KEMP VMware Horizon Access Point Gateway LoadMaster Deployment Guide
Below you will find brief information for LoadMaster VMware Horizon Access Point Gateway. This document provides the recommended LoadMaster settings used when load balancing the VMware Access Point workload for the Horizon View and Horizon Air Hybrid-Mode use cases.
Advertisement
Advertisement
LoadMaster VMware Horizon Access Point Gateway Deployment Guide VERSION: 1.0 UPDATED: OCTOBER 2016 VMware Horizon Access Point Copyright Notices Copyright © 2002-2016 KEMP Technologies, Inc.. All rights reserved.. KEMP Technologies and the KEMP Technologies logo are registered trademarks of KEMP Technologies, Inc.. KEMP Technologies, Inc. reserves all ownership rights for the LoadMaster product line including software and documentation. The use of the LoadMaster Exchange appliance is subject to the license agreement. Information in this guide may be modified at any time without prior notice. Microsoft Windows is a registered trademarks of Microsoft Corporation in the United States and other countries. All other trademarks and service marks are the property of their respective owners. Limitations: This document and all of its contents are provided as-is. KEMP Technologies has made efforts to ensure that the information presented herein are correct, but makes no warranty, express or implied, about the accuracy of this information. If any material errors or inaccuracies should occur in this document, KEMP Technologies will, if feasible, furnish appropriate correctional notices which Users will accept as the sole and exclusive remedy at law or in equity. Users of the information in this document acknowledge that KEMP Technologies cannot be held liable for any loss, injury or damage of any kind, present or prospective, including without limitation any direct, special, incidental or consequential damages (including without limitation lost profits and loss of damage to goodwill) whether suffered by recipient or third party or from any action or inaction whether or not negligent, in the compiling or in delivering or communicating or publishing this document. Any Internet Protocol (IP) addresses, phone numbers or other data that may resemble actual contact information used in this document are not intended to be actual addresses, phone numbers or contact information. Any examples, command display output, network topology diagrams, and other figures included in this document are shown for illustrative purposes only. Any use of actual addressing or contact information in illustrative content is unintentional and coincidental. Portions of this software are; copyright (c) 2004-2006 Frank Denis. All rights reserved; copyright (c) 2002 Michael Shalayeff. All rights reserved; copyright (c) 2003 Ryan McBride. All rights reserved. Redistribution and use in source and binary forms, with or without modification, are permitted provided that the following conditions are met: 1. Redistributions of source code must retain the above copyright notice, this list of conditions and the following disclaimer 2. Redistributions in binary form must reproduce the above copyright notice, this list of conditions and the following disclaimer in the documentation and/or other materials provided with the distribution. THIS SOFTWARE IS PROVIDED BY THE ABOVE COPYRIGHT HOLDERS ''AS IS'' AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE ARE DISCLAIMED. IN NO EVENT SHALL THE ABOVE COPYRIGHT HOLDERS OR CONTRIBUTORS BE LIABLE FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION) HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE. The views and conclusions contained in the software and documentation are those of the authors and should not be interpreted as representing official policies, either expressed or implied, of the above copyright holders.. Portions of the LoadMaster software are copyright (C) 1989, 1991 Free Software Foundation, Inc. -51 Franklin Street, Fifth Floor, Boston, MA 02110-1301, USA- and KEMP Technologies Inc. is in full compliance of the GNU license requirements, Version 2, June 1991. Everyone is permitted to copy and distribute verbatim copies of this license document, but changing it is not allowed. Copyright © 2002 - 2016 KEMP Technologies, Inc. All Rights Reserved. 2 VMware Horizon Access Point Portions of this software are Copyright (C) 1988, Regents of the University of California. All rights reserved. Redistribution and use in source and binary forms are permitted provided that the above copyright notice and this paragraph are duplicated in all such forms and that any documentation, advertising materials, and other materials related to such distribution and use acknowledge that the software was developed by the University of California, Berkeley. The name of the University may not be used to endorse or promote products derived from this software without specific prior written permission. THIS SOFTWARE IS PROVIDED ``AS IS'' AND WITHOUT ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, WITHOUT LIMITATION, THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE. Portions of this software are Copyright (C) 1998, Massachusetts Institute of Technology Permission is hereby granted, free of charge, to any person obtaining a copy of this software and associated documentation files (the "Software"), to deal in the Software without restriction, including without limitation the rights to use, copy, modify, merge, publish, distribute, sublicense, and/or sell copies of the Software, and to permit persons to whom the Software is furnished to do so, subject to the following conditions: The above copyright notice and this permission notice shall be included in all copies or substantial portions of the Software. THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM, OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE SOFTWARE. Portions of this software are Copyright (C) 1995-2004, Jean-loup Gailly and Mark Adler This software is provided 'as-is', without any express or implied warranty. In no event will the authors be held liable for any damages arising from the use of this software. Permission is granted to anyone to use this software for any purpose, including commercial applications, and to alter it and redistribute it freely, subject to the following restrictions: 1. The origin of this software must not be misrepresented; you must not claim that you wrote the original software. If you use this software in a product, an acknowledgment in the product documentation would be appreciated but is not required. 2. Altered source versions must be plainly marked as such, and must not be misrepresented as being the original software. 3. This notice may not be removed or altered from any source distribution. Portions of this software are Copyright (C) 2003, Internet Systems Consortium Permission to use, copy, modify, and/or distribute this software for any purpose with or without fee is hereby granted, provided that the above copyright notice and this permission notice appear in all copies. THE SOFTWARE IS PROVIDED "AS IS" AND THE AUTHOR DISCLAIMS ALL WARRANTIES WITH REGARD TO THIS SOFTWARE INCLUDING ALL IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS. IN NO EVENT SHALL THE AUTHOR BE LIABLE FOR ANY SPECIAL, DIRECT, INDIRECT, OR CONSEQUENTIAL DAMAGES OR ANY DAMAGES WHATSOEVER RESULTING FROM LOSS OF USE, DATA OR PROFITS, WHETHER IN AN ACTION OF CONTRACT, NEGLIGENCE OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR PERFORMANCE OF THIS SOFTWARE. Used, under license, U.S. Patent Nos. 6,473,802, 6,374,300, 8,392,563, 8,103,770, 7,831,712, 7,606,912, 7,346,695, 7,287,084 and 6,970,933 Copyright © 2002 - 2016 KEMP Technologies, Inc. All Rights Reserved. 3 VMware Horizon Access Point Table of Contents 1 Introduction ............................................................................................................................... 5 1.1 Document Purpose ............................................................................................................ 5 1.2 Intended Audience ............................................................................................................. 5 1.3 About this Document ......................................................................................................... 5 2 VMware Application Server Template ....................................................................................... 6 3 Architecture ............................................................................................................................... 7 4 Horizon Protocols....................................................................................................................... 8 5 6 4.1 Primary Horizon Protocol ................................................................................................... 8 4.2 Secondary Horizon Protocols ............................................................................................. 8 Configure the LoadMaster ......................................................................................................... 9 5.1 Enable Subnet Originating Requests Globally.................................................................... 9 5.2 Enable Check Persist Globally .......................................................................................... 10 Session Affinity Options ........................................................................................................... 11 6.1 Method 1 - Source IP Affinity ........................................................................................... 11 6.1.1 6.2 Method 2 - Multiple Port Number Groups ...................................................................... 15 6.2.1 6.3 Create the VMware Access Point Source IP Affinity Virtual Services ...................... 12 Create the VMware Access Point Multiple Port Number Groups Virtual Services .. 17 Method 3 - Multiple VIPs ................................................................................................. 25 6.3.1 Create the Multiple VIPs Virtual Services ................................................................ 27 References ....................................................................................................................................... 36 Document History ............................................................................................................................ 37 Copyright © 2002 - 2016 KEMP Technologies, Inc. All Rights Reserved. 4 VMware Horizon Access Point Introduction 1 Introduction Access Point is a Unified Gateway from VMware that comes in virtual appliance format and is designed to protect desktop and application resources to enable remote access from the Internet. Access Point is the default gateway for the following products: VMware Horizon View VMware Horizon Air (DaaS) VMware Horizon Air Hybrid-Mode VMware Identity Manager Airwatch Tunnel Gateway/Proxy The KEMP LoadMaster is used to load balance the VMware Access Point workload. The LoadMaster offers advanced Layer 4 and Layer 7 server load balancing, SSL Acceleration and a multitude of other advanced Application Delivery Controller (ADC) features. The LoadMaster intelligently and efficiently distributes user traffic among the application servers so that users get the best experience possible. 1.1 Document Purpose This document provides the recommended LoadMaster settings used when load balancing the VMware Access Point workload for the Horizon View and Horizon Air Hybrid-Mode use cases. The KEMP Support Team is available to provide solutions for scenarios not explicitly defined. The KEMP support site can be found at: https://support.kemptechnologies.com 1.2 Intended Audience This document is intended to be read by anyone who is interested in configuring the LoadMaster to optimize VMware Access Point Server. 1.3 About this Document This document was written with help from Mark Benson and Vish Kalsi of VMware. Some of the content in this document is based on the following VMware document: https://communities.vmware.com/docs/DOC-32792 In addition, you can find more information at https://www.vmware.com/support/pubs/access-pointpubs.html Copyright © 2002 - 2016 KEMP Technologies, Inc. All Rights Reserved. 5 VMware Horizon Access Point VMware Application Server Template 2 VMware Application Server Template KEMP has developed a template containing our recommended settings for VMware. You can install this template on the LoadMaster and use it when creating Virtual Services. Using a template automatically populates the settings in the Virtual Services, which is quicker and easier than manually configuring each Virtual Service. If needed, you can make changes to any of the Virtual Service settings after using the template. Download released templates from the Templates section on the KEMP documentation page: http://kemptechnologies.com/documentation/. For more information and steps on how to import and use templates, refer to the Virtual Services and Templates, Feature Description. For steps on how to manually add and configure each of the Virtual Services, refer to Section 5 of this document. Copyright © 2002 - 2016 KEMP Technologies, Inc. All Rights Reserved. 6 VMware Horizon Access Point Architecture 3 Architecture Access Point is typically deployed in a DMZ. For high availability and scalability requirements in a production deployment, several Access Point appliances are usually set up behind a load balancer as shown in Figure 3-1. The LoadMaster is deployed in-line as a proxy for all services including PCoIP. Alternative deployment options could have the secondary Horizon protocols bypass the LoadMaster as it is only the initial session establishment (HTTPS) that can be load balanced. Figure 3-1: Multiple Access Point Appliances behind a Load Balancer This deployment guide focuses on the load balancing requirements for the Horizon View and Horizon Air Hybrid-Mode use cases. It discusses the distinction between the primary and secondary Horizon protocols and describes the three methods for guaranteeing session affinity. The three methods ensure that all protocol traffic from a Horizon client session goes to the same Access Point appliance. This article also covers health monitoring and SSL offload/SSL bridging for load balancers. Copyright © 2002 - 2016 KEMP Technologies, Inc. All Rights Reserved. 7 VMware Horizon Access Point Horizon Protocols 4 Horizon Protocols When a Horizon Client user connects to a Horizon environment, several different protocols are used. The first connection is always the primary XML-API protocol over HTTPS. Following successful authentication, one or more secondary protocols are also made. 4.1 Primary Horizon Protocol The user enters a hostname at the Horizon Client and this starts the primary Horizon protocol. This is a control protocol for authentication, authorization and session management. It uses XML-structured messages over HTTPS (HTTP over SSL). This protocol is sometimes known as the Horizon XML-API control protocol. In a load-balanced environment as shown in Section 3, the load balancer routes this connection to one of the Access Point appliances. The load balancer usually selects the appliance based first on availability, and then out of the available appliances will route traffic based on the least number of current sessions. This has the effect of evenly distributing the traffic from different clients across the available set of Access Point appliances. 4.2 Secondary Horizon Protocols After the Horizon Client has established a secure communication to one of the Access Point appliances, the user authenticates. If this authentication attempt is successful, then one or more secondary connections are made from the Horizon client. These secondary connections can include: HTTPS Tunnel used for encapsulating TCP protocols such as RDP, MMR/CDR and the client framework channel (TCP 443). Blast Extreme display protocol (TCP 443 and UDP 443). PCoIP display protocol (TCP 4172 and UDP 4172). These secondary Horizon protocols must be routed to the same Access Point appliance to which the primary Horizon protocol is routed. This is so that Access Point can authorize the secondary protocols based on the authenticated user session. An important security capability of Access Point is that it will only forward traffic into the corporate datacenter if the traffic is on behalf of an authenticated user. If the secondary protocols were to be misrouted to a different Access Point appliance to the primary protocol one, they would not be authorized and would therefore be dropped in the DMZ and the connection would fail. Misrouting the secondary protocols is a common problem if the Load Balancer is not configured correctly. Copyright © 2002 - 2016 KEMP Technologies, Inc. All Rights Reserved. 8 VMware Horizon Access Point Configure the LoadMaster 5 Configure the LoadMaster The deployed VMware Access Point environment determines which of the following setups is used. 5.1 Enable Subnet Originating Requests Globally It is best practice to enable the Subnet Originating Requests option globally. In a one-armed setup (where the Virtual Service and Real Servers are on the same network/subnet), Subnet Originating Requests is usually not needed. However, enabling Subnet Originating Requests should not affect the routing in a one-armed setup. In a two-armed setup where the Virtual Service is on network/subnet A, for example, and the Real Servers are on network B - Subnet Originating Requests should be enabled on LoadMasters with firmware version 7.1-16 and above. When Subnet Originating Requests is enabled, the LoadMaster routes traffic so that the Real Server sees traffic arriving from the LoadMaster interface that is in that network/subnet. When Subnet Originating Requests is enabled globally, it is automatically enabled on all Virtual Services. If the Subnet Originating Requests option is disabled globally, you can select whether or not to enable Subnet Originating Requests on a per-Virtual Service basis. To enable Subnet Originating Requests globally, follow the steps below: 1. In the main menu of the LoadMaster WUI, go to System Configuration > Miscellaneous Options > Network Options. Figure 5-1: Subnet Originating Requests 2. Select the Subnet Originating Requests check box. Copyright © 2002 - 2016 KEMP Technologies, Inc. All Rights Reserved. 9 VMware Horizon Access Point Configure the LoadMaster 5.2 Enable Check Persist Globally It is recommended that you change the Always Check Persist option to Yes – Accept Changes. Use the following steps: 1. Go to System Configuration > Miscellaneous Options > L7 Configuration. Figure 5-2: Enable Check Persist Globally 2. Click the Always Check Persist dropdown arrow and select Yes – Accept Changes. Copyright © 2002 - 2016 KEMP Technologies, Inc. All Rights Reserved. 10 VMware Horizon Access Point Session Affinity Options 6 Session Affinity Options There are three main configuration options for session affinity. These are: 6.1 Source IP Affinity Multiple Port Number Groups Multiple VIPs Method 1 - Source IP Affinity Method 1 is recommended for all environments where source IP address affinity is possible. Where it is not possible, then either method 2 or method 3 should be used. Method 1 is the simplest configuration for a load balancer because it uses standard port numbers and a single load balanced VIP. It relies on the load balancer to route secondary protocols to the same Access Point appliance as was selected for the primary Horizon protocol. It does this on the basis of repeat connections coming from the same Horizon client IP address. Unfortunately, this method does not work in all situations. For example, with certain Network Service Providers or NAT devices, the source IP address is not available for this affinity configuration. If source IP affinity cannot be used in your environment, then one of the other two methods should be used as they do not rely on source IP affinity. Access Point Configuration for External URLs for this configuration is shown in the following table. In our example, the Fully Qualified Domain Name (FQDN) http://ap.myco.com resolves to 10.1.160.35. Access Point Appliance Configuration Item Value AP01 tunnelExternalURL https://ap.myco.com:443 AP01 blastExternalURL https://ap.myco.com:443 AP01 pcoipExternalURL 10.1.160.35:4172 AP02 tunnelExternalURL https://ap.myco.com:443 AP02 blastExternalURL https://ap.myco.com:443 AP02 pcoipExternalURL 10.1.160.35:4172 Table 6-1: Access Point Configuration for External URLs Advantages of Source IP Affinity Uses standard port numbers Does not require multiple public virtual IP addresses Disadvantages of Source IP Affinity Relies on source IP address affinity, which is not always possible. Copyright © 2002 - 2016 KEMP Technologies, Inc. All Rights Reserved. 11 VMware Horizon Access Point Session Affinity Options 6.1.1 Create the VMware Access Point Source IP Affinity Virtual Services The following sections describe the recommended settings for the VMware Access Point Source IP Affinity Virtual Services. 6.1.1.1 Create a APLB TCP-IP Affinity Virtual Service The following are the steps involved and the recommended settings to configure the APLB TCP-IP Affinity HTTP Virtual Service: 1. In the main menu of the LoadMaster Web User Interface (WUI), go to Virtual Services > Add New. Figure 6-1: Virtual Service parameters 2. 3. 4. 5. 6. Type a valid Virtual Address. Type 443 as the Port. Enter a recognizable Service Name, such as APLB TCP-IP Affinity. Click Add this Virtual Service. Configure the settings as recommended in the following table: Section Option Value Comment Standard Options Extra Ports Persistence Mode Timeout Scheduling Method Add a Port 80 Redirector VS 4172 Source IP Address 6 minutes least connection Click Set Extra Ports. Real Server Check Method URL HTTPS Protocol /favicon.ico Advanced Properties Real Servers Click the Add HTTP Redirector button. This automatically creates a redirect on port 80. Table 6-2: APLB TCP-IP Affinity Recommended Settings 7. Add the Real Servers: a) Expand the Real Servers section. Copyright © 2002 - 2016 KEMP Technologies, Inc. All Rights Reserved. 12 VMware Horizon Access Point Session Affinity Options b) c) d) e) f) Click Add New. Type the address of the relevant Real Server. Complete the other fields as required. Click Add this Real Server then click OK to the pop-up message. Repeat the steps above to add more Real Servers as needed, based on your environment. Create an APLB TCP-IP Affinity HTTPS HTTP Redirect Virtual Service Clicking the Add HTTP Redirector button automatically creates a port 80 redirect Virtual Service. This is optional, but the purpose of this Virtual Service is to redirect any clients who have connected using HTTP to the HTTPS Virtual Service. 6.1.1.2 Create an APLB UDP 443 Affinity Virtual Service The following are the steps involved and the recommended settings to configure the APLB UDP 443 Affinity Virtual Service: 1. In the main menu of the LoadMaster Web User Interface (WUI), go to Virtual Services > Add New. Figure 6-2: Virtual Service parameters 2. 3. 4. 5. 6. 7. Type a valid Virtual Address. Type 443 as the Port. Enter a recognizable Service Name, such as APLB UDP 443 Affinity. Select udp as the Protocol. Click Add this Virtual Service. Configure the settings as recommended in the following table: Section Option Value Standard Options Force L4 Persistence Mode Timeout Port Following Disabled Source IP Address 6 minutes tcp/10.1.160.35:443 Real Server Check Method ICMP Ping Advanced Properties Real Servers Copyright © 2002 - 2016 KEMP Technologies, Inc. All Rights Reserved. 13 VMware Horizon Access Point Session Affinity Options Table 6-3: APLB UDP 443 Affinity Recommended Settings 8. Add the Real Servers: a) Expand the Real Servers section. b) Click Add New. c) Type the address of the relevant Real Server. d) Complete the other fields as required. e) Click Add this Real Server then click OK to the pop-up message. f) Repeat the steps above to add more Real Servers as needed, based on your environment. 6.1.1.3 Create an APLB - UDP 4172 - Affinity Virtual Service The following are the steps involved and the recommended settings to configure the APLB - UDP 4172 Affinity Virtual Service: 1. In the main menu of the LoadMaster Web User Interface (WUI), go to Virtual Services > Add New. Figure 6-3: Virtual Service parameters 2. 3. 4. 5. 6. 7. Type a valid Virtual Address. Type 4172 as the Port. Enter a recognizable Service Name, such as APLB - UDP 4172. Select udp as the Protocol. Click Add this Virtual Service. Configure the settings as recommended in the following table: Section Option Value Standard Options Force L4 Persistence Mode Timeout Port Following Disabled Source IP Address 6 minutes tcp/10.1.160.35:443 Real Server Check Method ICMP Ping Advanced Properties Real Servers Table 6-4: APLB UDP 4172 Affinity Recommended Settings Copyright © 2002 - 2016 KEMP Technologies, Inc. All Rights Reserved. 14 VMware Horizon Access Point Session Affinity Options 8. Add the Real Servers: a) Expand the Real Servers section. b) Click Add New. c) Type the address of the relevant Real Server. d) Complete the other fields as required. e) Click Add this Real Server then click OK to the pop-up message. f) Repeat the steps above to add more Real Servers as needed, based on your environment. 6.2 Method 2 - Multiple Port Number Groups Multiple port group affinity does not rely on source IP address for affinity. Instead, the load balancer is configured to route the secondary Horizon protocols based on a group of unique port numbers assigned to each Access Point appliance. The primary Horizon protocol on HTTPS port 443 is load balanced to allocate the session to a specific Access Point appliance based on health and least loaded. The secondary connections are then routed to the correct Access Point appliance based on the following Load Balancer configuration table. Virtual IP Address Primary/Secondary Protocol Name Real Servers 10.1.160.31:443 Primary TCP APLB HTTPS 10.1.160.183:443 10.1.160.184:443 10.1.160.31:10143 Secondary TCP AP01 HTTPS 10.1.160.183:443 10.1.160.31:10143 Secondary UDP AP01 BLASTUDP 10.1.160.183:443 10.1.160.31:10172 Secondary TCP AP01 PCOIP 10.1.160.183:4172 10.1.160.31:10172 Secondary UDP AP01 PCOIPUDP 10.1.160.183:4172 10.1.160.31:10243 Secondary TCP AP02 HTTPS 10.1.160.184:443 10.1.160.31:10243 Secondary UDP AP02 BLASTUDP 10.1.160.184:443 10.1.160.31:10272 Secondary TCP AP02 PCOIP 10.1.160.184:4172 Copyright © 2002 - 2016 KEMP Technologies, Inc. All Rights Reserved. 15 VMware Horizon Access Point Session Affinity Options Virtual IP Address Primary/Secondary Protocol Name Real Servers 10.1.160.31:10272 Secondary UDP AP02 PCOIPUDP 10.1.160.184:4172 Table 6-5: Load Balancer Configuration Table The same port mapping scheme can be used for additional Access Point appliances 03 > 99. For example, we use the following mapping convention in this document for two access points: 10143 → AP01 443 10172 → AP01 4172 10243 → AP02 443 10272 → AP02 4172 The same convention is used for multiple access points: 10343 → AP03 443 10372 → AP03 4172 The Access Point Configuration for External URLs is shown below. In our example, the FQDN http://ap.myco.com resolves to 10.1.160.31. Access Point Appliance Configuration Item Value AP01 tunnelExternalURL https://ap.myco.com:10143 AP01 blastExternalURL https://ap.myco.com:10143 AP01 pcoipExternalURL 10.1.60.31:10172 AP02 tunnelExternalURL https://ap.myco.com:10243 AP02 blastExternalURL https://ap.myco.com:10243 AP02 pcoipExternalURL 10.1.60.31:10272 Table 6-6: Access Point Configuration for External URLs Advantages of Multiple Port Number Groups Does not rely on source IP affinity Does not require multiple public virtual IP addresses Disadvantages of Multiple Port Number Groups Uses non-standard port numbers from the Internet although the port numbers on the Access Point appliances themselves are standard. Copyright © 2002 - 2016 KEMP Technologies, Inc. All Rights Reserved. 16 VMware Horizon Access Point Session Affinity Options 6.2.1 Create the VMware Access Point Multiple Port Number Groups Virtual Services The following sections describe the recommended settings for the VMware Access Point Multiple Port Number Groups Virtual Services. 6.2.1.1 Create a APLB – HTTPS – Multiple Ports Virtual Service The following are the steps involved and the recommended settings to configure the APLB – HTTPS – Multiple Ports Virtual Service: 1. In the main menu of the LoadMaster Web User Interface (WUI), go to Virtual Services > Add New. Figure 6-4: Virtual Service parameters 2. Type a valid Virtual Address. 3. Type 443 as the Port. 4. Enter a recognizable Service Name, such as APLB – HTTPS Multiple Ports. 5. Click Add this Virtual Service. 6. Configure the settings as recommended in the following table: Section Option Advanced Properties Add a Port 80 Redirector VS Basic Properties Standard Options Service Type Persistence Mode Timeout Scheduling Method Real Server Check Method URL Real Servers Value Comment Click the Add HTTP Redirector button. This automatically creates a redirect on port 80. Generic SSL Session ID 6 minutes least connection HTTPS Protocol /favicon.ico Table 6-7: APLB – HTTPS – Multiple Ports Recommended Settings 7. Add the Real Servers: Copyright © 2002 - 2016 KEMP Technologies, Inc. All Rights Reserved. 17 VMware Horizon Access Point Session Affinity Options a) b) c) d) e) f) g) Expand the Real Servers section. Click Add New. Type the address of the relevant Real Server. Type 443 as the port number. Complete the other fields as required. Click Add this Real Server then click OK to the pop-up message. Repeat the steps above to add more Real Servers as needed, based on your environment. Create an APLB – HTTPS – Multiple Ports HTTPS HTTP Redirect Virtual Service Clicking the Add HTTP Redirector button automatically creates a port 80 redirect Virtual Service. This is optional, but the purpose of this Virtual Service is to redirect any clients who have connected using HTTP to the HTTPS Virtual Service. 6.2.1.2 Create an AP01 – HTTPS – Multiple Ports Virtual Service The following are the steps involved and the recommended settings to configure the AP01 – HTTPS – Multiple Ports Virtual Service: 1. In the main menu of the LoadMaster Web User Interface (WUI), go to Virtual Services > Add New. Figure 6-5: Virtual Service parameters 2. 3. 4. 5. 6. Type a valid Virtual Address. Type 10143 as the Port. Enter a recognizable Service Name, such as AP01 – HTTPS – Multiple Ports. Click Add this Virtual Service. Configure the settings as recommended in the following table: Section Option Value Basic Properties Standard Options Real Servers Service Type Force L4 Real Server Check Method Checked Port URL HTTP/HTTPS Disabled HTTPS Protocol 443 /favicon.ico Copyright © 2002 - 2016 KEMP Technologies, Inc. All Rights Reserved. 18 VMware Horizon Access Point Session Affinity Options Table 6-8: AP01 – HTTPS – Multiple Ports Recommended Settings 7. Add the Real Servers: a) Expand the Real Servers section. b) Click Add New. c) Type the address of the relevant Real Server. d) Type 443 as the port number. e) Complete the other fields as required. f) Click Add this Real Server then click OK to the pop-up message. g) Repeat the steps above to add more Real Servers as needed, based on your environment. 6.2.1.3 Create an AP01 – BLAST–UDP Multiple Ports Virtual Service The following are the steps involved and the recommended settings to configure the AP01 – Blast-UDP Multiple Ports Virtual Service: 1. In the main menu of the LoadMaster Web User Interface (WUI), go to Virtual Services > Add New. Figure 6-6: Virtual Service parameters 2. Type a valid Virtual Address. 3. Type 10143 as the Port. 4. Enter a recognizable Service Name, such as AP01 – BLAST-UDP Multiple Ports. Select udp as the Protocol. 5. Click Add this Virtual Service. 6. Configure the settings as recommended in the following table: Section Option Value Standard Options Real Servers Force L4 Real Server Check Method Disabled ICMP Ping Table 6-9: AP01 – BLAST-UDP Multiple Ports Recommended Settings 7. Add the Real Servers: a) Expand the Real Servers section. b) Click Add New. Copyright © 2002 - 2016 KEMP Technologies, Inc. All Rights Reserved. 19 VMware Horizon Access Point Session Affinity Options c) d) e) f) g) 6.2.1.4 Type the address of the relevant Real Server. Type 443 as the Port. Complete the other fields as required. Click Add this Real Server then click OK to the pop-up message. Repeat the steps above to add more Real Servers as needed, based on your environment. Create an AP01 – PCOIP Multiple Ports Virtual Service The following are the steps involved and the recommended settings to configure the AP01 – PCOIP Multiple Ports Virtual Service: 1. In the main menu of the LoadMaster Web User Interface (WUI), go to Virtual Services > Add New. Figure 6-7: Virtual Service parameters 2. 3. 4. 5. 6. Type a valid Virtual Address. Type 10172 as the Port. Enter a recognizable Service Name, such as AP01 – PCOIP Multiple Ports. Click Add this Virtual Service. Configure the settings as recommended in the following table: Section Option Value Standard Options Real Servers Force L4 Checked Port Disabled 4172 Table 6-10: AP01 – PCOIP Multiple Ports Recommended Settings 7. Add the Real Servers: a) Expand the Real Servers section. b) Click Add New. c) Type the address of the relevant Real Server. d) Type 4172 as the Port. e) Complete the other fields as required. f) Click Add this Real Server then click OK to the pop-up message. g) Repeat the steps above to add more Real Servers as needed, based on your environment. Copyright © 2002 - 2016 KEMP Technologies, Inc. All Rights Reserved. 20 VMware Horizon Access Point Session Affinity Options 6.2.1.5 Create an AP01 – PCOIP-UDP Multiple Ports Virtual Service The following are the steps involved and the recommended settings to configure the AP01 – PCOIPUDP Multiple Ports Virtual Service: 1. In the main menu of the LoadMaster Web User Interface (WUI), go to Virtual Services > Add New. Figure 6-8: Virtual Service parameters 2. 3. 4. 5. 6. 7. Type a valid Virtual Address. Type 10172 as the Port. Enter a recognizable Service Name, such as AP01 – PCOIP-UDP. Select udp as the Protocol. Click Add this Virtual Service. Configure the settings as recommended in the following table: Section Option Value Standard Options Real Servers Force L4 Real Server Check Method Disabled ICMP Ping Table 6-11: AP01 – PCOIP-UDP Multiple Ports Recommended Settings 8. Add the Real Servers: a) Expand the Real Servers section. b) Click Add New. c) Type the address of the relevant Real Server. d) Type 4172 as the Port. e) Complete the other fields as required. f) Click Add this Real Server then click OK to the pop-up message. g) Repeat the steps above to add more Real Servers as needed, based on your environment. 6.2.1.6 Create an AP02 – HTTPS Multiple Ports Virtual Service The following are the steps involved and the recommended settings to configure the AP02 – HTTPS Multiple Ports Virtual Service: Copyright © 2002 - 2016 KEMP Technologies, Inc. All Rights Reserved. 21 VMware Horizon Access Point Session Affinity Options 1. In the main menu of the LoadMaster Web User Interface (WUI), go to Virtual Services > Add New. Figure 6-9: Virtual Service parameters 2. 3. 4. 5. 6. Type a valid Virtual Address. Type 10243 as the Port. Enter a recognizable Service Name, such as AP02 – HTTPS. Click Add this Virtual Service. Configure the settings as recommended in the following table: Section Option Value Basic Properties Standard Options Real Servers Service Type Force L4 Real Server Check Method Checked Port URL HTTP/HTTPS Disabled HTTPS Protocol 443 /favicon.ico Table 6-12: AP02 – HTTPS Multiple Ports Recommended Settings 7. Add the Real Servers: a) Expand the Real Servers section. b) Click Add New. c) Type the address of the relevant Real Server. d) Type 443 as the Port. e) Complete the other fields as required. f) Click Add this Real Server then click OK to the pop-up message. g) Repeat the steps above to add more Real Servers as needed, based on your environment. 6.2.1.7 Create an AP02 – BLAST-UDP Multiple Ports Virtual Service The following are the steps involved and the recommended settings to configure the AP02 – Blast-UDP Multiple Ports Virtual Service: 1. In the main menu of the LoadMaster Web User Interface (WUI), go to Virtual Services > Add New. Copyright © 2002 - 2016 KEMP Technologies, Inc. All Rights Reserved. 22 VMware Horizon Access Point Session Affinity Options Figure 6-10: Virtual Service parameters 2. 3. 4. 5. 6. Type a valid Virtual Address. Type 10243 as the Port. Enter a recognizable Service Name, such as AP02 – BLAST-UDP. Click Add this Virtual Service. Configure the settings as recommended in the following table: Section Option Value Standard Options Real Servers Force L4 Real Server Check Method Disabled HTTPS Protocol Table 6-13: AP02 – BLAST-UDP Multiple Ports Recommended Settings 7. Add the Real Servers: a) Expand the Real Servers section. b) Click Add New. c) Type the address of the relevant Real Server. d) Type 443 as the Port. e) Complete the other fields as required. f) Click Add this Real Server then click OK to the pop-up message. g) Repeat the steps above to add more Real Servers as needed, based on your environment. 6.2.1.8 Create an AP02 – PCOIP Multiple Ports Virtual Service The following are the steps involved and the recommended settings to configure the AP02 – PCOIP Multiple Ports Virtual Service: 1. In the main menu of the LoadMaster Web User Interface (WUI), go to Virtual Services > Add New. Copyright © 2002 - 2016 KEMP Technologies, Inc. All Rights Reserved. 23 VMware Horizon Access Point Session Affinity Options Figure 6-11: Virtual Service parameters 2. 3. 4. 5. 6. Type a valid Virtual Address. Type 10272 as the Port. Enter a recognizable Service Name, such as AP02 – PCOIP. Click Add this Virtual Service. Configure the settings as recommended in the following table: Section Option Value Standard Options Force L4 Scheduling Method Checked Port Disabled round robin 4172 Real Servers Table 6-14: AP02 - PCOIP Multiple VIPs Recommended Settings 7. Add the Real Servers: a) Expand the Real Servers section. b) Click Add New. c) Type the address of the relevant Real Server. d) Type 4172 as the Port. e) Complete the other fields as required. f) Click Add this Real Server then click OK to the pop-up message. g) Repeat the steps above to add more Real Servers as needed, based on your environment. 6.2.1.9 Create an AP02 – PCOIP-UDP Multiple Ports Virtual Service The following are the steps involved and the recommended settings to configure the AP02 – PCOIPUDP Multiple Ports Virtual Service: 1. In the main menu of the LoadMaster Web User Interface (WUI), go to Virtual Services > Add New. Copyright © 2002 - 2016 KEMP Technologies, Inc. All Rights Reserved. 24 VMware Horizon Access Point Session Affinity Options Figure 6-12: Virtual Service parameters 2. 3. 4. 5. 6. Type a valid Virtual Address. Type 10272 as the Port. Enter a recognizable Service Name, such as AP02 – PCOIP-UDP. Click Add this Virtual Service. Configure the settings as recommended in the following table: Section Option Value Standard Options Real Servers Force L4 Real Server Check Method Disabled ICMP Ping Table 6-15: AP02 – PCOIP-UDP Multiple VIPs Recommended Settings 7. Add the Real Servers: a) Expand the Real Servers section. b) Click Add New. c) Type the address of the relevant Real Server. d) Type 4172 as the Port. e) Complete the other fields as required. f) Click Add this Real Server then click OK to the pop-up message. g) Repeat the steps above to add more Real Servers as needed, based on your environment. 6.3 Method 3 - Multiple VIPs This method is similar to the multiple port groups method except instead of dedicating a group of port numbers to each Access Point appliance, it dedicates an individual VIP to each appliance in addition to the primary load balanced VIP. If you have two Access Point appliances, then you would set up three VIPs. The primary Horizon protocol on HTTPS port 443 is load balanced to allocate the session to a specific Access Point appliance based on health and least loaded. The secondary connections are then routed to the correct Access Point appliance based on the following Load Balancer configuration table. Access Point Configurations for External URLs for this configuration are shown in the following table. Copyright © 2002 - 2016 KEMP Technologies, Inc. All Rights Reserved. 25 VMware Horizon Access Point Session Affinity Options Virtual IP Address 10.1.160.32:443 Primary/Secondary Protocol Primary TCP Name Real Servers APLB - HTTPS 10.1.160.186:443 10.1.160.187:443 10.1.160.33:443 Secondary TCP AP01 - HTTPS 10.1.160.186:443 10.1.160.33:443 Secondary UDP AP01 - BLAST-UDP 10.1.160.186:443 10.1.160.33:4172 Secondary TCP AP01 - PCOIP 10.1.160.186:4172 10.1.160.33:4172 Secondary UDP AP01 - PCOIP-UDP 10.1.160.186:4172 10.1.160.34:443 Secondary TCP AP02 - HTTPS 10.1.160.187:443 10.1.160.34:443 Secondary UDP AP02 - BLAST-UDP 10.1.160.187:443 10.1.160.34:4172 Secondary TCP AP02 - PCOIP 10.1.160.187:4172 10.1.160.34:4172 Secondary UDP AP02 - PCOIP-UDP 10.1.160.187:4172 Table 6-16: Load Balancer Configuration Table In our example, the FQDN http://ap1.myco.com resolves to 10.1.160.33 and https://ap2.myco.com:4172 resolves to 10.1.160.34 Access Point Appliance Configuration Item Value AP01 tunnelExternalURL https://ap1.myco.com:443 AP01 blastExternalURL https://ap1.myco.com:443 AP01 pcoipExternalURL 10.20.30.33:4172 AP02 tunnelExternalURL https://ap2.myco.com:443 AP02 blastExternalURL https://ap2.myco.com:4172 AP02 pcoipExternalURL 10.20.30.34:4172 Table 6-17: Access Point Configuration for External URLs Advantages of multiple VIPs Do not rely on source IP affinity Uses standard port numbers Disadvantages of multiple VIPs Requires an additional public facing VIP for each Access Point appliance in addition to the primary load balanced VIP. Copyright © 2002 - 2016 KEMP Technologies, Inc. All Rights Reserved. 26 VMware Horizon Access Point Session Affinity Options 6.3.1 Create the Multiple VIPs Virtual Services The following sections describe the recommended settings for the VMware Access Point Multiple VIPs Virtual Services. 6.3.1.1 Create an HTTPS-APLB Multiple VIPs Virtual Service The following are the steps involved and the recommended settings to configure the HTTPS-APLB Multiple VIPs Virtual Service: 1. In the main menu of the LoadMaster Web User Interface (WUI), go to Virtual Services > Add New. Figure 6-13: Virtual Service parameters 2. 3. 4. 5. 6. Type a valid Virtual Address. Type 443 as the Port. Enter a recognizable Service Name, such as HTTPS – APLB. Click Add this Virtual Service. Configure the settings as recommended in the following table: Section Option Advanced Properties Add a Port 80 Redirector VS Basic Properties Standard Options Service Type Persistence Mode Timeout Scheduling Method Real Server Check Method URL Real Servers Value Comment Click the Add HTTP Redirector button. This automatically creates a redirect on port 80. Generic SSL Session ID 6 minutes least connection HTTPS Protocol /favicon.ico Table 6-18: HTTPS – APLB Multiple VIPs Recommended Settings 7. Add the Real Servers: a) Expand the Real Servers section. Copyright © 2002 - 2016 KEMP Technologies, Inc. All Rights Reserved. 27 VMware Horizon Access Point Session Affinity Options b) c) d) e) f) Click Add New. Type the address of the relevant Real Server. Complete the other fields as required. Click Add this Real Server then click OK to the pop-up message. Repeat the steps above to add more Real Servers as needed, based on your environment. Create a HTTPS - APLB Multiple Ports HTTPS HTTP Redirect Virtual Service Clicking the Add HTTP Redirector button automatically creates a port 80 redirect Virtual Service. This is optional, but the purpose of this Virtual Service is to redirect any clients who have connected using HTTP to the HTTPS Virtual Service. 6.3.1.2 Create an AP01 – BLAST-UDP Multiple VIPs Virtual Service The following are the steps involved and the recommended settings to configure the AP01 – BLASTUDP Multiple VIPs Virtual Service: 1. In the main menu of the LoadMaster Web User Interface (WUI), go to Virtual Services > Add New. Figure 6-14: Virtual Service parameters 2. 3. 4. 5. 6. 7. Type a valid Virtual Address. Type 443 as the Port. Enter a recognizable Service Name, such as AP01 – BLAST-UDP. Select udp as the Protocol. Click Add this Virtual Service. Configure the settings as recommended in the following table: Section Option Value Standard Options Real Servers Force L4 Real Server Check Method Disabled ICMP Ping Table 6-19: AP01 – BLAST-UDP Multiple VIPs Recommended Settings 8. Add the Real Servers: a) Expand the Real Servers section. Copyright © 2002 - 2016 KEMP Technologies, Inc. All Rights Reserved. 28 VMware Horizon Access Point Session Affinity Options b) c) d) e) f) 6.3.1.3 Click Add New. Type the address of the relevant Real Server. Complete the other fields as required. Click Add this Real Server then click OK to the pop-up message. Repeat the steps above to add more Real Servers as needed, based on your environment. Create an AP01 – HTTPS Multiple VIPs Virtual Service The following are the steps involved and the recommended settings to configure the AP01 – HTTPS Multiple VIPs Virtual Service: 1. In the main menu of the LoadMaster Web User Interface (WUI), go to Virtual Services > Add New. Figure 6-15: Virtual Service parameters 2. 3. 4. 5. 6. Type a valid Virtual Address. Type 443 as the Port. Enter a recognizable Service Name, such as AP01 – HTTPS. Click Add this Virtual Service. Configure the settings as recommended in the following table: Section Option Value Standard Options Force L4 Scheduling Method Real Server Check Method Checked Port URL Disabled round robin HTTPS Protocol Real Servers 443 /favicon.ico Table 6-20: AP01 - HTTPS Multiple VIPs Recommended Settings 7. Add the Real Servers: a) Expand the Real Servers section. b) Click Add New. c) Type the address of the relevant Real Server. Copyright © 2002 - 2016 KEMP Technologies, Inc. All Rights Reserved. 29 VMware Horizon Access Point Session Affinity Options d) Complete the other fields as required. e) Click Add this Real Server then click OK to the pop-up message. f) Repeat the steps above to add more Real Servers as needed, based on your environment. 6.3.1.4 Create an AP01 - PCOIP Multiple VIPs Virtual Service The following are the steps involved and the recommended settings to configure the AP01 - PCOIP Multiple VIPs Virtual Service: 1. In the main menu of the LoadMaster Web User Interface (WUI), go to Virtual Services > Add New. Figure 6-16: Virtual Service parameters 2. 3. 4. 5. 6. Type a valid Virtual Address. Type 4172 as the Port. Enter a recognizable Service Name, such as AP01 - PCOIP. Click Add this Virtual Service. Configure the settings as recommended in the following table: Section Option Value Real Servers Real Server Check Method Checked Port TCP Connection only 4172 Comments Click Set Check Port. Table 6-21: AP01 - PCOIP Multiple VIPs Recommended Settings 7. Add the Real Servers: a) Expand the Real Servers section. b) Click Add New. c) Type the address of the relevant Real Server. d) Type 4172 as the Port. e) Complete the other fields as required. f) Click Add this Real Server then click OK to the pop-up message. g) Repeat the steps above to add more Real Servers as needed, based on your environment. Copyright © 2002 - 2016 KEMP Technologies, Inc. All Rights Reserved. 30 VMware Horizon Access Point Session Affinity Options 6.3.1.5 Create an AP01 – PCOIP-UDP Multiple VIPs Virtual Service The following are the steps involved and the recommended settings to configure the AP01 – PCOIPUDP Multiple VIPs Virtual Service: 1. In the main menu of the LoadMaster Web User Interface (WUI), go to Virtual Services > Add New. Figure 6-17: Virtual Service parameters 2. 3. 4. 5. 6. 7. Type a valid Virtual Address. Type 4172 as the Port. Enter a recognizable Service Name, such as AP01 – PCOIP-UDP. Select udp as the Protocol. Click Add this Virtual Service. Configure the settings as recommended in the following table: Section Option Value Standard Options Real Servers Force L4 Real Server Check Method Disabled ICMP Ping Table 6-22: AP01 – PCOIP-UDP Multiple VIPs Recommended Settings 8. Add the Real Servers: a) Expand the Real Servers section. b) Click Add New. c) Type the address of the relevant Real Server. d) Complete the other fields as required. e) Click Add this Real Server then click OK to the pop-up message. f) Repeat the steps above to add more Real Servers as needed, based on your environment. 6.3.1.6 Create an AP02 – BLAST-UDP Multiple VIPs Virtual Service The following are the steps involved and the recommended settings to configure the AP02 – BLASTUDP Multiple VIPs Virtual Service: Copyright © 2002 - 2016 KEMP Technologies, Inc. All Rights Reserved. 31 VMware Horizon Access Point Session Affinity Options 1. In the main menu of the LoadMaster Web User Interface (WUI), go to Virtual Services > Add New. Figure 6-18: Virtual Service parameters 2. 3. 4. 5. 6. 7. Type a valid Virtual Address. Type 443 as the Port. Enter a recognizable Service Name, such as AP02 – BLAST-UDP – Multiple IPs. Select udp as the Protocol. Click Add this Virtual Service. Configure the settings as recommended in the following table: Section Option Value Standard Options Real Servers Force L4 Real Server Check Method Disabled ICMP Ping Table 6-23: AP02 – BLAST-UDP Multiple VIPs Recommended Settings 8. Add the Real Servers: a) Expand the Real Servers section. b) Click Add New. c) Type the address of the relevant Real Server. d) Complete the other fields as required. e) Click Add this Real Server then click OK to the pop-up message. f) Repeat the steps above to add more Real Servers as needed, based on your environment. 6.3.1.7 Create an AP02 – HTTPS Multiple VIPs Virtual Service The following are the steps involved and the recommended settings to configure the AP02 – HTTPS Multiple VIPs Virtual Service: 1. In the main menu of the LoadMaster Web User Interface (WUI), go to Virtual Services > Add New. Copyright © 2002 - 2016 KEMP Technologies, Inc. All Rights Reserved. 32 VMware Horizon Access Point Session Affinity Options Figure 6-19: Virtual Service parameters 2. 3. 4. 5. 6. Type a valid Virtual Address. Type 443 as the Port. Enter a recognizable Service Name, such as AP02 – HTTPS – Multiple IPs. Click Add this Virtual Service. Configure the settings as recommended in the following table: Section Option Value Standard Options Real Servers Force L4 Real Server Check Method Checked Port URL Disabled HTTPS Protocol 443 /favicon.ico Table 6-24: AP02 - HTTPS Multiple VIPs Recommended Settings 7. Add the Real Servers: a) Expand the Real Servers section. b) Click Add New. c) Type the address of the relevant Real Server. d) Complete the other fields as required. e) Click Add this Real Server then click OK to the pop-up message. f) Repeat the steps above to add more Real Servers as needed, based on your environment. 6.3.1.8 Create an AP02 – PCOIP Multiple VIPs Virtual Service The following are the steps involved and the recommended settings to configure the AP02 – PCOIP Multiple VIPs Virtual Service: 1. In the main menu of the LoadMaster Web User Interface (WUI), go to Virtual Services > Add New. Copyright © 2002 - 2016 KEMP Technologies, Inc. All Rights Reserved. 33 VMware Horizon Access Point Session Affinity Options Figure 6-20: Virtual Service parameters 2. 3. 4. 5. 6. Type a valid Virtual Address. Type 4172 as the Port. Enter a recognizable Service Name, such as AP02 – PCOIP. Click Add this Virtual Service. Configure the settings as recommended in the following table: Section Standard Options Real Real Server Check Servers Method Option Value Force L4 Disabled TCP Connection Only Checked Port 4172 Table 6-25: AP02 - PCOIP Multiple VIPs Recommended Settings 7. Add the Real Servers: a) Expand the Real Servers section. b) Click Add New. c) Type the address of the relevant Real Server. d) Complete the other fields as required. e) Click Add this Real Server then click OK to the pop-up message. f) Repeat the steps above to add more Real Servers as needed, based on your environment. 6.3.1.9 Create an AP02 – PCOIP-UDP Multiple VIPs Virtual Service The following are the steps involved and the recommended settings to configure the AP02 – PCOIPUDP Multiple VIPs Virtual Service: 1. In the main menu of the LoadMaster Web User Interface (WUI), go to Virtual Services > Add New. Copyright © 2002 - 2016 KEMP Technologies, Inc. All Rights Reserved. 34 VMware Horizon Access Point Session Affinity Options Figure 6-21: Virtual Service parameters 2. 3. 4. 5. 6. Type a valid Virtual Address. Type 4172 as the Port. Enter a recognizable Service Name, such as AP02 – PCOIP-UDP. Click Add this Virtual Service. Configure the settings as recommended in the following table: Section Option Value Standard Options Real Servers Force L4 Real Server Check Method Disabled ICMP Ping Table 6-26: AP02 – PCOIP-UDP Multiple VIPs Recommended Settings 7. Add the Real Servers: a) Expand the Real Servers section. b) Click Add New. c) Type the address of the relevant Real Server. d) Complete the other fields as required. e) Click Add this Real Server then click OK to the pop-up message. f) Repeat the steps above to add more Real Servers as needed, based on your environment. Copyright © 2002 - 2016 KEMP Technologies, Inc. All Rights Reserved. 35 VMware Horizon Access Point References References Unless otherwise specified, the following documents can be found at http://kemptechnologies.com/documentation. Virtual Services and Templates, Feature Description Copyright © 2002 - 2016 KEMP Technologies, Inc. All Rights Reserved. 36 VMware Horizon Access Point Document History Document History Date Oct 2016 Change Reason for Change Version Resp. First Release First release of document 1.0 POC Copyright © 2002 - 2016 KEMP Technologies, Inc. All Rights Reserved. 37 ">
Download
Advertisement
Key features
Layer 4 and Layer 7 server load balancing
SSL Acceleration
Session Affinity Options
Health monitoring
SSL offload/SSL bridging
Frequently asked questions
Access Point is designed to protect desktop and application resources to enable remote access from the Internet. It is the default gateway for the following products: VMware Horizon View, VMware Horizon Air (DaaS), VMware Horizon Air Hybrid-Mode, VMware Identity Manager, Airwatch Tunnel Gateway/Proxy.
The three methods discussed in this document ensure that all protocol traffic from a Horizon client session goes to the same Access Point appliance. These methods are: Source IP Affinity, Multiple Port Number Groups and Multiple VIPs.
Advantages of Source IP Affinity: Uses standard port numbers and does not require multiple public virtual IP addresses.
Advantages of Multiple Port Number Groups: Does not rely on source IP affinity and does not require multiple public virtual IP addresses.