Skip to main content

August 26, 2026

Deployment with Horizon 8

Unified Access Gateway (UAG) enables secure remote access to On-Premises virtual desktops and applications in a customer data center. It operates with an On-Premises deployment of Horizon 8 for unified management. By providing strong assurance of user identity, Unified Access Gateway precisely controls access to desktops and applications based on user entitlements.

Deploying Unified Access Gateway in your network's DMZ

When deployed in the DMZ, Unified Access Gateway ensures that:

  • All traffic entering the data center to desktop and application resources comes from authenticated users.

  • Traffic for an authenticated user can be directed only to desktop and application resources to which the user is entitled. This level of protection involves specific inspection of desktop protocols and coordination of rapidly changing policies and network addresses to control access accurately.

UAG deployment architecture

The following figure shows an example of a configuration that includes front-end and back-end firewalls.

Before you deploy

Verify the following requirements for a seamless deployment with Horizon 8.

  • By default, port 8443 must be available for Blast TCP/UDP. However, port 443 can also be configured for Blast TCP/UDP.
  • The Blast Secure Gateway and PCoIP Secure Gateway must be enabled when Unified Access Gateway is deployed with Horizon 8. This ensures that the display protocols can serve as proxies automatically through Unified Access Gateway. The BlastExternalURL and pcoipExternalURL settings specify connection addresses used by the Horizon Clients to route these display protocol connections through the appropriate gateways on Unified Access Gateway. This provides improved security as these gateways ensure that display protocol traffic is controlled on behalf of an authenticated user. Unauthorized display protocol traffic is disregarded by Unified Access Gateway.

  • Disable the secure gateways (Blast Secure Gateway and PCoIP Secure Gateway) on Horizon Connection Server instances and enable these gateways on the Unified Access Gateway appliances.

Authentication

The following user authentication methods are supported in Unified Access Gateway:

  • Active Directory user name and password
  • Kiosk mode. For details about Kiosk mode, see the Horizon 8 documentation
  • RSA SecurID two-factor authentication, formally certified by RSA for SecurID
  • RADIUS through various third-party, two-factor security-vendor solutions
  • Smart card, X.509 user certificates
  • SAML, X.509 and SAML, SAML and Unauthenticated
  • OIDC

These authentication methods are supported with Horizon Connection Server. Unified Access Gateway is not required to communicate directly with Active Directory. This communication serves as a proxy through the Horizon Connection Server, which can directly access Active Directory. After the user's session is authenticated according to the authentication policy, Unified Access Gateway can forward requests for entitlement information, and desktop and application launch requests to the Horizon Connection Server. Unified Access Gateway also manages its desktop and application protocol handlers to allow them to forward only authorized protocol traffic.

Unified Access Gateway handles smart card authentication by itself. This includes options for Unified Access Gateway to communicate with Online Certificate Status Protocol (OCSP) servers to check for X.509 certificate revocation, and so on.

Was this page helpful?

Provide feedback for this topic

Was this topic helpful?

Please do not include any personal or confidential information.

Generating link…