6.0

Table Of Contents
3 Configure use of the Blast Secure Gateway.
Option Description
Enable the Blast Secure Gateway
Select Use Blast Secure Gateway for HTML access to machine
Disable the Blast secure Gateway
Deselect Use Blast Secure Gateway for HTML access to machine
The Blast Secure Gateway is enabled by default.
4 Click OK to save your changes.
Open the Port Used by HTML Access on Security Servers
When you install the HTML Access component during a View Connection Server installation, the installer
creates and enables a Windows Firewall rule to open the port that is used by HTML Access for client
connections. However, on security servers, you must manually enable the rule in Windows Firewall to
allow communication to the port.
By default, HTML Access uses TCP port 8443 for client connections to the Blast Secure Gateway.
Procedure
n
To open the port used by HTML Access on a View Connection Server computer, install HTML Access
with View Connection Server on that computer.
The installer enables the VMware View Connection Server (Blast-In) rule in Windows Firewall.
n
To open the port for HTML Access on a security server, manually enable the VMware View
Connection Server (Blast-In) rule in Windows Firewall.
Off-load SSL Connections to Intermediate Servers
Horizon Client must use HTTPS to connect to View. If your Horizon clients connect to load balancers or
other intermediate servers that pass on the connections to View Connection Server instances or security
servers, you can off-load SSL to the intermediate servers.
Import SSL Off-loading Servers' Certificates to View Servers
If you off-load SSL connections to an intermediate server, you must import the intermediate server's
certificate onto the View Connection Server instances or security servers that connect to the intermediate
server. The same SSL server certificate must reside on both the off-loading intermediate server and each off-
loaded View server that connects to the intermediate server.
If you deploy security servers, the intermediate server and the security servers that connect to it must have
the same SSL certificate. You do not have to install the same SSL certificate on View Connection Server
instances that are paired to the security servers and do not connect directly to the intermediate server.
If you do not deploy security servers, or if you have a mixed network environment with some security
servers and some external-facing View Connection Server instances, the intermediate server and any View
Connection Server instances that connect to it must have the same SSL certificate.
If the intermediate server's certificate is not installed on the View Connection Server instance or security
server, clients cannot validate their connections to View. In this situation, the certificate thumbprint sent by
the View server does not match the certificate on the intermediate server to which Horizon Client connects.
Do not confuse load balancing with SSL off-loading. The preceding requirement applies to any device that is
configured to provide SSL off-loading, including some types of load balancers. However, pure load
balancing does not require copying of certificates between devices.
For information about importing certificates to View servers, see "Import a Signed Server Certificate into a
Windows Certificate Store" in the View Installation document.
View Administration
36 VMware, Inc.