3.1
Table Of Contents
- View Manager Administration Guide
- Contents
- About This Book
- Introduction
- Installation
- View Administrator
- Virtual Desktop Deployment
- Client Management
- View Client and View Portal
- Client Connections from the Internet
- Creating SSL Server Certificates
- Using Existing SSL Certificates
- Smart Card Authentication
- RSA SecurID Authentication
- View Client Command Line Options
- Virtual Printing
- Adobe Flash Bandwidth Reduction
- Client Device Information
- Enabling HP RGS Display Protocol
- View Composer
- Overview of View Composer
- Preparing VirtualCenter for View Composer
- Preparing a Parent VM
- Deploying Linked Clone Desktops from View Manager
- Refreshing, Recomposing, and Rebalancing Linked Clone Desktops
- Using an Existing View Composer Database
- Using the SviConfig Tool for View Composer
- Offline Desktop
- Component Policies
- Unified Access
- Troubleshooting
- locked.properties
- Glossary
- Index
VMware, Inc. 35
Chapter 2 Installation
ToallowexternalclientdevicestoconnecttoasecurityserverwithintheDMZ,the
front‐endfirewallmustallowinboundtrafficonTCPports80and443.Toallowthe
securityservertocommunicatewitheachstandardorreplicaserverthatresideswithin
theinternalnetwork,theback‐endfirewall
mustallowinboundtrafficonTCP
port 8009forAJP13‐forwardedWebtrafficandTCPport4001forJavaMessageService
(JMS)traffic.
Behindtheback‐endfirewall,internalfirewallsmustbesimilarlyconfiguredinorder
toallowtheViewManagerdesktopsandViewConnectionServerinstancesto
communicatewitheach
other.Port4001isusedforJMStrafficoriginatingfromeither
theViewAgentcomponentinstalledoneachViewManagerdesktoporfromasecurity
serverintheDMZ,andisdirectedatstandardorreplicaViewConnectionServer
instances.
Inanyfirewallconfiguration,TCPports3389and32111areused
fortrafficbetween
ViewClientforWindowsandViewAgent,andbetweenthinclientsandViewAgent.
TCPport3389isusedforRDPtraffic.TCPport32111isusedforUSBdevicetraffic,to
enabletheclienttoinitiatesessionlogoff,andtopassadditionalinformationbetween
ViewAgentand
ViewClientforWindowsandthinclients.
FirewallrulesaresummarizedinTable 2‐1.
Table 2-1. Firewall Rules
Firewall
Type TCP Port Protocol Source Destination
Front‐end 80 HTTP
Any Securityserver
443 HTTPS
Back‐end 4001 JMS
Securityserver Standardorreplica
server
8009 AJP13
4001 JMS
ViewAgent
Any 3389 RDP
ViewClient(Windows
andthinclients)
32111 USB
3389 RDP
ViewClient(Windows
andthinclients)
ViewAgent
32111 USB