3.0.1
Table Of Contents
- Administration Guide
- Contents
- About This Book
- Introduction
- Installation
- View Administrator
- Virtual Desktop Deployment
- Client Management
- View Client and View Portal
- Client Connections from the Internet
- Creating SSL Server Certificates
- Using Existing SSL Certificates
- Smart Card Authentication
- RSA SecurID Authentication
- View Client Command Line Options
- Virtual Printing
- View Composer
- Offline Desktop
- Component Policies
- Unified Access
- Troubleshooting
- Glossary
- Index
View Manager Administration Guide
34 VMware, Inc.
Toallowexternalclientdevicestoconnecttoasecurityserverwit hintheDMZ,the
front‐endfirewallmustallowinboundtrafficonTCPports80and443.Toallowthe
securityservertocommunicatewitheachstandardorreplicaserverthatresideswithin
theinternalnetwork,theback‐endfirewallmu
stallowinboundtrafficonTCPport
8009forAJP13‐forwardedWebtraffic,TCPport4001forJavaMessageService(JMS)
traffic,andTCPport3389forRDPtraffic.
Behindtheback‐endfirewall,internalfirewallsmustbesimilarlyconfiguredinorder
toallowtheViewManagerdesktopsandViewConnectionServ
erinstancesto
communicatewitheachother.Port3389(RDP)isusedfortrafficoriginatingfroma
standardorreplicaserverthatisdirectedataguestsystem.Port4001isusedforJMS
trafficoriginatingfromeithertheViewAgentcomponentinstalledoneachView
Managerdesktoporfromasecu
rityserverintheDMZ,andisdirectedatstandardor
replicaViewConnectionServerinstances.
Theback‐endandfront‐endfirewallrulesaresummarizedinTable 2‐1.
External URL
Bydefault,thefully‐qualifieddomainname(FQDN)ofthehostisrequiredbyView
ClientinordertoestablishaconnectionwithViewConnectionServer.Thisinformation
willnotbeavailabletoclientswhoattempttocontacttheserverfromoutsideyour
networkenvironment.
Referto“ClientConnectionsfromtheIn
ternet”onpage 71forinformationonhowto
addanexternalURLtoasecurityservertomakeitaccessiblefromtheInternet.
Table 2-1. Firewall Rules
Firewall Type TCP Port Protocol Source Destination
Front‐end 80 HTTP Any Securityserver
443 HTTPS
Back‐end 3389 RDPSecurityserver Anydesktopvirtualmachine
4001 JMSStandardorreplicaserver
8009 AJP13
4001 JMSAnydesktopVM