VMware Horizon Community
pizzingrilli
Contributor
Contributor

VMware View with Microsoft Forefront TMG

Has anyone successfully configured VMware View Security Server with Microsoft Forefront TMG Server as Frontend Firewall?

I have created a web publishing rule that allows HTTP and HTTPS access to the VMware view manager security server.

The VMware view client can authenticate successful but after then the client seems to hang and will never display the available desktops to the user.

The Problem is definitely related to the ISA/TMG box. It works without ISA/TMG server.

I have installed the latest version of VMware View.

Any ideas?

Regards

Sandro

0 Kudos
3 Replies
regnak
Hot Shot
Hot Shot

Hi,

I haven't tried it with this product. Is there anything in the Forefront logs indicating what it's doing / blocking when the connection is attempting to connect / establish itself? Do you have Direct Connection enabled in the View Manager Configuration which may present problems?

Mike

0 Kudos
rorup
Contributor
Contributor

I have the exact same problem. The funny thing is that it works with the RDP protocol but NOT when I select the PCoIP protocol ??

0 Kudos
DWSzofer
Contributor
Contributor

Hi Sandro,

Although  more then a year later Smiley Happy ... I managed to publish the View Security server using TMG 2010 in a test environment (POC).

My security server is not in the DMZ but on the internal LAN. So I didn't have to setup any rules for communication between the security server and the connection server. It is documented pretty much here:

http://www.thatsmyview.net/tag/security-server/

and here

http://kb.vmware.com/selfservice/microsites/search.do?language=en_US&cmd=displayKC&externalId=101238... 4.6.x

  • Published the HTTPS server (pointing to the security server) just as you did
  • Created user defined protocols for TCP inbound port 4172, TCP outbound port 4172, UDP inbound (receive/send) port 4172, UDP outbound (send/receive) port 4172
  • Published PCoIP TCP as well as UDP protocol pointing to the security server (both using port 4172)

It looks like the UDP publishing rule is never used if I check the logging during initial session setup.

Your problem not seeing the available desktops has to do with communication restrictions between security server and connection server.

Of course don't forget to enter your external IP to the security server config:

security server.PNG

and here (connection server config):

connection server.PNG

Hope this helps anyone trying to publish the View security server using ISA or TMG 2010.

0 Kudos