6.2

Table Of Contents
3 Set the RedirectionPolicy value to always.
Value name = RedirectionPolicy
Value Type = REG_SZ
Value data = always
4 Restart Windows Media Player on the desktop to allow the updated value to take effect.
Managing Access to Client Drive Redirection
When you deploy Horizon Client 3.5 or later and View Agent 6.2 or later with client drive redirection
(CDR), folders and files are sent across the network with encryption. CDR connections between clients and
the View Secure Gateway and connections from the View Secure Gateway to desktop machines are secure.
With earlier client or View Agent releases, CDR folders and files are sent across the network without
encryption and might contain sensitive data, depending on the content being redirected. If the secure tunnel
is enabled, CDR connections between Horizon Clients and the View Secure Gateway are secure, but
connections from the View Secure Gateway to desktop machines are not encrypted. If the secure tunnel is
disabled, CDR connections from Horizon Clients to the desktop machines are not encrypted. To ensure that
this data cannot be monitored on the network, use CDR only on a secure network if Horizon Client is earlier
than version 3.5 or View Agent is earlier than version 6.2.
The Client Drive Redirection setup option in the View Agent installer is selected by default. As a best
practice, install the Client Drive Redirection setup option only in desktop pools where users require this
feature.
You can disable CDR by configuring a Microsoft Remote Desktop Services group policy setting in Active
Directory.
1 In the Group Policy Editor, go to Computer Configuration\Policies\Administrative
Templates\Windows Components\Remote Desktop Services\Remote Desktop Session Host\Device
and Resource Redirection.
This navigation path is for Active Directory on Windows Server 2012. The navigation path differs on
other Windows operating systems.
2 Enable the Do not allow drive redirection group policy setting.
NOTE If your View deployment includes a back-end firewall between your DMZ-based security servers and
your internal network, verify that the back-end firewall allows traffic to port 9427 on your single-user and
RDS desktops. TCP connections on port 9427 are required to support CDR.
Currently, this feature is supported on Horizon Client for Mac OS X, Horizon Client for Windows, and
Horizon Client for Linux. For more information, see the Using VMware Horizon Client document for the
specific type of desktop client device. Go to
https://www.vmware.com/support/viewclients/doc/viewclients_pubs.html.
Setting Up Desktop and Application Pools in View
188 VMware, Inc.