5.2

Table Of Contents
Figure 5-4. Dual Firewall Topology
View Client View Client
HTTPS
traffic
HTTPS
traffic
fault-tolerant
load balancing
mechanism
View
Security
Server
DMZ
internal
network
View
Connection
Server
View
Connection
Server
VMware
vCenter
Active
Directory
VMware
ESX servers
View
Security
Server
back-end
firewall
front-end
firewall
Firewall Rules for DMZ-Based Security Servers
DMZ-based security servers require certain firewall rules on the front-end and back-end firewalls. During
installation, Horizon View services are set up to listen on certain network ports by default. If necessary, to
comply with organization policies or to avoid contention, you can change which port numbers are used.
IMPORTANT For additional details and security recommendations, see the VMware Horizon View Security
document.
Front-End Firewall Rules
To allow external client devices to connect to a security server within the DMZ, the front-end firewall must
allow traffic on certain TCP and UDP ports. Table 5-1 summarizes the front-end firewall rules.
VMware Horizon View Architecture Planning
72 VMware, Inc.