Horizon Cloud supports the scenario where end users and client systems can broker Horizon Cloud desktops within an organization’s private network without that network traffic passing through a public network. When working in this type of closed network setting, you can configure end users to connect to the Horizon Control Plane through Azure Private Link by using ExpressRoute or VPN and a private brokered endpoint.
This scenario applies to Microsoft Azure environments in which end users and client systems need to broker Horizon Cloud desktops within an organization's private network, without that network traffic passing through a public network.
Note: The Horizon Web Client does not currently support private brokering.
The following sections describe the prerequisites and procedure for creating a private brokered endpoint to enable closed network settings within Horizon Cloud.
Note: When using DNS mapping and creating more than one private endpoint, you must configure DNS for additional endpoints by using the FQDN setting that is provided in the UI. You must create an entry in your regional DNS forwarder or DNS server as an alias with the private broker endpoint FQDN to private endpoint FQDN for all additional endpoints. If your DNS does not have a line of sight to a public DNS, you can create a DNS entry with the private IP address of the private endpoint. Be aware that if a regional outage occurs that impacts Horizon Cloudbecause of infrastructure issues, automatic failover will not occur and may cause end user downtime. To avoid this potential problem, update your DNS mappings with the failover IP for regional failover and for notifications. Contact Support if assistance is required.
For related information about Azure virtual private networks, see What is Azure Virtual Network?.
For related information about Azure ExpressRoute, see What is Azure ExpressRoute?.
For related information about using a Home Site in Horizon Cloudfor associating specific users to a specified home site endpoint, see Creating and Using a Home Site.
Prerequisites
- Ensure that you have administrator access to a valid Microsoft Azure subscription for your organization.
- Ensure that you have administrator access to a valid Horizon Cloud subscription for your organization.
Procedure
Create and enable private network access to one or more private brokered endpoints within a given tenant organization by using the following procedure. This procedure applies to Azure environments only.
-
Log in to Horizon Cloud with administrator access rights. See Log in to Horizon Cloud.
-
From the Horizon Universal Console Home page, click Settings and then click Manage in the Client Settings sections of the Settings page.
-
Click the Private Brokering tab on the Client Settings page.
-
If you have not yet enabled private brokering, click Edit as prompted.
-
Toggle the Private Brokering option on and provide a custom Subdomain.
-
Click Save and then click either Skip if you have already created the needed endpoint or click Add Endpoint.
-
Click Skip to add a new endpoint later or be prompted to select or edit an existing private brokered endpoint now.
-
Click Add Endpoint to add a new private brokered endpoint by specifying a Provider, Virtual Network, and Subnet as prompted on the Add Private Brokered Endpoint page.
- Click Save. If you have specified a valid subdomain and private brokered endpoint, Azure end users can now connect to the Horizon Cloud Cloud Plane within the private network.
Result
End users working within the current tenant can now use Horizon Cloud within a private network environment by connecting to the specified private brokered endpoint. If you want to add additional private endpoints, you can add them now or later. You can also edit the subdomain of an existing endpoint.
Was this page helpful?