Administration

Table Of Contents
6 For RADIUS authentication, complete the rest of the fields:
a Select Use the same username and password for RADIUS and Windows authentication
if the initial RADIUS authentication uses Windows authentication that triggers an out-of-
band transmission of a token code, and this token code is used as part of a RADIUS
challenge.
If you select this check box, users will not be prompted for Windows credentials after
RADIUS authentication if the RADIUS authentication uses the Windows username and
password. Users do not have to reenter the Windows username and password after
RADIUS authentication.
b From the Authenticator drop-down list, select Create New Authenticator and complete
the page.
n Set Accounting port to 0 unless you want to enable RADIUS accounting. Set this port
to a non-zero number only if your RADIUS server supports collecting accounting data.
If the RADIUS server does not support accounting messages and you set this port to a
nonzero number, the messages will be sent and ignored and retried a number of times,
resulting in a delay in authentication.
Accounting data can be used in order to bill users based on usage time and data.
Accounting data can also be used for statistical purposes and for general network
monitoring.
n If you specify a realm prefix string, the string is placed at the beginning of the
username when it is sent to the RADIUS server. For example, if the username entered
in Horizon Client is jdoe and the realm prefix DOMAIN-A\ is specified, the username
DOMAIN-A\jdoe is sent to the RADIUS server. Similarly if you use the realm suffix, or
postfix, string @mycorp.com, the username jdoe@mycorp.com is sent to the RADIUS
server.
7 Click OK to save your changes.
You do not need to restart the Connection Server service. The necessary configuration files are
distributed automatically and the configuration settings take effect immediately.
Results
When users open Horizon Client and authenticate to Connection Server, they are prompted for
two-factor authentication. For RADIUS authentication, the login dialog box displays text prompts
that contain the token label you specified.
Changes to RADIUS authentication settings affect remote desktop and application sessions that
are started after the configuration is changed. Current sessions are not affected by changes to
RADIUS authentication settings.
What to do next
If you have a replicated group of Connection Server instances and you want to also set up RADIUS
authentication on them, you can re-use an existing RADIUS authenticator configuration.
Horizon 7 Administration
VMware, Inc. 73