6.1

Table Of Contents
You can configure an initial security server pairing without using IPsec rules. Before you install the security
server, you can open View Administrator and deselect the global setting Use IPSec for Security Server
Connections, which is enabled by default. If IPsec rules are not in effect, you do not have to remove them
before you upgrade or reinstall.
NOTE You do not have to remove a security server from View Administrator before you upgrade or
reinstall the security server. Remove a security server from View Administrator only if you intend to
remove the security server permanently from the View environment.
With View 5.0.x and earlier releases, you could remove a security server either from within the View
Administrator user interface or by using the vdmadmin -S command-line command. In View 5.1 and later
releases, you must use vdmadmin -S. See "Removing the Entry for a View Connection Server Instance or
Security Server Using the -S Option" in the View Administration document.
CAUTION If you remove the IPsec rules for an active security server, all communication with the security
server is lost until you upgrade or reinstall the security server.
Procedure
1 In View Administrator, click View Configuration > Servers.
2 In the Security Servers tab, select a security server and click More Commands > Prepare for Upgrade
or Reinstallation.
If you disabled IPsec rules before you installed the security server, this setting is inactive. In this case,
you do not have to remove IPsec rules before you reinstall or upgrade.
3 Click OK.
The IPsec rules are removed and the Prepare for Upgrade or Reinstallation setting becomes inactive,
indicating that you can reinstall or upgrade the security server.
What to do next
Upgrade or reinstall security server.
Firewall Rules for View Connection Server
Certain ports must be opened on the firewall for View Connection Server instances and security servers.
When you install View Connection Server, the installation program can optionally configure the required
Windows Firewall rules for you. These rules open the ports that are used by default. If you change the
default ports after installation, you must manually configure Windows Firewall to allow Horizon Client
devices to connect to View through the updated ports.
If you choose to install HTML Access with View Connection Server, the installer configures the VMware
Horizon View Connection Server (Blast-In) rule in Windows Firewall to open TCP port 8443, used by
HTML Access.
The following table lists the default ports that can be opened automatically during installation. Ports are
incoming unless otherwise noted.
Table 64. Ports Opened During View Connection Server Installation
Protocol Ports View Connection Server Instance Type
JMS TCP 4001 Standard and replica
JMS TCP 4002 Standard and replica
JMSIR TCP 4100 Standard and replica
JMSIR TCP 4101 Standard and replica
Chapter 6 Installing View Connection Server
VMware, Inc. 65