VMware Workspace ONE Community
ductom2002
Contributor
Contributor

Launch Blast Desktop from Horizon Workspace: Redirect issues from external

Hi folks,

i have successfully set up the whole thing in my lab:

  • View Connection Server with Win7 Desktop Pool in a vSphere 5 environment
  • Blast/HTML Access setup and working fine
  • Split DNS working as expected from internal and external
  • External Gateway is NGINX Proxy

I can log in from external (public ip with certificate) without a problem and launch applications.

If i try to open my desktop pool connection it redirects to the private fqdn which of course cannot be accessed from outside.

How can i launch that blast session from within workspace not redirecting to the inetrnal address/fqdn

Best regards

Thomas

0 Kudos
8 Replies
Linjo
Leadership
Leadership

Hi Thomas and welcome to the VMware Communities!

Can you connect directly to the View Connection broker and access the desktop that way?

You probably need to enable "tunneling" on the connection-broker and set the external URL to whatever the connection-broker should resolve to on the outside.

// Linjo

Best regards, Linjo Please follow me on twitter: @viewgeek If you find this information useful, please award points for "correct" or "helpful".
0 Kudos
ductom2002
Contributor
Contributor

Hi Linjo,

meanwhile we tried a lot scenarios but none is working. We shutdown horizon workspace and reconfigured our dns so that we could simulate a minimum environment which is the following secenario:

ViewSecureServer (https://view.mycompany.com if1=external (internet) and if2=internal (dmz)) <--> ViewConnectionServer (lan) --> DesktopPool

Portal is working and i can login so far. If i open my desktop pool nothing happens and after a while it shows the internal ip of one of my virtual desktops in the addressbar of the browser and complains about connection issues:

error_1.JPG

What am i doing wrong? In my opinion everything should be inside the tunnel so why is it presenting an internal ip?

Anybody out who successfully implemented that blast gateway?

Best regards

Thomas

0 Kudos
Linjo
Leadership
Leadership

I have it running fine, did you enable tunneling as I asked earlier?

// Linjo

Best regards, Linjo Please follow me on twitter: @viewgeek If you find this information useful, please award points for "correct" or "helpful".
0 Kudos
ductom2002
Contributor
Contributor

Hi Linjo,

tunneling is enabled.

Meanwhile i opened the firewall rule (internet-to-dmz) for debugging to temporary allow any service. Now i can logon to my desktops 😉

Which ports beside https are mandatory from outside to the dmz host to run it a secure way?

BR

Thomas

0 Kudos
Linjo
Leadership
Leadership

Thats great!

Here is a recent blogpost with an excellent chart of all the ports:

http://www.simonlong.co.uk/blog/2013/04/16/vmware-horizon-view-5-2-network-ports-external-design/

// Linjo

Best regards, Linjo Please follow me on twitter: @viewgeek If you find this information useful, please award points for "correct" or "helpful".
0 Kudos
ductom2002
Contributor
Contributor

Hi Linjo,

that's what i was looking for 🙂

Best regards and thanks for your support!

Thomas

0 Kudos
eddyccl
Contributor
Contributor

Hi,

I'm currently facing similar issues in my test lab which it happens when I am connecting from public IP address to security server via Blast. No issues if I'm connect using View Client.

using blast, i can login, select pool and then i was redirected to the NAT private IP of the target view desktop and obviously I could not connect.

Note: The redirection to local private ip does not happens if i configured to connect to view connection server via blast.

I have:

  • self-signed SSL installed, without warnings
  • enabled tunneling on connection server
  • enabled tunneling on security server
  • disabled all firewall for testing purposes
  • locally defined in host file to resolve my security server fqdn to static IP used in my office. (vsecurity.icliq.com in this case)
  • required ports are configured with port forwarding in my office router

security.png

Therefore i hope someone could shed some light on my issue.

Thank you

Eddyc

Message was edited by: eddyccl

0 Kudos
eddyccl
Contributor
Contributor

I guess i'm posting to wrong forum. I should have posted to Horizon View forum.

0 Kudos