5.2

Table Of Contents
3 Configure use of the Blast Secure Gateway.
Option Description
Enable the Blast Secure Gateway
Select Use Blast Secure Gateway for HTML access to desktop
Disable the Blast secure Gateway
Deselect Use Blast Secure Gateway for HTML access to desktop
The Blast Secure Gateway is enabled by default.
4
Click OK to save your changes.
Open the Port Used by HTML Access on Security Servers
When you install View Connection Server or security server, the View server installer creates the Windows
Firewall rule for the port that is used by HTML Access for client connections, but the installer leaves the rule
disabled until it is actually needed. When you later install HTML Access on a View Connection Server instance,
the HTML Access installer automatically enables the rule to allow communication to that port. However, on
security servers, you must manually enable the rule in the Windows Firewall to allow communication to the
port.
By default, HTML Access uses TCP port 8443 for client connections to the Blast Secure Gateway.
Procedure
n
To open the port used by HTML Access on a View Connection Server computer, install HTML Access on
that computer.
The HTML Access installer enables the VMware View Connection Server (Blast-In) rule in the Windows
Firewall.
n
To open the port for HTML Access on a security server, manually enable the VMware View Connection
Server (Blast-In) rule in the Windows Firewall.
Off-load SSL Connections to Intermediate Servers
View Clients must use HTTPS to connect to View Manager. If your View Clients connect to load balancers or
other intermediate servers that pass on the connections to View Connection Server instances or security servers,
you can off-load SSL to the intermediate servers.
Import SSL Off-loading Servers' Certificates to View Servers
If you off-load SSL connections to an intermediate server, you must import the intermediate server's certificate
onto the View Connection Server instances or security servers that it is off-loading. The same SSL server
certificate must reside on both the off-loading intermediate server and the off-loaded View servers.
If the intermediate server's certificate is not installed on the View Connection Server instance or security server,
View Clients cannot validate their connections to View. In this situation, the certificate thumbprint sent by the
View server does not match the certificate on the intermediate server to which View Clients are connecting.
Do not confuse load balancing with SSL off-loading. The preceding requirement applies to any device that is
configured to provide SSL off-loading, including some types of load balancers. However, pure load balancing
does not require copying of certificates between devices.
For information about importing certificates to View servers, see "Import a Signed Server Certificate into a
Windows Certificate Store" in the VMware Horizon View Installation document.
Chapter 1 Configuring View Connection Server
VMware, Inc. 33