Skip to main content

2026 年 8 月 24 日

Replacing a Security Server with an Omnissa Unified Access Gateway Appliance

Replace a security server with a Unified Access Gateway appliance.

Procedure

  1. Uninstall the security server software.

  2. Remove the security server's LDAP entry: vdmadmin -S [-bauthentication_arguments] -r -sserver

    See Removing the Entry for an Omnissa Horizon Connection Server Instance Using the -S Option in the Omnissa Horizon 8 Administration document.

  3. In Omnissa Horizon Console, register the Unified Access Gateway appliance.

  4. At the network firewall between Unified Access Gateway and Horizon Connection Server, remove firewall rules associated with the removed security server and add firewall rules associated with the incoming Unified Access Gateway. The Unified Access Gateway needs to communicate with Horizon Connection Server on TCP port 443.

    The back-end firewall rules for Security Server to Horizon Connection Server are as follows:

    SourceDefault PortProtocolDestinationDefault PortNotes
    Security ServerUDP 500ISAKMPHorizon Connection ServerUDP 500IPsec phase 1 negotiation.
    Security ServerUDP 4500NAT-THorizon Connection ServerUDP 4500Encapsulated AJP13 traffic when using NAT.
    Security ServerESPHorizon Connection ServerEncapsulated AJP13 traffic when NAT traversal is not required. ESP is IP protocol 50. Port numbers are not specified.
    Security ServerAJP13Horizon Connection ServerTCP 8009AJP13 traffic without IPsec and during pairing.
    Security ServerJMSHorizon Connection ServerTCP 4001Message channel for key negotiation.
    Security ServerJMS-TLSHorizon Connection ServerTCP 4002Message channel for management.
  5. Configure and start the Unified Access Gateway appliance.

    See the Unified Access Gateway Deployment and Configuration Guide available at the Unified Access Gateway documentation.

此页面对您有帮助吗?

对本主题提供反馈

本主题对您有帮助吗?

请勿填写任何个人信息或机密信息。

正在生成链接…