Client endpoints communicate with an Omnissa Horizon Connection Server host over secure connections.
The initial client connection, which is used for user authentication and remote desktop and application selection, is created over HTTPS when a user provides a domain name to Horizon Client. If firewall and load balancing software are configured correctly in your network environment, this request reaches the Horizon Connection Server host. With this connection, users are authenticated and a desktop or application is selected, but users have not yet connected to the remote desktop or application.
When users connect to remote desktops and applications, by default the client makes a second connection to the Horizon Connection Server host. This connection is called the tunnel connection because it provides a secure tunnel for carrying RDP and other data over HTTPS.
When users connect to remote desktops and applications with the PCoIP display protocol, the client can make a further connection to the PCoIP Secure Gateway on the Horizon Connection Server host. The PCoIP Secure Gateway ensures that only authenticated users can communicate with remote desktops and applications over PCoIP.
You can also provide secure connections to users connect to remote desktops and applications with the Omnissa Horizon Blast display protocol and to external users who use Omnissa Horizon Web Client to connect to remote desktops. The Blast Secure Gateway ensures that only authenticated users can communicate with remote desktops.
Note: Horizon Web Client is available with Horizon 8 versions 2412 and later. For Horizon 8 versions 2406 and earlier, Horizon Web Client is called "HTML Access." This documentation page uses the name "Horizon Web Client" to refer to both Horizon Web Client and HTML Access.
Depending on the type of client device being used, additional channels are established to carry other traffic such as USB redirection data to the client device. These data channels route traffic through the secure tunnel if it is enabled.
When the secure tunnel and secure gateways are disabled, desktop and application sessions are established directly between the client device and the remote machine, bypassing the Horizon Connection Server host. This type of connection is called a direct connection.
Desktop and application sessions that use direct connections remain connected even if Horizon Connection Server is no longer running.
Typically, to provide secure connections for external clients that connect to a Horizon Connection Server host over a WAN, you enable the secure tunnel, the PCoIP Secure Gateway, and the Blast Secure Gateway. You can disable the secure tunnel and the secure gateways to allow internal, LAN-connected clients to establish direct connections to remote desktops and applications.
If you enable only the secure tunnel or only one secure gateway, a session might use a direct connection for some traffic but send other traffic through the Horizon Connection Server host, depending on the type of client being used.
TLS is required for all client connections to Horizon Connection Server hosts.
Was this page helpful?