Skip to main content

February 19, 2025

Preparing Omnissa Horizon Connection Server

<<<<<<< HEAD

Preparing Omnissa Horizon Connection Server

Before end users can connect to a server and access a remote desktop or published application, a Horizon administrator must install and configure Horizon Connection Server.

Install the HTML Access Component in Horizon Connection Server

Install Horizon Connection Server with the Install HTML Access setting selected on the server, or servers, that comprise a Horizon Connection Server replicated group. This setting installs the HTML Access component. This setting is selected in the installer by default. For more information, see the Horizon Installation and Upgrade document.

Configure the Omnissa Horizon Blast External URL

After the servers are installed, the Blast Secure Gateway setting is enabled on the applicable Horizon Connection Server instances in Omnissa Horizon Console. Also, the Blast External URL setting is configured to use the Blast Secure Gateway on the applicable Horizon Connection Server instances.

By default, the URL includes the FQDN of the secure tunnel external URL and the default port number, 8443. The URL must contain the FQDN and port number that a client system can use to reach the Horizon Connection Server host.

For more information, see "Set the External URLs for Horizon Connection Server Instances," in the Horizon Installation and Upgrade document.

Configure Firewall Rules

If you use third-party firewalls, configure rules to allow inbound traffic to TCP port 8443 for all Horizon Connection Server hosts in a replicated group, and configure a rule to allow inbound traffic (from servers) to TCP port 22443 on remote desktop virtual machines and RDS hosts in the data center.

For more information, see Firewall Rules for Client Web Browser Access.

Configure User Authentication

Use the following check list when setting up user authentication.

  • Verify that each Horizon Connection Server instance has a TLS certificate that can be fully verified by using the host name that you enter in the web browser. For more information, see the Horizon Installation and Upgrade document.
  • To use two-factor authentication, such as RSA SecurID or RADIUS authentication, verify that this feature is enabled on Horizon Connection Server. You can customize the labels on the RADIUS authentication login page. You can configure two-factor authentication to occur after a remote session times out. For more information, see the topics about two-factor authentication in the Horizon Administration document.
  • To hide the Domain drop-down menu in HTML Access, enable the Hide domain list in client user interface global setting. This setting is enabled by default. For more information, see the Horizon Administration document.
  • To send the domain list to HTML Access, activate the Send domain list global setting. This setting is deactivated by default. For more information, see the Horizon Administration document.
  • To provide unauthenticated access to published applications, enable this feature in Horizon Connection Server. For more information, see the Horizon Administration document.

The following table shows how the Send domain list and Hide domain list in client user interface global settings determine how users can log in to the server from HTML Access.

Send domain list settingHide domain list in client user interface settingHow users log in
Deactivated (default)Activated (default)The Domain drop-down menu is hidden. Users must enter one of the following values in the User name text box.
  • User name (not allowed for multiple domains)
  • domain\username
  • username@domain.com
DeactivatedDeactivatedIf a default domain is configured on the client, the default domain appears in the Domain drop-down menu. If the client does not know a default domain, *DefaultDomain* appears in the Domain drop-down menu. Users must enter one of the following values in the User name text box.
  • User name (not allowed for multiple domains)
  • domain\username
  • username@domain.com
ActivatedActivatedThe Domain drop-down menu is hidden. Users must enter one of the following values in the User name text box.
  • User name (not allowed for multiple domains)
  • domain\username
  • username@domain.com
ActivatedDeactivatedUsers can enter a user name in the User name text box and then select a domain from the Domain drop-down menu. Alternatively, users can enter one of the following values in the User name text box.
  • domain\username
  • username@domain.com

Use HTML Access with Omnissa Workspace ONE

You can optionally use HTML Access with Omnissa Workspace ONE. For information about installing Workspace ONE and configuring it for use with Horizon Connection Server, see the Workspace ONE documentation.

For information about pairing Horizon Connection Server with a SAML Authentication server, see the Horizon Administration document.

=======

Preparing Connection Server

3a9abdeab3b2aeb721724d2c17ff888053281e37

Before end users can connect to a server and access a remote desktop or published application, a Horizon administrator must install and configure Connection Server.

Install the HTML Access Component in Connection Server

Install Connection Server with the Install HTML Access setting selected on the server, or servers, that comprise a Connection Server replicated group. This setting installs the HTML Access component. This setting is selected in the installer by default. For more information, see the Horizon Installation and Upgrade document.

Configure the Blast External URL

After the servers are installed, the Blast Secure Gateway setting is enabled on the applicable Connection Server instances in Horizon Console. Also, the Blast External URL setting is configured to use the Blast Secure Gateway on the applicable Connection Server instances.

By default, the URL includes the FQDN of the secure tunnel external URL and the default port number, 8443. The URL must contain the FQDN and port number that a client system can use to reach the Connection Server host.

For more information, see "Set the External URLs for Horizon Connection Server Instances," in the Horizon Installation and Upgrade document.

Configure Firewall Rules

If you use third-party firewalls, configure rules to allow inbound traffic to TCP port 8443 for all Connection Server hosts in a replicated group, and configure a rule to allow inbound traffic (from servers) to TCP port 22443 on remote desktop virtual machines and RDS hosts in the data center.

For more information, see Firewall Rules for Client Web Browser Access.

Configure User Authentication

Use the following check list when setting up user authentication.

  • Verify that each Connection Server instance has a TLS certificate that can be fully verified by using the host name that you enter in the web browser. For more information, see the Horizon Installation and Upgrade document.
  • To use two-factor authentication, such as RSA SecurID or RADIUS authentication, verify that this feature is enabled on Connection Server. You can customize the labels on the RADIUS authentication login page. You can configure two-factor authentication to occur after a remote session times out. For more information, see the topics about two-factor authentication in the Horizon Administration document.
  • To hide the Domain drop-down menu in HTML Access, enable the Hide domain list in client user interface global setting. This setting is enabled by default. For more information, see the Horizon Administration document.
  • To send the domain list to HTML Access, activate the Send domain list global setting. This setting is deactivated by default. For more information, see the Horizon Administration document.
  • To provide unauthenticated access to published applications, enable this feature in Connection Server. For more information, see the Horizon Administration document.

The following table shows how the Send domain list and Hide domain list in client user interface global settings determine how users can log in to the server from HTML Access.

Send domain list settingHide domain list in client user interface settingHow users log in
Deactivated (default)Activated (default)The Domain drop-down menu is hidden. Users must enter one of the following values in the User name text box.
  • User name (not allowed for multiple domains)
  • domain\username
  • username@domain.com
DeactivatedDeactivatedIf a default domain is configured on the client, the default domain appears in the Domain drop-down menu. If the client does not know a default domain, *DefaultDomain* appears in the Domain drop-down menu. Users must enter one of the following values in the User name text box.
  • User name (not allowed for multiple domains)
  • domain\username
  • username@domain.com
ActivatedActivatedThe Domain drop-down menu is hidden. Users must enter one of the following values in the User name text box.
  • User name (not allowed for multiple domains)
  • domain\username
  • username@domain.com
ActivatedDeactivatedUsers can enter a user name in the User name text box and then select a domain from the Domain drop-down menu. Alternatively, users can enter one of the following values in the User name text box.
  • domain\username
  • username@domain.com

Use HTML Access with Workspace ONE

You can optionally use HTML Access with Workspace ONE. For information about installing Workspace ONE and configuring it for use with Connection Server, see the Workspace ONE documentation.

For information about pairing Connection Server with a SAML Authentication server, see the Horizon Administration document.

Was this page helpful?

Provide feedback for this topic

Was this topic helpful?

Please do not include any personal or confidential information.

Generating link…