To deploy the Unified Access Gateway appliance, ensure that your system meets the hardware and software requirements.
Supported product versions
You must use product versions that are compatible with specific versions of Unified Access Gateway. Refer to the product release notes for the latest information about compatibility, and refer to the Product Interoperability Matrix.
Hypervisor requirements
Unified Access Gateway supports the following virtualization platforms:
- vSphere (ESXi with vCenter)
- Microsoft Azure
- Microsoft Hyper-V
- Amazon AWS EC2
- Google Cloud GCE
- vCloud Director
- Nutanix AHV
ESXi Server hardware requirements
The Unified Access Gateway appliance must be deployed on a supported version of vSphere.
If you plan to use the vSphere Web client, verify that the client integration plug-in is installed. For more information, see the VMware vSphere Tech Docs. If you do not install this plug-in before you start the deployment wizard, the wizard prompts you to install the plug-in. This requires that you close the browser and exit the wizard.
Virtual Appliance requirements
The OVF package for the Unified Access Gateway appliance automatically selects the virtual machine configuration that the Unified Access Gateway requires. Although you can change these settings, it is recommended that you not change the CPU, memory, or disk space to smaller values than the default OVF settings.
- CPU minimum requirement is 2000 MHz
- Minimum memory of 4GB
Important: Unified Access Gateway is a virtual appliance. Security and general patches are distributed by Omnissa as updated virtual appliance image files. Customization of a Unified Access Gateway appliance or upgrading individual components is not supported apart from increasing memory and the number of vCPUs which can be performed through vCenter Server Edit settings.
Ensure that the datastore you use for the appliance has enough free disk space and meets other system requirements.
- Virtual appliance download size (depends on the Unified Access Gateway version)
- Thin-provisioned disk minimum requirement is 3.5 GB
- Thick-provisioned disk minimum requirement is 20 GB
Note: In addition to the minimum disk requirements, vSphere can create other files such as a swap file on the ESXi datastore for each virtual machine. Disk space is also used for any virtual machine snapshots created with vCenter Server. An ESXi datastore also contains some other small files for each virtual machine.
If memory reservation is not configured, vSphere creates a per-virtual machine swap file (.vswp) of up to the virtual machine memory size. This swap space is for any unreserved virtual machine memory. For example, a 4 GB RAM Unified Access Gateway appliance with a vSphere thick-provisioned disk uses a 20 GB ESXi .vmdk file and the appliance can use a 4 GB ESXi swap file. This results in a total disk space requirement of 24 GB. Similarly, for a 16 GB RAM Unified Access Gateway appliance, the total disk space requirement can be 36 GB.
For more information about Swap Space and Memory Overcommitment, see vSphere Resource Management documentation.
The following information is required to deploy the virtual appliance.
- Static IP address (recommended)
- IP address of the DNS server
- Password for the root user
- Password for the admin user
- URL of the server instance of the load balancer that the Unified Access Gateway appliance points to
Unified Access Gateway sizing options
-
Standard: This configuration is recommended for Horizon deployments supporting up to 2,000 Horizon connections, aligned with the Connection Server capacity. It is also recommended for Workspace ONE UEM Deployments (mobile use cases) up to 10,000 concurrent connections.
-
Large: This configuration is recommended for Workspace ONE UEM deployments, where Unified Access Gateway needs to support up to 150,000 concurrent connections. This size allows Content Gateway, Per App Tunnel, and Reverse Proxy to use the same Unified Access Gateway appliance.
-
Extra Large: This configuration is recommended for Horizon connections supporting up to 4,000 Horizon sessions. It is also recommended for Workspace ONE UEM deployments, where Unified Access Gateway needs to support up to 200,000 concurrent connections. This size allows Content Gateway, Per App Tunnel, and Reverse Proxy to use the same Unified Access Gateway appliance.
VM options for Standard, Large, and Extra Large deployments:
- Standard - 2 core and 4GB RAM
- Large - 4 core and 16GB RAM
- Extra Large - 8 core and 32GB RAM
You can configure these settings using PowerShell. For information about PowerShell parameters, see Prepare the INI File to Deploy Unified Access Gateway.
For more information about the Unified Access Gateway sizing recommendations, see Configuration Maximums.
Browser versions supported
Supported browsers for launching the Admin UI are Chrome and Firefox. Use the most current version of the browser.
Windows Hyper-V Server hardware requirements
-
Workspace ONE UEM Per-App Tunnel deployment - Windows Server 2012 R2 and Windows Server 2016
-
Horizon 8 deployment - Windows Server 2022
Networking configuration requirements - deployment options
You can use one, two, or three network interfaces, and Unified Access Gateway requires a separate static IP address for each. Many DMZ implementations use separated networks to secure the different traffic types. Configure Unified Access Gateway according to the network design of the DMZ in which it is deployed.
- NIC 1 - One network interface is appropriate for POCs (proof of concept) or testing. With one NIC, external, internal, and management traffic is all on the same subnet.
- NIC 2 - With two network interfaces, external traffic is on one subnet, and internal and management traffic are on another subnet.
- NIC 3 - Using three network interfaces is the most secure option. With a third NIC, external, internal, and management traffic all have their own subnets.
Multicast DNS and .local hostnames
UAG (Unified Access Gateway) 3.7 and later versions support Multicast DNS in addition to the Unicast DNS. Multi-label names with the domain suffix .local are routed to all local interfaces, which are capable of IP multicasting by using the Multicast DNS protocol.
Avoid defining .local in a Unicast DNS server because RFC6762 reserves this domain use for Multicast DNS. For example, if you use a hostname hostname.example.local in a configuration setting such as Proxy Destination URL on the UAG, then the hostname is not resolved with Unicast DNS because .local is reserved for Multicast DNS.
Alternatively, you can use one of the following methods in which the .local domain suffix is not required:
-
Specify an IP address instead of a
.localhostname. -
An additional alternative DNS record can be added in the DNS server.
In the earlier example of host name,
hostname.example.intcan be added to the same IP address ashostname.example.localand used in the UAG configuration. -
A local
hostsfile entry can be defined.In the earlier example, a local
hostsentry can be defined forhostname.example.local.hostsfile entries specify names and IP addresses and can be set by using the UAG Admin UI or through PowerShell.inifile settings.Important: The
/etc/hostsfile on UAG must not be edited.On the UAG, local
hostsfile entries are searched before performing a DNS search. Such a search ensures that if the host name is present on thehostsfile, then the.localnames can be used and a DNS search is not required at all.
Log retention requirements
The log files are configured by default to use a certain amount of space, which is smaller than the total disk size in the aggregate. The logs for Unified Access Gateway are rotated by default. You must use syslog to preserve these log entries. See Collecting Logs from the Unified Access Gateway Appliance.
System requirements for deploying Omnissa Workspace ONE Tunnel
To deploy Tunnel with Unified Access Gateway, ensure that your system meets the following requirements:
Supported Hypervisors
Unified Access Gateway that deploys the Tunnel requires a hypervisor to deploy the virtual appliance. You must have a dedicated admin account with full privileges to deploy the OVF.
-
vSphere web client
Note: You must use product versions that are compatible with specific versions of Unified Access Gateway.
-
Microsoft Hyper-V on Windows Server 2012 R2 or Windows Server 2016
Software Requirements
Ensure that you have the most recent version of Unified Access Gateway. Tunnel supports backwards compatibility between Unified Access Gateway and the Workspace ONE UEM console. Backward compatibility allows you to upgrade your Tunnel server shortly after upgrading your Workspace ONE UEM console. To ensure parity between Workspace ONE UEM console and Tunnel, consider planning an early upgrade.
Hardware Requirements
The OVF package for Unified Access Gateway automatically selects the virtual machine configuration that Tunnel requires. Although you can change these settings, do not change the CPU, memory, or disk space to smaller values than the default OVF settings.
To change the default settings, power off the VM in vCenter. Right-click the VM and select Edit Settings.
The default configuration uses 4 GB of RAM and 2 CPUs. You must change the default configuration to meet your hardware requirements. To handle all the device loads and maintenance requirements, consider running a minimum of two Tunnel servers.
Hardware Requirements
| Number of Devices | Up to 40000 | 40000-80000 | 80000-120000 | 120000-160000 |
|---|---|---|---|---|
| Number of Servers | 2 | 3 | 4 | 5 |
| CPU Cores | 4 CPU Cores* | 4 CPU Cores each | 4 CPU Cores each | 4 CPU Cores each |
| RAM (GB) | 8 | 8 | 8 | 8 |
Hard Disk Space (GB)
- 10 GB for distro (Linux only)
- 400 MB for installer
- ~10 GB for log file space**
*It is possible to deploy only a single Tunnel appliance as part of a smaller deployment. However, consider deploying at least two load-balanced servers with four CPU Cores each regardless of the number of devices for uptime and performance purposes.
**10 GB for a typical deployment. Scale the log file size based on your log use and requirements for storing the logs.
Was this page helpful?