on Windows 2000
5. 3. Installing MetaFrame Feature Release 3 on Windows Server 2003
5. 4. Installing MetaFrame XP HotFixes
5. 5. How to Add Licenses through the Management Console for MetaFrame XP

6. Install “Image” Applications


7. Rapid Server Deployment

7. 1. How to Clone a Citrix MetaFrame XP Server
7. 2. How to Create a Network Boot Disk

8. Configure MetaFrame XP Farm Wide Settings

8. 1. Recycling Operating Systems
8. 2. MetaFrame XP Delegated Administration
8. 3. How to Create a Zone & Move MetaFrame XP Servers to it
8. 4. How to Set a Server’s Preference for Data Collector Elections
8. 5. MetaFrame XP User Policies
8. 6. How to Implement Automatic ICA Client Updates
8. 7. Client Drive Mapping
8. 8. How to Implement Client to Server Content Redirection
8. 9. How to Implement Server to Client Content Redirection
8. 10. Configure ICA Keep-Alive
8. 11. Configure SpeedScreen Browser Acceleration

9. Install “Manual” Applications

9. 1. How to Install and Configure Microsoft Office 2000
9. 2. How to Install and Configure Microsoft Office XP
9. 3. How to Install and Configure Microsoft Office 2003

10. MetaFrame Conferencing Manager 2.0

10. 1. How to Install the Conference Organizer Service
10. 2. How to Install the Conference Room
10. 3. How to Install Conferencing Manager User Interface
10. 4. How to Specify the License Type through the CM Configuration Tool
10. 5. How to Add Users to the Conferencing Manager
10. 6. Microsoft Exchange Server Integration
10. 7. Troubleshooting

11. Publishing Resources through the Management Console

11. 1. How to Publish an Application
11. 2. How to Publish Content
11. 3. How to Publish Application from a Shortcut
11. 4. How to Publish the Printer Folder
11. 5. How to Publish Windows Explorer

12. How to Configure the Printing Environment

12. 1. Set the proper expectations
12. 2. Setup the Print Environment
12. 3. Create Printer Compatibility Driver Mappings
12. 4. Set Printer Bandwidth Limits for Client Auto-Created Printers
12. 5. How to use Project Compatibility automate Driver Mapping
12. 6. How to Manually Connect a Client Printer within an ICA Session

13. Install MetaFrame Secure Access Manager 2.0

13. 1. Install MetaFrame Secure Access Manager on Windows 2000 Server
13. 2. Install MetaFrame Secure Access Manager 2.0 on Windows Server 2003
13. 3. How to Install MetaFrame Secure Access Manager 2.0 Service Pack 1
13. 4. Install the Access Management Console on MetaFrame XP or a Workstation
13. 5. Create an Access Center
13. 6. Configure the Access Center
13. 7. Customizing MetaFrame Secure Access Manager
13. 8. How to Configure Internet Explorer for a Secure Access Center

14. Install Web Interface 2.1

14. 1. How to Install Web Interface 2.1 (Clean Install)
14. 2. How to Upgrade a NFuse Server to Web Interface 2.1
14. 3. Web Interface 2.1 Web Administration Tool
14. 4. How to Customize Web Interface 2.1
14. 5. How to Repair Web Interface 2.1

15. Install SSL Certificates and Secure IIS Server

15. 1. How to install and configure the IIS Lockdown Tool (version 2.1)
15. 2. How to Enable SSL on an IIS Web Server
15. 3. How to Force the use of SSL Encryption on a IIS Web Site

16. Install Secure Gateway 2.0 for MetaFrame

16. 1. Pre-installation Check List
16. 2. How to Install and Configure the STA Component
16. 3. Install the Secure Gateway Service
16. 4. Secure Gateway for MetaFrame Management Tools

17. MetaFrame XP Remote Administration Tools

17. 1. Management Console for MetaFrame XP
17. 2. Citrix Web Console (CWC)

18. ICA Clients

18. 1. How to Install the ICA Win32 Program Neighborhood Agent
18. 2. How to Install the ICA Win32 Web Client
18. 3. How to Configure the ICA Java Client
18. 4. How to Utilize the ICA Program Neighborhood Pass-Through Client
18. 5. Citrix ICA Client 6.20 for OS 9.X
18. 6. Citrix ICA Client 6.30 for OS 10.x

19. Microsoft Terminal Services Licensing

19. 1. Summary of Licensing Options in Windows 2000 Server
19. 2. Summary of the licensing options in Microsoft Windows Server 2003

20. Implement Windows System Policies

20. 1. MIAB Administrative Template Overview
20. 2. How to Create an Administrative Template to Hide Drives
20. 3. Implementing Windows 2000 Active Directory Group Policies
20. 4. Implementing Windows NT, Terminal Server 4.0 System Policies

21. How to Install and Configure MetaFrame Password Manager

21. 1. Prepare the Directory Service
21. 2. Install and Configure the MetaFrame Password Manager Console
21. 3. Deploy the MetaFrame Password Manager Agent
21. 4. On-Going Maintenance

22. Implementation Phase Checkpoint


READINESS PHASE
1. Readiness Phase Overview
2. Testing your New MetaFrame Access Suite Environment
3. Pilot Implementation
4. Rollout Any Remaining Servers
5. Implement Change Management Policies and Procedures
6. Readiness Phase Checkpoint

ROLLOUT PHASE
1. Rollout Phase Overview
2. End-User Training
3. Administrator Training
4. Go Live!
5. Rollout Phase Checkpoint

APPENDIX
1. Additional Resources
2. MIAB3.0.ZIP - Files Explained

20. 3.    Implementing Windows 2000 Active Directory Group Policies

Group Policies give you the means of controlling what users and computers can do when logged on. You can do this by controlling their desktop, network connections and user interface. You do this to ensure that users have what they need to perform their jobs, but do not have the ability to corrupt or incorrectly configure their environment.

Group Policy applies to the user or computer in a manner that depends on where both the user and the computer objects are located in Active Directory. However, in a MetaFrame XP environment you need policies applied to just the MetaFrame XP Servers and the users who log in to them based on the location of the computer object alone. You can use the Group Policy loopback feature to apply Group Policy Objects (GPOs) that depend only on which computer the user logs on to.

This policy directs the system to apply the set of GPOs for the computer to any user who logs on to a computer affected by this policy.

With the Group Policy loopback policy, you can specify two other ways to retrieve the list of GPOs for any user of the computers in this specific OU.

        Merge Mode - In this mode, when the user logs on, the user's list of GPOs is gathered normally by using the GetGPOList function. The GetGPOList function is then called again, using the computer's location in Active Directory. The list of GPOs for the computer is then added to the end of the GPOs for the user. This causes the computer's GPOs to have higher precedence than the user's GPOs. In this example, the list of GPOs for the computer is added to the user's list.

        Replace Mode - In this mode, the user's list of GPOs is not gathered. Only the list of GPOs based on the computer object is used.

NOTE: Loopback is supported only in a purely Windows 2000based environment. Both the computer account and the user account must be in Active Directory. If either account is managed by a Microsoft Windows NT 4.0based domain controller, loopback does not function. The client computer must be a Windows 2000based computer.

 

For more information, please refer to the Microsofts support web site.

Step-by-Step Guide to Understanding the Group Policy Feature Set

http://www.microsoft.com/windows2000/techinfo/planning/management/groupsteps.asp

 

 

The following sections will describe how to prepare the Active Directory and create Group policies.

 

 

 


20. 3. 1 Prepare the Active Directory Environment

When MetaFrame XP Servers are in a Windows 2000 Active Directory domain, the domain administrator needs to implement Group Policy Objects (GPOs) that affect only the MetaFrame XP Servers to control the user environment. The following describes the recommended process of applying GPOs to MetaFrame XP Servers without adversely affecting other Windows 2000 servers and workstations on the network.

The first option is to create an organizational unit (OU) specifically for the MetaFrame XP Servers in Application Server mode. This OU allows specific GPOs to be applied to only those MetaFrame XP Servers and computers, creating a tightly controlled MetaFrame XP experience for the users without affecting the other servers and workstations in the Active Directory domain. This OU should not contain users or other computers; therefore, domain administrators can fine-tune the MetaFrame XP experience. The OU can also be delegated for control to subordinate groups such as server operators or individual users.

To create a new OU for the MetaFrame XP Servers, follow these steps:

 

1.      Click Start click Programs click Administrative Tools Click Active Directory Users and Computer and click Action New Organizational Unit.

 


2.      Enter the name for the OU that will house you Citrix MetaFrame XP Servers. Click OK

 

3.      You are now ready to move the desired MetaFrame XP Servers to the newly created OU. Locate the MetaFrame XP Server in question (located in the Servers or Computers OU). Right click on the desired server and click Move.


4.      Click the newly created OU dedicated for MetaFrame XP Servers and click OK.

5.      From the MetaFrame XP Server console of the server(s) added to the newly created OU click Start click Run type: MMC and click OK.

6.      Click Add/Remove Snap-In


7.      The Add/Remove Snap-In box opens and click Add.

8.      Click to select Group Policy and click Add.

 

9.      Click Finish

 

10. Click Close

11. Click OK

12. Open the Local Computer Policy and drill down to: Computer Configuration Administrative Templates System Group Policy folder and doube click to select User Group Policy loopback processing mode.

13. Click to select the Enabled radio button and click OK.

14. Repeat steps 3 and 4 for every MetaFrame XP Server running in Application mode.

You are now ready to create group policies to customize and lockdown the user environment and experience.


20. 3. 2 How to Add / Edit Group Policies

For the purpose of example, the following illustrates how to create a Group Policy made up of miscellaneous changes along with the MIAB.ADM file.

 

1.      Right click on the OU created above and click Properties

2.      Click New


3.      Give a name to the newly created Group Policy Object.

1.      Click Properties assign users / groups to be assigned to the GPO. As you see in this example I have given deny access to to the CTX Admins group to verfiy the the policy will not be implemented and have applied the GPO to the CTX Users group.

 

2.      Click OK with finished.


3.      Double click on the newly created Group Policy Object to open and edit the group policies.

NOTE: Most of the relevant settings are under Computer Configuration, Security Settings, or Local Policies. For example, under User Rights Assignment in the list on the right, you find Log on Locally, which is required for logging on to a session on Terminal Services; and you find Access this computer from the network, which is required to connect to the server outside of a MetaFrame XP session. This is also where you can prevent users from being able to shut down the system and other functions.

4.      If you will be adding or removing an Administrative Template you will need to right click on Administrative Templates and click Add/Remove Templates.


5.      The Add/Remove Templates windows opens and you are able to add or remove the desired template. For this example we will be adding the MIAB.ADM file. Click Add to add a customer Administrative Template.

6.      Browse to the location of the MIAB.ADM file found in the Methodology in a Box download and click Open.

7.      Click Close.


8.      Reopen the Group Policy and click the Administrative Templates folder in User Configuration section of the policy. Click View from the action menu bar and uncheck Show Polices Only.

 

9.      Due to a bug in Users and Computer you will need to close down the policy and reopen it.

10. You will now find a Project in a Box v.2.0 section in both the Computer Configuration and User Configuration sections of the Group Policy tool. The following are the four different pages of configuration settings found in MIAB.ADM.

+ Computer Configuration Administrative Templates Project in a Box v.2.0

+ Computer Configuration Administrative Templates Project in a Box v2.0 User Override on Win Station

 

+ User Configuration Administrative Templates Project in a Box v2.0

 

 

 

+ User Configuration Administrative Templates Project in a Box v2.0 SAP

11. Make the appropriate changes to the Group Policy Object and close the policy.

 

You have now successfully added MIAB.ADM and configured the settings. I highly recommend doing the same for a HideCalc ADM file as documented below. This will give you a wider selection of drives to hide (including not only the server drive letters but also any Citrix related file shares).

 


DABCC Site Map | Legal Notice | Privacy Statement | All Rights Reserved for DABCC, Inc.