6.1.1

Table Of Contents
Configuring the Linux Firewall to Allow Incoming TCP Connections
To allow users to connect to their Linux desktops, the desktops must be able to accept incoming TCP
connections from Horizon Client devices, security server, and View Connection Server.
On Ubuntu and Kylin distributions, the iptables firewall is configured by default with an input policy of
ACCEPT.
On RHEL and CentOS distributions, where possible, the View Agent installer script configures the iptables
firewall with an input policy of ACCEPT.
Make sure that iptables on a RHEL or CentOS guest operating system has an input policy of ACCEPT for
new connections from the Blast port, 5443.
When the BSG is enabled, client connections are directed from a Horizon Client device through the BSG on a
security server or View Connection Server to the Linux desktop. When the BSG is not enabled, connections
are made directly from the Horizon Client device to the Linux desktop.
Chapter 4 Administering Horizon 6 for Linux Desktops
VMware, Inc. 47