Skip to main content

7. Oktober 2026

Create a UAG Deployment for a Google Cloud Platform Edge

In Horizon Cloud, you configure the Unified Access Gateway (UAG) settings for your Google Cloud Platform (GCP) Edge as part of the Edge creation process.

Note: Horizon Cloud on Google Cloud Platform is currently available in Limited Availability (LA) mode only.

Create the Unified Access Gateway (UAG) for the Horizon Cloud on GCP Edge

After you have created the Horizon Cloud on GCP Edge, you can configure a Unified Access Gateway.

You need to provide one or more certificates for the Unified Access Gateway in PEM format. The certificate's Common Name (CN) or Subject Alternative Name (SAN) must match the fully qualified domain name (FQDN) used to access the UAG. For information about formatting your certificate in PEM format, see Format a PEM Certificate for Use with Unified Access Gateway.

Open the Existing Edge in Horizon Cloud and Confirm Requirements

In the Horizon Cloud console, locate the Horizon Cloud on GCP Edge by clicking Capacity > Horizon Edges and locate the deployed GCP Edge.

In the Unified Access Gateway column, click on the Not Configured status to begin the setup.

  1. On the Requirements page, confirm that you have met the stated requirement and click Next.

General Information

On the General Information page, enter the following information and click Next.

Enter a name and description for the UAG and specify the number of Unified Access Gateway VMs to be created for this deployment. A minimum of 2 UAG VM instances is strongly recommended for production environments to ensure high availability.

In the Provider field, specify the GCP provider where UAG is to be deployed.

For Deployment type, choose Basic or Advanced as below:

  • Basic — recommended for most deployments. Load balancer is configured in "session persistence/source IP affinity" distribution mode. Traffic from same client IP is routed through the same UAG instance. Basic mode enables 2K session support per UAG.
  • Advanced — for large-scale environments, or when end user clients connect to the load balancer behind a proxy or NAT. Load balancer is configured in "hash-based" distribution mode. Advanced mode enables 2000 connections per Horizon Edge. To use Advanced mode, ensure that the UAG is configured with a minimum of 4 vCPU and 16 GB RAM. Actual compute requirements may vary based on your specific use case and workload.

For Access type, select one of the following:

  • Internal access over a corporate network — a Layer 4 load balancer will be deployed with a frontend in the Desktop network.
  • External access over the internet — a Layer 4 load balancer will be deployed with a public IP.
  • Internal and external access — allows both internal and external access.

In the External FQDN field, enter the fully qualified domain name that end users will use to connect. This FQDN must resolve to the UAG load balancer's public IP address via a DNS A record you control.

Gateway VMs

In the Certificate type dropdown, select:

  • CA Signed — recommended for production.
  • Self-Signed — for development or testing only. End users will see a browser security warning.

Click Browse next to Certificate to upload your PEM-format certificate file including the full certificate chain. For information about formatting your certificate in PEM format, see Format a PEM Certificate for Use with Unified Access Gateway.

In the VM Model dropdown, select the GCP machine type for each UAG VM. Choose a machine type with a minimum of 4 vCPU and 16 GB memory to support 2000 sessions.

Networking

In the VM VPC and VM Subnet dropdowns, select the VPC network and subnet for the UAG VM's primary network interface.

In the Management VPC and Management Subnet dropdowns, select the VPC network and subnet for management plane communication between the UAG and the Horizon Edge Gateway.

In the DMZ VPC and DMZ Subnet dropdowns, select the VPC network and subnet for the DMZ-facing network interface.

Note: The DMZ VPC and DMZ Subnet fields are not required when the Access type is Internal access over a corporate network only. They are required when the Access type is External access over the internet or Internal and external access. The Management VPC and Management Subnet fields are always required.

Click Save to complete the UAG configuration for the Edge. Horizon Cloud will begin deploying the UAG VMs in your GCP project. Deployment typically takes 20–40 minutes. You can monitor progress on the Horizon Edges list page.

Advanced Unified Access Gateway Configuration

The advanced UAG guidance below is adapted from the Omnissa documentation Add and Deploy an Amazon WorkSpaces Core Edge.

Prerequisites for Configuring UAG Advanced Mode

  • Ensure that all Horizon Clients connecting to the Edge (for which UAG Advanced mode is being configured) have been upgraded to Horizon HAI agent version 24.12 or above. See the Horizon Cloud Release Notes for related information about HAI agent version requirements.
  • UAG Advanced Mode is available across all supported platforms, including Native Desktop, Mobile, and Web clients.
  • When editing a deployed Horizon Edge, if there is a change in the deployment type from Basic to Advanced or Advanced to Basic, the load balancer IP address in the Unified Access Gateway section of the Edge deployment UI page might change. If a change in the load balancer IP does occur, you must update the DNS record with the new IP address.

Deployment Type — Basic or Advanced

In the Deployment section, select the Deployment Type of Basic or Advanced as described in the onscreen help. The deployment type setting specifies that load balancer distribution uses either source-ip-affinity or hash.

  • Basic — Load balancer is configured in "session persistence/source IP affinity" distribution mode. Traffic from same client IP is routed through the same UAG instance. Supports up to 2000 connections for each Horizon Edge if NAT gateway or firewall configured in front of a load balancer.
  • Advanced — Load balancer is configured in "hash-based" distribution mode. Supports up to 2000 connections for each Horizon Edge. Use of this option requires that you use a new management subnet with a subnet mask of /28. This UAG management subnet should be in the same VPC, or in a peered VPC, as the Edge management subnet. The new UAG management subnet must be provided with a /28 subnet mask selected from the list.

For example, in scenarios where you deploy a NAT gateway or firewall in front of a load balancer with Basic/source-ip-affinity UAG enabled, only 2000 connections are supported for each Horizon Edge. With Advanced/hash UAG deployment enabled, up to 2000 connections can be supported for each Horizon Edge.

If you select Advanced, you can perform one or more of the following operations:

  • If you are deploying the UAG as Blast Extreme, you can specify that port 443 be used.
  • The deployer service automatically enables 8445 inbound UDP port via a firewall rule on the UAG management network.
  • You can specify an NTP server.

When you click Save to configure the UAG Advanced mode, a message appears stating that UAG advanced mode configuration is in progress. The UAG Advanced mode configuration may take up to 15 minutes to complete.

After the successful configuration of the UAG Advanced mode, the UAG Load balancer IP might change. If so, you might have to update the DNS record with the new IP Address.

Edit the Unified Access Gateway (UAG)

If using the API, the following fields are editable for the UAG deployment:

  • Internal FQDN
  • Certificate type
  • Certificate update
  • VM model
  • UAG VMs
  • NTP Servers
  • Cipher Suites

Additional Information

You can expand the Advanced node to perform the following operations:

  • If you are deploying the Unified Access Gateway as Blast Extreme, you can use port 443.
  • You can specify an NTP server, as shown and described in the onscreen help for those options.
  • You can manage Google resource labels as needed, which includes viewing inherited labels, editing and deleting existing tags, and adding tags to be applied to the resource groups specific to this Unified Access Gateway. For related information, see Use GCP Resource Labels.

What to do next

After you have deployed the Horizon Cloud on GCP Edge and its configured UAG, you can create images and add the Edge to Pools and Pool Groups.

For images, see Managing Images for Google Cloud Platform Provider Deployments.

For pools and pool groups, see Creating a Pool and Pool Group for Google Cloud Platform Provider.

War diese Seite hilfreich?

Feedback zu diesem Thema geben

War dieses Thema hilfreich?

Bitte geben Sie keine personenbezogenen oder vertraulichen Daten an.

Link wird erstellt…