Skip to main content

July 20, 2026

Deploying Omnissa Workspace ONE Tunnel using Single-Tier Deployment

If you are using the single-tier deployment model, use the basic-endpoint mode. The basic endpoint deployment model of Tunnel is a single instance of the product installed on a server with a publicly available DNS. Basic Tunnel is typically installed in the internal network behind a load balancer in the DMZ that forwards traffic on the configured ports to the Tunnel, which then connects directly to your internal Web applications. All deployment configurations support load balancing and reverse proxy.

Basic Tunnel is typically installed in the internal network behind a load balancer in the DMZ that forwards traffic on the configured ports to the Tunnel, which then connects directly to your internal Web applications. All deployment configurations support load balancing and reverse proxy.

The basic endpoint Tunnel server communicates with API and AWCM to receive a whitelist of clients allowed to access Tunnel. Both proxy and Per-App Tunnel components support using an outbound proxy to communicate with API/AWCM in this deployment model. When a device connects to Tunnel, it is authenticated based on unique X.509 certificates issued by Workspace ONE UEM. Once a device is authenticated, the Tunnel (basic endpoint) forwards the request to the internal network.

If the basic endpoint is installed in the DMZ, the proper network changes must be made to allow the Tunnel to access various internal resources over the necessary ports. Installing this component behind a load balancer in the DMZ minimizes the number of network changes to implement the Tunnel and provides a layer of security because the public DNS is not pointed directly to the server that hosts the Tunnel.

Was this page helpful?

Provide feedback for this topic

Was this topic helpful?

Please do not include any personal or confidential information.

Generating link…