Unified Access Gateway (UAG) enables secure remote access to On-Premises virtual desktops and applications in a customer data center. It operates with an On-Premises deployment of Horizon 8 for unified management. By providing strong assurance of user identity, Unified Access Gateway precisely controls access to desktops and applications based on user entitlements.
Deploying Unified Access Gateway in your network's DMZ
When deployed in the DMZ, Unified Access Gateway ensures that:
-
All traffic entering the data center to desktop and application resources comes from authenticated users.
-
Traffic for an authenticated user can be directed only to desktop and application resources to which the user is entitled. This level of protection involves specific inspection of desktop protocols and coordination of rapidly changing policies and network addresses to control access accurately.
UAG deployment architecture
The following figure shows an example of a configuration that includes front-end and back-end firewalls.
Before you deploy
Verify the following requirements for a seamless deployment with Horizon 8.
-
By default, port 8443 must be available for Blast TCP/UDP. However, port 443 can also be configured for Blast TCP/UDP.
Note: If you configure Unified Access Gateway to use both IPv4 and IPv6 mode, then the Blast TCP/UDP must be set to port 443. See Unified Access Gateway Support for IPv4 and IPv6 Dual Mode for Horizon Infrastructure.
-
The Blast Secure Gateway and PCoIP Secure Gateway must be enabled when Unified Access Gateway is deployed with Horizon 8. This ensures that the display protocols can serve as proxies automatically through Unified Access Gateway. The
BlastExternalURLandpcoipExternalURLsettings specify connection addresses used by the Horizon Clients to route these display protocol connections through the appropriate gateways on Unified Access Gateway. This provides improved security as these gateways ensure that display protocol traffic is controlled on behalf of an authenticated user. Unauthorized display protocol traffic is disregarded by Unified Access Gateway. -
Disable the secure gateways (Blast Secure Gateway and PCoIP Secure Gateway) on Horizon Connection Server instances and enable these gateways on the Unified Access Gateway appliances.
Authentication
Supported user authentication methods in Unified Access Gateway include the following:
- Active Directory user name and password.
- Kiosk mode. For details about Kiosk mode, see the Horizon 8 documentation.
- RSA SecurID two-factor authentication, formally certified by RSA for SecurID.
- RADIUS through various third-party, two-factor security-vendor solutions.
- Smart card, X.509 user certificates
- SAML, X.509 and SAML, SAML and Unauthenticated
- OIDC
These authentication methods are supported with Horizon Connection Server. Unified Access Gateway is not required to communicate directly with Active Directory. This communication serves as a proxy through the Horizon Connection Server, which can directly access Active Directory. After the user's session is authenticated according to the authentication policy, Unified Access Gateway can forward requests for entitlement information, and desktop and application launch requests to the Horizon Connection Server. Unified Access Gateway also manages its desktop and application protocol handlers to allow them to forward only authorized protocol traffic.
Unified Access Gateway handles smart card authentication by itself. This includes options for Unified Access Gateway to communicate with Online Certificate Status Protocol (OCSP) servers to check for X.509 certificate revocation, and so on.
Was this page helpful?