Citrix MetaFrame
Presentation Server 3.0
Codename – “Hudson”
Release Date – April 27, 2004
Douglas A. Brown
New Features
•
Lots of new and useful features
– Lots of new Presentation Server Features
– Lots of new Web Interface Features
– Lots of new Client Features
– A few new Secure Gateway Features
– A few new RM, IM, and NM Features
•
Not as big an architectural change as 1.8 -> XP
– License Server is the only architectural change
Architecture and
New Architecture / Administrative
Features
•
Enhanced Farm Scalability
•
Access Suite Management Console
•
Enhanced Delegated Administration
•
Enhanced Policies
Enhanced Farm Scalability
•
Validated up to 1000 servers in a farm
Access Suite Management Console
• Does not replace the existing Management Console
Enhanced Policies
•
Can throttle any virtual channel bandwidth (not just
printing)
– Client Drives
– Client Devices
– Custom Virtual Channels (i.e. Tricerat Screwdrivers)
•
Network printer behavior
– Client printer via ICA, or– Network printer via RPC
•
MetaFrame Password Manager settings
– Disable Password Manager
Enhanced Policies - Filtering
•
Additional filtering options:
–
Client IP Address
–
Client Name
–
Servers
Enhanced Policies - Filtering
•
Can use wildcards in filters
– i.e. Filter by Client Name: use WI_* as filter for users coming from Workspace Control-enabled WI site
•
Filter can allow or deny policy
•
Can mix allow and deny policies within same policy
– i.e. disable client drive mapping for “domain users” and deny policies to specific users within the “domain users” group
•
Supports anonymous and/or explicit user filtering
•
IP Addresses evaluated is the actual client IP
address
Zone Preference and Failover
•
Implemented as a Presentation Server policy
•
Good for distributed farms and ASPs
– Forces users to preferred zone for applications
– Lowest loaded server within that zone is used
•
Also useful for Disaster Recovery
– Backup zones (up to 10) can be specified
•
Works for PN Agent and WI connections
– Connections via PN and Conferencing Manager may be
MPS Certifications and Standards
Microsoft Certifications
Certified for Microsoft Windows
Windows Server 2003 (Standard, Enterprise, and Datacenter)
Windows 2000 Server (Server, Advanced, and Datacenter)
Designed for Windows XP Gold
Windows XP, 2000, ME, 98, NT
Designed for Windows Mobile
Windows Pocket PC, Windows CE
RSA Security Certifications
RSA SecurID Ready
Industry Regulations
FIPS 140-1
U.S. Rehabilitation Act Section 508
HIPAA
New End User / Access Features
• Workspace Control
• Web Interface
Enhancements
• RDP Support
• Enhanced PN Agent
• Enhanced Logon Feedback
• Bi-directional Audio
• SpeedScreen
Improvements
• Session Reliability
• Enhanced Tablet PC
Support
• Enhanced Java Client
• Secure Computing
SafeWord Support
• Section 508 Conformance
• Secure Gateway and Port
Workspace Control
•
“Follow me roaming” with WI or PN Agent
•
Requires latest versions of:
– Presentation Server Client
– Web Interface
– Presentation Server
•
Reconnects printers and client drives from new client
•
Can reconnect to a session, even if screen resolution
has changed
Workspace Control
•
1
•
2
Web Interface Improvements
• Can install to Non-default web site
• WI Ticketing done via IMA, not RPC/XML
• Icons are generated on the fly, not stored on disk
– Should alleviate missing icons syndrome
• Able to Hide disabled applications
• Asian Language Web Server Support
– Unicode format of ICA files
Web Interface Improvements
RDP Client Support from WI
•
More limited features than ICA
•
May be useful as a “client of last resort” for Windows
XP clients
Enhanced Logon Feedback
•
Better feedback to user on logon process
Bi-Directional Audio
•
Full stereo sound can travel from client to server
•
Support for:
– Headset microphones
– Philips SpeechMike (i.e. Medical Transcription)
• Serial port and USB versions supported
• Does not work with Workspace Control
•
Requires latest client and server
SpeedScreen Improvements
•
SpeedScreen Flash Acceleration
– Improves rendering of Macromedia Flash content on
published browsers by setting player to “low quality” playback by default.
•
SpeedScreen Multimedia Acceleration
– Streaming of video and audio data to the local device to leverage local content player resources.
•
SpeedScreen Image Acceleration
– Allows tradeoff of image quality for lower bandwidth
SpeedScreen Multimedia
Acceleration
Media Type (encoding) File Format (.ext) Windows Media Player 6.4/8.0/9.0 RealPlayer 8+ QuickTime Embedded DirectShow Based Players DIVX Video AVI MPEG MPG ASF X
XVID Video X
Microsoft Video 1 X
MPEG-1 Video X
MPEG-4 Video X
Indeo Interactive
Video X
MPEG-1 Audio X
AC3 Audio X
Fraunhofer MPEG
Layer-3 Codec X
MP3 MP3 * X X X
WMA WMA * X X X
WMV WMV X X X X
Real Media RM X X X X
Quick Time MOV X X X X
Session Reliability
•
Allows sessions to remain viewable when network
connectivity is interrupted
– Seamless windows can be moved/resized
•
Uses a configurable TCP port
– Noteworthy for some high-security networks
•
Requires latest version of
– Client
Enhanced Tablet PC Support
•
Can use “input panel”
(soft keyboard) for input
–
Including login screen
on ICA session
•
Voice input support
•
Support for display
mode switching
–
Landscape, Portrait
Java Client 8.0
• Printer auto detection
• Support for local root certificates
• Enhanced UI and seamless windows support
• New MPS feature support:
– universal printer driver (mono and 300dpi)
– SpeedScreen browser acceleration (MF XP FR3)
– SpeedScreen image and flash acceleration
– session reliability
– workspace control
– dynamic session reconfiguration
Secure Access Manager 2.2
•
Remote employees need
offline
access to email.
•
Need to support additional browser beyond
Microsoft’s Internet Explorer.
•
Desire to secure existing Enterprise Information Portal
(EIP) or other existing Web based infrastructure.
•
Challenges displaying Java based internal Web sites
and applications.
•
Challenges accessing internal Web sites with unique
verb sets, WebDAV enabled sites, etc…
MetaFrame Secure Access
Manager 2.2 delivers…
•
Alternative User Interface:
– Allows MetaFrame Secure Access Manager to direct users to
different EIPs or Web based infrastructures (other than the Access Center) immediately after authentication.
•
New
Advanced
Gateway Client, providing support for:
– Most common PC browsers (IE, Netscape, etc…)
– Synchronization of Outlook 2000+ clients
– Access to java based Web sites and applications
– Access to sites incorporating unique verb sets such as WebDAV enabled sites, Outlook Web Access, etc…
Conferencing Manager Evolution
•
Guest attendees
– Users that are not MetaFrame users or are not employees
•
Overall enhanced usability
– All users launching applications
– Attendee moderated mouse and keyboard control
– Request mouse/keyboard control
Guest Web Login
•
Friendly Name
•
Guest ID
– unique for each
– guest attendee
– E.g. email address
•
Conference ID
Adding attendees
•
Invite users
from the
domain,
Usability Improvements
• Set Mouse/KeyB Control
• Pass Mouse/KeyB Control
• Request Mouse/KeyB Control
Password Manager Architecture
vGOConfig vGO Client Settings vGO Enterprise Application Configs vGO FTU Settings People vGOSecrets user1 vGOConfig vGO Client Settings vGO Enterprise Application Configs vGO FTU Settings People vGOSecrets user1 vGOConfig vGO Client Settings vGO Enterprise Application Configs vGO FTU Settings People vGOSecrets user1 vGOConfig vGO Client Settings vGO Enterprise Application Configs vGO FTU Settings People vGOSecrets user1 Directoryor File share
Sync Push
MetaFrame and/or Desktop Deployed
SSO Agent
SSO Agent
Administration Console
MetaFrame Password Manager 2.5
New Features
•
Novell Authentication
– Works with Novell’s version of the Windows GINA
– Primary authentication against eDirectory (formerly NDS)
•
Support for Certificate-based (PKI) Smart Cards
•
Hot Desktop through compatibility with Workspace
Roaming
– No Primary Authentication logoff required
– Works only with MetaFrame Presentation Server 3.0
•
Workstation Lockout for Re-authentication
MetaFrame Password Manager 2.5
New Features
•
Localized Agent
– German, French, Spanish and Japanese
•
Drop-down Logon Menu Support
– Windows and Web based applications
– E.g.: Domain Drop Downs
•
Manual Password Change Policy Enforcement