When the Microsoft Azure VNet that is used by your pods is configured for NSX Cloud, you are able to leverage the features of NSX-T Data Center network virtualization with those pods' farms and VDI desktop assignments. You can use the micro-segmentation features of NSX Cloud to restrict access between farm RDSH instances and VDI desktops even when those virtual machines are in the same tenant subnet.
For the specific version of NSX-T Data Center that is supported for this integration with the current pod manifest for the current version, see the documentation topic Horizon Cloud — Environments, Operating Systems, and Compatibility.
Note: When you have updated an existing pod from manifest versions prior to 1101 to a later manifest version, those farms and VDI desktop assignments that existed in the pod prior to updating the pod cannot be edited after the update to enable them for NSX Cloud management.
Horizon Cloud integration is supported with NSX Cloud management components — NSX Manager and Cloud Service Manager (CSM) — deployed either on-premises or, starting with NSX-T Data Center version 3.1.1, natively in Microsoft Azure. For an overview of the NSX Cloud architecture and components, see 'NSX Cloud Architecture and Components' within the NSX documentation at the Broadcom site techdocs.broadcom.com.
Note: Starting with NSX Cloud 3.1.1, both quarantine and non-quarantine mode are supported for use with Horizon Cloud pods in Microsoft Azure. Earlier releases support only non-quarantine mode.
One requirement of using NSX Cloud with your Microsoft Azure environment is you must establish a connection between your Microsoft Azure VNet and your on-premises NSX-T Data Center appliances. Because Microsoft Azure does not allow you to modify a VNet's CIDR block after a VNet is peered or after attaching a VPN Gateway, ensure you have checked all of the values you want to use before you attach the VNet to the VPN Gateway. For a workflow of the high-level steps for connecting NSX Cloud to your public cloud, see the NSX topic 'Integrate with NSX Cloud' within the NSX documentation at the Broadcom site techdocs.broadcom.com.
The following table is a high-level summary of the end-to-end steps to enable using the NSX Cloud features with your pod's RDSH VMs and VDI desktop VMs.
| High-Level Step | Details |
|---|---|
| Integrate Horizon Cloud with NSX Cloud for use with the Horizon Cloud pod | Refer to the NSX documentation page 'Integrate with NSX Cloud' within the NSX documentation at the Broadcom site techdocs.broadcom.com.
Important: If you intend to create App Volumes assignments in the pod, you must manually open port 445/TCP for the pod's tenant subnet in your NSX firewall rules after you deploy the NSX PCG and before you create your first App Volumes assignment using that pod. As stated in App Volumes Applications for Horizon Cloud on Microsoft Azure - Overview and Prerequisites, to support the use of the App Volumes features that are supported for use with a Horizon Cloud pod, you must configure port 445 for TCP protocol traffic on the pod's tenant subnet. |
| Create a VM and import it into Horizon Cloud using the Import Virtual Machine from Marketplace wizard. | See Create a Base Virtual Machine Automatically from the Microsoft Azure Marketplace and Pair it with Horizon Cloud on a Per-Pod Basis. To make it easy to install the required NSX agent, a best practice is to select the option for a public IP address. Note: When importing the VM, select the options for optimizing the VM and, for Windows 10 or 11, removing Windows Store Apps. Using those options helps prevent sysprep issues when subsequently sealing the image. |
| Connect to the imported VM and install the required NSX Tools. | Install the NSX Tools in the Horizon Cloud Imported Image VM |
| Publish the image. | Convert a Configured Image VM to an Assignable Image in Horizon Cloud on a Per-Pod Basis |
| Create farms and VDI desktop assignments using that image and the setting to enable NSX Cloud management for that farm or assignment. When the RDSH VMs and VDI desktop VMs are created, they appear in your NSX Cloud inventory. | |
| Enable the distributed firewalls rules in NSX Manager that will allow communication with the RDSH VMs and VDI desktop VMs | Because NSX Cloud will block these communications by default, you must enable some distributed firewall rules in NSX Manager to allow communication with the NSX-managed VMs that are provisioned from the pod. See Firewall Rules Required in NSX Manager for Pod-Provisioned VMs. If you are using NSX-T Data Center 2.4, in addition to enabling the firewall rules, you must also add a forwarding policy to route the traffic pertaining to the NSX-managed VMs over the Microsoft Azure cloud's network (underlay). See Add the Required Forwarding Policy in NSX Manager for the Pod-Provisioned VMs. |
| Use NSX Cloud features with the RDSH VMs and VDI desktop VMs in your NSX Cloud inventory. | For details about the NSX Cloud inventory and NSX Cloud features, see the NSX Administration Guide at the Broadcom site techdocs.broadcom.com. |
Horizon Cloud Workflows and NSX Cloud
When you create an RDSH farm or a VDI desktop assignment in your Horizon Cloud pod using a golden image VM that you configured with the NSX agent, you can decide to whether to enable NSX Cloud management on that farm or VDI desktop assignment. When you enable NSX Cloud management for a farm or VDI desktop assignment, all of the virtual machines (VMs) in that farm or VDI desktop assignment are tagged for use in NSX Cloud. You specify NSX Cloud management when you create the farm or VDI desktop assignment, and you cannot change that state after the farm or assignment is created. The Horizon Cloud workflows to create a farm and a VDI desktop assignment include a toggle for enabling use of NSX Cloud with the farm's RDSH instances or the VDI desktop assignment's virtual desktops. For details of those workflows, see:
- First-Gen Horizon Cloud Pods - Creating and Managing Farms
- Create a Dedicated VDI Desktop Assignment Provisioned by a Single Pod in Microsoft Azure
- Create a Floating VDI Desktop Assignment Provisioned by a Single Pod in Microsoft Azure
Setting the NSX Cloud Managed toggle to Yes when creating a farm or VDI desktop assignment gives the resulting farm's RDSH VMs or VDI desktop VMs with a custom tag named nsx.network=default. The NSX Cloud PCG manages all VMs that have that tag. NSX Cloud automatically discovers the VMs in your configured Microsoft Azure VNet that have this tag and includes these VMs in your public cloud inventory. You can then manage and secure those VMs using the CSM component of NSX-T Data Center. For details about the CSM component, see the NSX Administration Guide within the Broadcom site techdocs.broadcom.com.
Some limitations apply when using the NSX Cloud management feature with your pods in Horizon Cloud:
- You cannot edit the name of a farm or VDI desktop assignment that has NSX Cloud management enabled.
- To use both disk encryption and the NSX Cloud management features for a floating VDI desktop assignment, you must install the latest version of the NSX agent. That combination is not supported with previous NSX agent versions.
Install the NSX Tools in the Horizon Cloud Imported Image VM
When you want to create a farm or VDI desktop assignment that is enabled for NSX Cloud management, the NSX Tools must be installed in published image you use for that farm or assignment. You must install the NSX Tools into the image VM before you publish it. You install the NSX Tools after the VM is created and the Imported VMs page shows the status of the VM's Horizon agent software is active.
The steps in this page here follow the NSX Cloud method described as downloading and installing NSX Tools in the individual image VMs. This method involves downloading a PowerShell install script file from the download location identified in your NSX Cloud environment's Cloud Service Manager (CSM). In the image VM, you run that install script to download the NSX Tools install binaries and run the installation. Many of this method's details are located in the NSX Administration Guide page 'Install NSX Tools on Windows VMs' within the Broadcom site techdocs.broadcom.com.
Prerequisites
Verify the Imported VMs page indicates the agent-related status is active for the VM. To get that status, use the Imported VMs page's Reset Agent Pairing action on the VM. That action is located in the More drop-down list.
Note: When using the Microsoft Remote Desktop Client as your RDP software to connect to the VM, ensure it is the most up-to-date version. For example, the default RDP software in the Windows 7 operating system is not at a high enough version. The version must be version 8 or higher.
Verify you have at least one of the following credentials (user name and password) to log in to the VM's guest Windows operating system, according to how the VM was created.
| How the VM was created | Credentials to use to log in |
|---|---|
| Import Virtual Machine wizard, from the Imported VMs page. |
Starting with the December 2019 service release date, the Import Virtual Machine wizard provides the option of either having the wizard-created VM joined to a specified Active Directory domain or not having the VM joined to the domain at the end of the creation process.
|
| Manual preparation steps. |
Typically you do not need to join the VM to your Active Directory domain when you manually build the VM. To log in to that VM, use one of the following:
|
Important: Starting with pod manifest 1230 and later, domain accounts can direct connect to domain-joined image VMs that have the agent software installed. Prior to pod manifest 1230, the agent software installed in a domain-joined VM prevented domain accounts from directly connecting to that VM. Please note that such manifests that are earlier than 2298 are out of support and must be updated, as described in KB 86476.
If you are installing NSX Tools by downloading and installing into the VMs, verify you have the credentials to log in to the portal for your NSX Cloud environment's CSM. You use the CSM to identify the location for downloading the PowerShell install script to install NSX Tools. CSM is a component of NSX Cloud and provides a single-pane-of-glass management endpoint for your public cloud inventory. For more details about CSM, see the NSX documentation within the Broadcom site techdocs.broadcom.com.
Procedure
-
Use the VM's IP address in your RDP software to connect to the VM's Windows operating system.
- If the VM was created with a public IP address, you can use that IP address in your RDP software
- If the VM has a private IP address, you must RDP into it by one of these two methods:
- Using another VM in your Microsoft Azure subscription that does have a public IP address and doing an outbound RDP into the image VM.
- Use your VPN and RDP into the image VM over your corporate network Note: To access a VM that is running the agent-related software components, the version of the Remote Desktop Client must be version 8 or later. Otherwise, the connection fails. Using the most up-to-date Remote Desktop Client is recommended.
-
Log in to the Windows operating system using credentials (user name and password) as described in the prerequisites here.
When using the local administrator account credentials that were specified in the Import Image wizard when the VM was created, enter the username as
\username.Note: When the VM is a domain-joined VM, as described in the prerequisites, and you want to use a domain account instead of the local administrator account, enter the user name as
domain\usernamewhere domain is the name of the domain. -
From the Windows VM, log in to CSM and navigate to Clouds > Azure > VNets and navigate to the appropriate VNet for the pod.
-
Locate the NSX Tools Download & Installation area of the screen, to obtain the download location and installation command for Windows.
In that area, locate the displayed Windows install script download location. Under the download location is also a simple basic installation command.
-
The displayed download location has the pattern
http://filepath/nsx_install.ps1, wherensx_install.ps1is the PowerShell script file andfilepathis the path from which to download the file. -
The displayed basic installation command includes a portion
-dnsSuffix DNS-suffix, where DNS-suffix is a dynamically generated value related to the DNS settings you chose when you deployed the PCG on your Microsoft Azure VNet as part of configuring NSX Cloud. Important: When you run the script to install NSX Tools for an image VM in Horizon Cloud, you must specify: -
The same DNS-suffix that you see displayed in CSM for your Microsoft Azure VNet. The DNS-suffix is unique to your configured environment.
-
The
startOnDemand trueoption. That option optimizes NSX Tools for the Horizon Cloud publishing workflow.
-
-
Copy the displayed DNS-suffix so that you have it when you run the install script in the next steps.
-
Use the download location to download the
nsx_install.ps1file to a location on the VM. -
Open a PowerShell prompt, navigate to where you downloaded the nsx_install.ps1 file, and install NSX Tools by running the installation command using your value for DNS-suffix and the option
-startOnDemand true.Important: The option -startOnDemand true is required.
The following code block is an example of the command in a PowerShell prompt with an example DNS-suffix of
xxxxxxxxxxxxxxxxxxxxxxxxx.xx.internal.cloudapp.net.powershell -file 'nsx_install.ps1' -operation install -dnsSuffix xxxxxxxxxxxxxxxxxxxxxxxxx.xx.internal.cloudapp.net -startOnDemand trueWhen the script finishes running, a message appears indicating whether NSX Tools is installed successfully.
-
Close the PowerShell command prompt.
-
Verify that the NSX Tools bootstrap status is ready by opening a regular command prompt and running the following command.
schtasks /query /tn nsx_bootstrapRunning that command should show the nsx_bootstrap task in
Readystatus. The following shows an example.TaskName Next Run Time Status --------------------- ------------------- ----------- nsx_bootstrap N/A Ready -
Sign out of the VM's Windows operating system.
What to do next
With the NSX Tools installed and the nsx_bootstrap task showing as Ready, you can publish the image if you have no further customizations to make. See Convert a Configured Image VM to an Assignable Image in Horizon Cloud on a Per-Pod Basis.
Firewall Rules Required in NSX Manager for Pod-Provisioned VMs
When using NSX Cloud features with your pod in Microsoft Azure, you must enable some distributed firewall rules in NSX Manager to allow communication with the NSX-managed VMs that are provisioned from the pod. If these rules are not enabled, end users will not be able to launch and log in to their desktops or remote applications.
In NSX Manager, enable these rules to allow the traffic as indicated. In the table, the phrase desktop pool refers to the RDSH farm or VDI desktop assignment.
| Traffic Type | Source | Destination | Service/Protocol/Port |
|---|---|---|---|
| Horizon Web Client (Blast) traffic | The pod's Unified Access Gateway VMs | Desktop pool |
|
| Desktop pool to pod manager traffic | Desktop pool | Pod's manager VM |
|
| Desktop pool to Active Directory domain server traffic | Desktop pool | Pod's manager VM |
|
Add the Required Forwarding Policy in NSX Manager for the Pod-Provisioned VMs
When you are using NSX-T Data Center 2.4 with a pod in Microsoft Azure, in addition to enabling the firewall rules, you must also add a forwarding policy to route the traffic pertaining to the pod's NSX-managed VMs over the Microsoft Azure cloud's network (underlay). Forwarding policies were introduced in NSX-T Data Center 2.4.
You perform these steps in your NSX-T Data Center 2.4 environment.
Procedure
-
Log in to your environment's NSX Manager.
-
Navigate to Networking > Forwarding Policies.
-
On that Forwarding Policies page, expand the section that represents the VNet on which the NSX Public Cloud Gateway (PCG) is deployed for your pod's use.
-
In the expanded section, make a copy of the last rule listed in that section, the one named
CloudDefaultRoute, by right-clicking and selecting Copy rule. -
Set the action of the new copy to Route to Underlay.
-
Click Publish.
Was this page helpful?