Administration

Table Of Contents
Do not confuse load balancing with TLS off-loading. The preceding requirement applies to any
device that is configured to provide TLS off-loading, including some types of load balancers.
However, pure load balancing does not require copying of certificates between devices.
For information about importing certificates to Horizon 7 servers, see "Import a Signed Server
Certificate into a Windows Certificate Store" in the
Horizon 7 Installation
document.
Set Horizon 7 Server External URLs to Point Clients to TLS Off-loading Servers
If TLS is off-loaded to an intermediate server and Horizon Client devices use the secure tunnel to
connect to Horizon 7, you must set the secure tunnel external URL to an address that clients can
use to access the intermediate server.
You configure the external URL settings on the Connection Server instance or security server that
connects to the intermediate server.
If you deploy security servers, external URLs are required for the security servers but not for the
Connection Server instances that are paired with the security servers.
If you do not deploy security servers, or if you have a mixed network environment with
some security servers and some external-facing Connection Server instances, External URLs are
required for any Connection Server instances that connect to the intermediate server.
Note You cannot off-load TLS connections from a PCoIP Secure Gateway (PSG) or Blast Secure
Gateway. The PCoIP external URL and Blast Secure Gateway external URL must allow clients to
connect to the computer that hosts the PSG and Blast Secure Gateway. Do not reset the PCoIP
external URL and Blast external URL to point to the intermediate server unless you plan to require
TLS connections between the intermediate server and the Horizon 7 server.
For information about configuring External URLs, see “Configuring External URLs for PCoIP
Secure Gateway and Tunnel Connections” in the
Horizon 7 Installation
document.
Allow HTTP Connections From Intermediate Servers
When TLS is off-loaded to an intermediate server, you can configure Connection Server instances
or security servers to allow HTTP connections from the client-facing, intermediate devices. The
intermediate devices must accept HTTPS for Horizon Client connections.
To allow HTTP connections between Horizon 7 servers and intermediate devices, you must
configure the locked.properties file on each Connection Server instance and security server
on which HTTP connections are allowed.
Even when HTTP connections between Horizon 7 servers and intermediate devices are allowed,
you cannot disable TLS in Horizon 7. Horizon 7 servers continue to accept HTTPS connections as
well as HTTP connections.
Note If your Horizon clients use smart card authentication, the clients must make HTTPS
connections directly to Connection Server or security server. TLS off-loading is not supported
with smart card authentication.
Horizon 7 Administration
VMware, Inc. 45