User manual

Table Of Contents
of the secure tunnel external URL and the default port number, 8443. The URL must contain the FQDN and
port number that a client system can use to reach this View Connection Server host or security server host.
For more information, see "Set the External URLs for a View Connection Server Instance," in the View
Installation documentation.
N You can use HTML Access in conjunction with VMware Workspace Portal to allow users to connect
to their desktops from an HTML5 browser. For information about installing Workspace Portal and
conguring it for use with View Connection Server, see the Workspace Portal documentation. For
information about pairing View Connection Server with a SAML Authentication server, see the View
Administration documentation.
Firewall Rules for HTML Access
To allow client Web browsers to use HTML Access to make connections to security servers, View
Connection Server instances, and remote desktops, your rewalls must allow inbound trac on certain TCP
ports.
HTML Access connections must use HTTPS. HTTP connections are not allowed.
By default, when you install a View Connection Server instance or security server, the VMware Horizon
View Connection Server (Blast-In) rule is enabled in the Windows Firewall, so that the rewall is
automatically congured to allow inbound trac to TCP port 8443.
Table 11. Firewall Rules for HTML Access
Source
Default
Source
Port Protocol Target
Default
Target
Port Notes
Client Web
browser
TCP
Any
HTTPS Security
server or
View
Connection
Server
instance
TCP 443 To make the initial connection to View, the Web browser on a
client device connects to a security server or View Connection
Server instance on TCP port 443.
Client Web
browser
TCP
Any
HTTPS Blast Secure
Gateway
TCP 8443 After the initial connection to View is made, the Web browser
on a client device connects to the Blast Secure Gateway on
TCP port 8443. The Blast Secure Gateway must be enabled on
a security server or View Connection Server instance to allow
this second connection to take place.
Blast Secure
Gateway
TCP
Any
HTTPS HTML
Access agent
TCP
22443
If the Blast Secure Gateway is enabled, after the user selects a
remote desktop, the Blast Secure Gateway connects to the
HTML Access agent on TCP port 22443 on the desktop. This
agent component is included when you install View Agent.
Client Web
browser
TCP
Any
HTTPS HTML
Access agent
TCP
22443
If the Blast Secure Gateway is not enabled, after the user
selects a View desktop, the Web browser on a client device
makes a direct connection to the HTML Access agent on TCP
port 22443 on the desktop. This agent component is included
when you install View Agent.
Using HTML Access
10 VMware, Inc.