From the Horizon Universal Console, you can use the Add Horizon Edge UI to add and deploy a Horizon Edge into your Microsoft Azure subscription.
Introduction
The Horizon Edge is a thin-edge cloud infrastructure. For Microsoft Azure deployments, an Azure subscription is the provider.
After your environment is configured with at least one Active Directory domain and an identity provider, the Horizon Universal Console makes the Add Horizon Edge UI flow available.
Note: After you deploy an edge VM, you cannot change its IP address. Attempting to do so causes edge gateway downtime as the Kubernetes cluster stops working and must be reinitialized. Changing the IP address of a deployed edge VM is not supported.
Edge Deployment Types
As an administrator, you can specify that a Horizon Edge Gateway be deployed in Microsoft Azure as either a Single Virtual Machine or as an Azure Kubernetes Service (AKS). The preferred mode is AKS.
If you choose to deploy the Horizon Edge Gateway as a single virtual machine during initial set-up, you can also change the deployment to AKS later on. However, once the Edge Gateway is deployed successfully in AKS mode, you cannot revert back to single VM mode. If during this change workflow, AKS deployment fails, you can review the error message and retry the workflow to move to AKS or you can revert back to single VM mode.
Note: You cannot change the network connectivity type (Internet to Azure private link) while making the Edge Gateway deployment mode change (single VM to AKS). Only one operation is supported at a time.
Decide which Horizon Edge Gateway deployment type to use based on the qualities that you need.
| Deployment Type | Key Qualities | Details |
|---|---|---|
| Azure Kubernetes Service (AKS) |
| AKS is a Microsoft Azure standard for enterprise cloud-native apps in Microsoft Azure data centers. The AKS type provides an Edge Gateway of a clustered architecture, which provides for replicated services supporting the SSO login experience and monitoring data collections. AKS also allows for high availability (HA). |
| Single Virtual Machine |
|
Even though the Single VM type is simpler to deploy due to less prerequisites than the AKS type, if the deployed VM becomes unavailable, the following may occur:
|
Prerequisites
Before doing these steps in the Horizon Cloud stepper pages, you must verify that you or your IT team have completed the following prerequisites.
As you select items in the Horizon Cloud stepper UI, the system attempts to confirm that specific items are fulfilled. If those requirements are unfulfilled, you are blocked from completing the UI steps. For example, when deploying the AKS deployment type, if the selected NAT gateway in Cluster outbound type is not connected to the selected Management Subnet, when you click Deploy, the UI displays a message and prevents further progress. At that point, you'll have to back out of the UI steps, complete that requirement to connect the NAT gateway with the management subnet, and restart the UI steps from the beginning.
-
Review the Requirements Checklist for Deploying a Microsoft Edge and ensure that those requirements are fulfilled.
-
Review the preparatory items described in the hyperlinked pages within the page Microsoft Azure Edge Deployments and ensure that those items are completed.
-
Verify you have the Azure subscription information, network information, FQDNs, and such items so that you can specify those in the wizard's fields and lists.
-
Verify that the necessary outbound ports are allowed. See Make Appropriate Destination URLs Reachable to Deploy a Horizon Edge Gateway in a Microsoft Azure Environment.
-
If you plan to use a proxy server for routing traffic, it must be reachable via the Edge management subnet.
-
Decide whether you want this Horizon Edge's primary provider to be dedicated to the Horizon Edge Gateway and Unified Access Gateway instances, or if you want the primary provider to also deliver the end-user desktops and applications.
Note: If you want the primary provider dedicated to this Horizon Edge's gateway appliances, you'll need the Azure subscription information for the UI's step of specifying a secondary provider for the desktops and applications.
Prerequisites for Configuring UAG Advanced Mode
-
Ensure that all Horizon Clients connecting to the Edge (for which UAG Advanced mode is being configured) have been upgraded to Horizon HAI agent version 24.12 or above. See the Horizon Cloud Release Notes for related information about HAI agent version requirements.
-
UAG advanced mode is available only for desktop-native clients.
-
When editing a deployed Horizon Edge, if there is a change in the deployment type from Basic to Advanced or Advanced to Basic, the load balancer IP address in the Unified Access Gateway section of the Edge deployment UI page might change. If a change in the load balancer IP does occur, you must update the DNS record with the new IP address.
Note: If the Unified Access Gateway load balancer has a private front-end IP address allocated from a DMZ or VM subnet, the load balancer IP address will change if you select a different subnet while changing the deployment type to or from Basic and Advanced. For more information, see Update Unified Access Gateway Deployment Type and Load Balancer IP Address Impact.
Prerequisites for Deploying the UAG Outside of the Azure Marketplace
When you deploy a UAG, if your Azure Subscription is Azure China, Horizon Cloud automatically creates a storage account in a new resource group and imports the UAG VHD. We then create an image from that VHD in your Azure Subscription. The image version is valid for create, scale-out, scale-in, and upgrade operations. The name of the auto-generated resource group is hcsappimg-{providerInstanceId}-rg. The storage account name is randomly generated because it must be unique across all of Azure. If you do not want Horizon Cloud to automatically create that new resource group or new storage account, you must contact Omnissa Customer Connect and provide Support with the Storage Account ID for one of your existing resource groups or storage accounts so that we can run an API ahead of time to import the VHD into your existing storage account and create the image in an existing resource group. Currently, this capability is available only for an Azure China provider.
Procedure
The console makes the Add Horizon Edge UI stepper available from various entry points. Your starting point in the console for this step typically depends on whether your environment is greenfield or it has existing deployments of Horizon Edge for Horizon 8 or for Microsoft Azure.
-
No Horizon Edges yet - start from the console's Horizon Edge card
If your environment has no Horizon Edges, you can start the wizard by clicking START DEPLOYMENT.
-
No Horizon Edges - alternatively, start from the console's Capacity page
If there are no Horizon Edges deployed in the environment yet, the Capacity page contains text and a Start menu. In this scenario, you can click Capacity and clicking Start > Microsoft Azure to open the UI stepper.
-
At least one Horizon Edge - start from the console's Capacity page
If there is at least one Horizon Edge for Microsoft Azure that has already been created and deployed in your Horizon Cloud environment, click Capacity > Horizon Edges > Add > Horizon Cloud > Microsoft Azure from the Horizon Universal Console to open the Add Horizon Edge stepper page.
General Information
Add a unique Horizon Edge Name that will distinguish this Horizon Edge from others you'll see in the console. You can add an optional description.
Primary Provider
Complete this section. When you have completed this step, continue to the next step.
-
For Azure Subscription, either select one of your environment's existing providers or use Add New to provide new provider subscription information.
When adding new provider subscription information, provide:
-
A unique name for this provider that will distinguish it from others you'll see in the console.
-
Your Microsoft Azure Subscription ID from the Microsoft Azure Portal.
-
Select the Azure Cloud Type, Azure Region, and Directory ID applicable for that Microsoft Azure subscription ID.
-
Provide the service principal's information (the Application ID, Application Key, and Expiry Date) that you created in the Microsoft Azure portal for this purpose.
For related information about expiry of the service principal application key, see Viewing and Managing Notifications.
-
-
If you want to dedicate this provider to the Horizon Edge Gateway and Unified Access Gateway instances and use a separate provider for delivering end user entitled resources, then select the displayed checkbox.
If unselected, this provider will also deliver the end user entitled resources.
-
(Optional): Add up to four additional service principals (the Application ID, Application Key pairs, and Expiry Date).
-
(Optional): If the provider type is Microsoft Azure, you can manage Azure resource tags as needed.
To manage resource tags, perform the steps that follow. See Using Azure Resource Tags for related information.
-
Expand the Advanced node.
-
Click Add.
-
Enter a name and value of a resource tag to be applied to the resource groups in Microsoft Azure.
-
If you want to add additional tags, click Add Tag.
-
Click Done.
-
If the propagate tags option does not apply to your situation, unselect that option.
-
Secondary Providers
Adding secondary providers to a Horizon Edge is optional.
The secondary provider must be in the same Azure region as the primary provider.
For each secondary provider, you can add up to five unique service principals, for a maximum total Horizon Edge capacity of 20,000 VMs.
Networks
In the Networks section, select the tenant (desktop) subnets you want to use for the primary and secondary providers.
You can select the subnets at a later stage. However, the system prevents deploying any resources into a provider until the Horizon Edge has at least one associated tenant subnet.
Site
In the Site section, select from an existing site in your environment or select Add New to add new site information. For a new site, provide a unique name and an optional description.
Connectivity
Complete the Connectivity section.
-
Using the Network connection type option, select the type of network connection to use for this Horizon Edge as either Azure Private Link or Internet.
For related information, see Microsoft Azure Subscription Requirements.
Note: Because Microsoft Azure Government subscriptions do not support Azure Private Link, the connectivity type is fixed as Internet if you selected Azure - US Government as your Azure Cloud Type on the Primary Provider page.
-
In the App Volumes Application Storage section, select the subnet for the Azure private endpoint.
Note: After configuring the private endpoint, users should log out from their virtual machines and log in again.
Option Description Use Edge Gateway management subnet Edge Gateway management subnet where a private endpoint resource is created. It is recommended to use this default option. Configure custom subnet Ensure that you have set up the prerequisites. For information about these prerequisites, see Azure Private Endpoint for an App Volumes Application Storage Account. - Select the confirmation check boxes.
- Select a virtual network from the Private Endpoint vNet drop-down.
- Select the corresponding subnet from the Subnet drop-down.
After the Horizon Edge is deployed and the private endpoint is successfully created, status of the private endpoint is Configured. If the status is Not Configured, the private endpoint can be configured again using the Configure Private Endpoint option in the App Volumes Application Storage section of the Horizon Edge. For more information about using this option, see the Configure Private Endpoint for an App Volumes Application Storage Account section in Horizon Edge Details.
If there are connectivity issues between any of the existing desktop pools and file shares affecting application delivery and you want to revert to the public network access for the storage account until you troubleshoot these issues, then you can use the Remove Private Endpoint option. This option removes the configured private endpoint and automatically enables public network access for the storage account in the Azure portal. After fixing the issues, you can configure the private endpoint using the Configure Private Endpoint option.
Horizon Edge Gateway
In the Horizon Edge Gateway section, select a deployment type (Azure Kubernetes Service or Single Virtual Machine).
-
Azure Kubernetes Service - This option is for Edge Gateway (AKS). The following screenshot shows the type of information displayed and prompted for when you select the Azure Kubernetes Service deployment type. This deployment type is typically used for a production environment.
-
Single Virtual Machine - This option is for Edge Gateway (VM). The following screenshot shows the type of information displayed and prompted for when you select the Single Virtual Machine deployment type. This deployment type is typically used for a simple or proof-of-concept environment.
Note: The UI displays a High Availability string based on the selected deployment type. For the Single Virtual Machine deployment type, the displayed string means that if the VM is unavailable, end users will see the login flow without the SSO login experience and the desktops' monitoring data is not recorded when the VM is unavailable. For the Azure Kubernetes Service deployment type, the displayed string means the SSO login experience and monitoring data collection are handled through replicated services that enable a full failover of those functions.
Note: As stated earlier, you can initially deploy the edge using the Single Virtual Machine deployment type and later change to the Azure Kubernetes Service (AKS) deployment type. You cannot, however, change a successfully deployed edge from the Azure Kubernetes Service (AKS) deployment type to the Single Virtual Machine deployment type.
After selecting the deployment type, configure the Horizon Edge Gateway settings using the instructions for that specific deployment type, as follows. When you have completed the UI fields as displayed for your chosen deployment type, continue to follow the on-screen prompts.
| Deployment Type | Steps |
|---|---|
| Azure Kubernetes Service (AKS) |
For the Azure Kubernetes Service option,
|
| Single Virtual Machine |
For the Single Virtual Machine option,
|
Unified Access Gateway
In the Unified Access Gateway section, complete the following UI step options that are are required for your deployment. Also, see Prerequisites for Configuring UAG Advanced Mode above if you intend to use the Advanced deployment type.
For information about proxy options when specifying UAG outputs, see Port and Protocol Requirements for Your Horizon Cloud Deployment in Microsoft Azure.
For information about deploying the UAG without the use of the Azure Marketplace, see the Prerequisites for Deploying the UAG Outside of the Azure Marketplace section at the top of the page.
-
In the Deployment section, select the Deployment Type of Basic or Advanced. The deployment type setting specifies that load balancer distribution uses either source-ip-affinity or hash.
- Basic - Use for a load balancer scenario with source-ip-affinity to support up to 2000 connections for each Horizon Edge if NAT gateway or firewall configured in front of an Azure load balance.
- Advanced - Use for a load balancer scenario with hash-based affinity to support up to 18000 connections for each Horizon Edge. Use of this option requires that you use a new management subnet with a subnet mask of /28. This UAG management subnet should be in the same vNet, or in a peered vNet, as the Edge management subnet. The new UAG management subnet must be provided with a /28 subnet mask selected from the list.
For example, in scenarios where you deploy a NAT gateway or firewall in front of an Azure load balancer with Basic/source-ip-affinity UAG enabled, only 2000 connections are supported for each Horizon Edge. With Advanced/hash UAG deployment enabled, up to 18000 connections can be supported for each Horizon Edge.
When you click Save to configure the UAG Advanced mode, a message appears staing that UAG advanced mode configuration is in progress. The UAG Advanced mode configuration may take up to 15 minutes to complete.
After the successful configuration of the UAG Advanced mode, the UAG Load balancer IP might change. If so, you might have to update the DNS record with the new IP address.
Note: If the Unified Access Gateway load balancer has a private front-end IP address allocated from a DMZ or VM subnet, the load balancer IP address will change if you select a different subnet while changing the deployment type to or from Basic and Advanced. For more information, see Update Unified Access Gateway Deployment Type and Load Balancer IP Address Impact.
If you select Advanced, you can perform one or more of the following operations:
- If you are deploying the UAG as Blast Extreme, you can specify that either port 8443 or port 443 be used.
- For the Advanced option, the deployer service automatically enables 8445 inbound UDP port on the UAG management NSG.
- You can specify an NTP server and Proxy information, as shown and described in the onscreen help for those options.
- If the provider type is Microsoft Azure, you can manage Azure resource tags as needed, which includes viewing inherited tags, editing and deleting existing tags, and adding tags to be applied to the resource groups specific to this Unified Access Gateway. See Using Azure Resource Tags for the background information on this feature.
For more information about Azure load balancers, see Azure Load Balancer distribution modes.
-
In the Gateway Access section, select an Access Type from the following options:
- Internal access over a corporate network - if you want to reach your VMs over the intranet (internal corporate network) only. A layer 4 load balancer will be deployed with a frontend in the Desktop network.
- External access over the internet - if you want to reach your VMs over the Internet. A layer 4 load balancer will be deployed with a public IP.
- Internal and external access - allow both internal and external access.
Note: For all three options, outbound Internet access to
*.horizon.omnissa.comis required. See Unified Access Gateway Requirements. When using Internal access over a corporate network, either user-defined routing or NAT Gateway can be applied to the Management subnet to allow outbound traffic. When the external access is configured externally with a DMZ network, external access to*.horizon.omnissa.commust be configured on the DMZ network.Note: If you are deploying the Unified Access Gateway as Blast or Blast Extreme, you can specify that either port 8443 or port 443 be used.
Note: If you are using a supported Horizon Edge version, you can also deploy a UAG with a proxy that uses HTTPS instead of HTTP or deploy a UAG with a proxy without being required to provide trusted certificates. To enable these 2 options, contact the Omnissa Ops team at at Omnissa Customer Connect.
-
In the Access Configuration section, select the toggle to enable Automatic Public IP for Unified Access Gateway, or switch off if you prefer to go with manual public IP.
The toggle is switched on by default. If a manual custom IP address is selected, an external Unified Access Gateway is deployed with a private front-end IP address on the DMZ network. You must then take care of the routing from this private IP address to the customer provided public one.
-
In the Gateway VMs section, provide the FQDN or FQDNs for the Unified Access Gateway deployment. The FQDN(s) must be reachable.
When configuring internal and external access, if you want to use the same FQDN, enter the same FQDN in both fields: External FQDN and Internal FQDN.
-
In the Gateway VMs section for the Certificate Type field, select between PEM and PFX from the drop-down menu.
-
In the Gateway VMs section for the Certificate field, upload the certificate that allows clients to trust connections to the Unified Access Gateway in Microsoft Azure.
Note: A self-signed certificate is supported.
Note: The 'SHA256withRSA' signature algorithm is supported and required.
-
In the Gateway VMs section, select the VM Model from the available VM models from the menu.
-
In the Gateway VMs section, add a value in the UAG VMs field.
-
Review the read-only information in the Networking section and specify any editable information.
-
(Optional) Expand the Advanced node if you want to perform one or more of the following operations:
-
You can manage Azure resource tags as needed, which includes viewing inherited tags, editing and deleting existing tags, and adding tags to be applied to the resource groups specific to this Unified Access Gateway. For related information, see Using Azure Resource Tags.
-
If deploying in Azure China, the Azure Marketplace image for the the UAG is not supported. In this scenario, the Unified Access Gateway is copied to an auto-created Azure Storage Account as part of the deployment. This capability is automatically triggered when the UAG deployment uses an Azure China provider. However, you must also add the Storage Blob Data Contributor role to your service principle to support this workflow.
When you deploy a UAG, if your Azure Subscription is Azure China, Horizon Cloud automatically creates a storage account in a new resource group and imports the UAG VHD. We then create an image from that VHD in your Azure Subscription. The image version is valid for create, scale-out, scale-in, and upgrade operations. The resource group, storage account container, and image name will all have the name prefix hcs-app-img. The name of the auto-generated resource group is hcs-app-img-{providerInstanceId}-rg. The storage account name is randomly generated and cannot contain the dash (-) character, thus the name follows the hcsappimg{random-suffix} naming convention.
To instead specify an existing resource group or storage account for this process, contact Support at [Omnissa Customer Connect](https://customerconnect.omnissa.com as described in the Prerequisites for Deploying the UAG Outside of the Azure Marketplace section at the top of the page.
-
-
Click Save.
What to do next
After you complete this procedure, you must create DNS records that match the FQDN you entered for the Unified Access Gateway instances. See Configure Required DNS Records After Deploying Horizon Edge Gateway and Unified Access Gateway.
After you complete the Horizon Cloud deployment and entitle desktops or applications to end users, be aware of how the following Unified Access Gateway behavior affects and benefits end users using Horizon Web Client. If a Unified Access Gateway instance goes into maintenance mode or enters an unhealthy state and becomes inaccessible, ongoing sessions for end users using Horizon Web Client will reconnect to a healthy Unified Access Gateway instance. The reconnection period can take a couple of minutes. Be aware that refreshing the SSL certificate for the Unified Access Gateway terminates end user sessions.
For information about monitoring your deployment, see Monitoring Your Environment.
Questa pagina è stata utile?