alienjoker's Posts

Hi all, After an upgrade from View 5.3.4 to Horizon 7.0.1 we now find that with 3D Rendering turned on (Software) at the Pool level, during a user logon on a P25 Wyse zero client that the scre... See more...
Hi all, After an upgrade from View 5.3.4 to Horizon 7.0.1 we now find that with 3D Rendering turned on (Software) at the Pool level, during a user logon on a P25 Wyse zero client that the screen goes black and back to the "Welcome" prompt roughly 3-4 times before the desktop is eventually displayed. This doesn't however exist if we disable 3D rendering, but the problem we then find is that Aero is no longer functional within Windows 7 because according to Windows, the "Video Card Driver doesn't support Aero effects!". On the odd occasion, during the black to back screen refreshing on the Wyse P25 device, that the resolution drops to something crazy like 1280x1024 instead of the 2x monitors 1920x1200 resolutions. PCoIP logs show a number of failed attempts to get the right information about the attached monitors:- "Failed to reconfigure 2 current display(s) from 1 reported displays" It would suggest that there have been some significant changes to the SVGA driver used within the Horizon Agent package which results in this bizarre behaviour. Typically, I wouldn't care so much about leaving Aero switched off as per VMware OSOT recommendation, however we find that Outlook 2010 has problems dynamically updating inbox content without the DWM service running with Composition switched on. Any others experiencing similar behaviour? Thanks Andrew
Hi, Can you confirm if your pool is using disposable disks? The reason I ask is that I've experienced the exact same problem and after hours of root cause analysis with ProcMon, found that the... See more...
Hi, Can you confirm if your pool is using disposable disks? The reason I ask is that I've experienced the exact same problem and after hours of root cause analysis with ProcMon, found that the logging levels on the RDPBridgeservice for TPAutoconnect were filling up the disposable disk. This then prevents the PCOIP service from being able to run successfully and the only way back onto the desktop was with HTML access. I have existing SRs open with VMware on this as I've warned them that their logging levels are too aggressive in Horizon 7.0.x Cheers Andrew
Hi, Responding to my own question in the hope that anyone else with this problem knows how to overcome this issue:- Thanks to a discussion with Mark Benson (thanks Mark), here's his respons... See more...
Hi, Responding to my own question in the hope that anyone else with this problem knows how to overcome this issue:- Thanks to a discussion with Mark Benson (thanks Mark), here's his response, despite what GSS have told me that it wasn't currently possible:- "The limitation was with Access Point 2.5.x and older where users were required to login again after they had been logged in for 10 hours. With Access Point 2.7.2 you can specify the sessionTimeout if a value other than 10 hours is required. The default is still 10 hours (as it is with Horizon View too), but you can set it to any value now. Just set sessionTimeout in the PowerShell .ini file and it will be applied automatically when the appliance is deployed. Make sure source= refers to point-2.7.2.0-4354291_OVF10.ova." It does frustrate me that GSS don't have the most relevant and recent information, or update their respective KB articles on their product portfolio capabilities, but really pleased that the internal staff are readily available to help assist when you reach out to them. Cheers Andrew
Hi all, I'd like to reach out to the community to determine the success ratio of people deploying VMware Horizon View 7 in association with AppVolumes. A client of mine recently embarked up... See more...
Hi all, I'd like to reach out to the community to determine the success ratio of people deploying VMware Horizon View 7 in association with AppVolumes. A client of mine recently embarked upon the upgrade of their existing VMware View 5.3 environment to Horizon 7 in order to remain within support compliance but unfortunately, the journey has not been the most pleasant and still continues to be plagued with daily problems. I'll try to keep things as succinct as possible but here are the high level steps taken to get to where we are now. a) Deploy vSphere 6 U2 hosts (having come from vSphere 5.5 U2) b) Deploy new 7.0.1 Connection Servers (7.0.2 was not out at the time of start having come from 5.3.4) c) Deploy new 2.5.1 Access Points (2.7.2 was not out at the time of start) d) Deploy new 2.11 AppVolumes Managers (having come from 2.6) e) Upgrade existing Gold image to reflect updated VM hardware version and include updated VMware tools, AppVolumes 2.11 Agent and Horizon 7.0.1 Agent with Instant Clone Support Pilot phase identified the following the following problems:- 1) AppStacks would randomly disconnect mid session (SR logged - no resolution) 2) Logon times would be continually inconsistent and in some cases longer than the previous user experience in the old environment (SR logged - advised limitation of the AppVolumes product and the way it mounts stacks - no resolution) 3) AppVolumes issues whereby a user could not successfully delete a file that had been created on the local disk with a Windows Error - (SR logged, filter driver problem private fix available, but not production ready- pending AppVolumes 2.12) 4) Remote Sessions would disconnect after 10 hours (SR logged - known issue under KB2131762 or KB2145172) 5) Sessions would sometimes disconnect and could not be reconnected to unless HTML access/Blast Exterme was used or the old session terminated (SR raised - no resolution) 6) LAN based sessions would sometimes disconnect after 20 hours despite having set to Never disconnect (KB 2091458) - FIXED 7) Performance problems mid session and logon/logoffs were really slow (VMware tools version needed upgrading to 10.0.9 as per KB2144236) - FIXED Off the back of the above and in terms of priority and show stoppers, given we couldn't proceed with a non supported filter driver fix, we resorted to AppVolumes v2.10 which immediately meant we had to drop the ability to use Instant Clones. Once we had downgraded the AppVolumes agent and changed the Horizon 7 agent to linked clones in the Gold build, here's a summary of where we're at regarding the issues above: 1) No Resolution : This has happened even on 2.10 (we use Mount on host, the SR is still pending) 2) Much better, and more consistent 3) No longer a problem 4) No resolution : Doesn't look likely that there will be a fix until a re-release 5) No resolution. 6) FIXED as per above 7) FIXED as per above As you can see, we're still in a bad place with items 1) and 5) with too greater risks for users to be left with an unworkable system. Item 4) whilst an education issue, is simply not acceptable. Is anyone else out there able to share their pain and or comment/help above beyond what GSS are already investigating? I look forward to hearing peoples experiences. Thanks Andrew
Hi all, I wanted to reach out to the community to gauge just how many people are actually using the Access Point appliances to control remote access to their Horizon/View implementations. We h... See more...
Hi all, I wanted to reach out to the community to gauge just how many people are actually using the Access Point appliances to control remote access to their Horizon/View implementations. We have identified an effective show stopper for transitioning between security servers and the access point based upon the unchangeable/hard coded 10 hour disconnect that is enforced by the access point. ‌ The following KB articles highlight this limitation which is a pretty significant blocker given that I work with a large number of clients that have remote locations that rely on uninterrupted access to their Virtual Desktop environments via the remote access method. To put a workaround as "reconnect to the desktop new session from Horizon Client after time out." is simply not acceptable. If a customer happens to be performing a time sensitive deal negotiation only to be faced with a system enforced disconnect, you can see where I'm going with this. User sessions are timed out when connecting to View desktops from Access point/ VMware Horizon DaaS (2145172) | VMware K… VMware Horizon DaaS/Air user sessions are timed out after 10 hours even when the Broker Session Timeout is set to a high…‌ I look forward to hearing peoples views on this. Cheers Andrew
Hi Mark, Thanks very much for your response. Item #2 was indeed the culprit here and having discussed the submitted FW rules with the security team, they admitted they had failed to apply one ... See more...
Hi Mark, Thanks very much for your response. Item #2 was indeed the culprit here and having discussed the submitted FW rules with the security team, they admitted they had failed to apply one of the UDP ports which continually resulted in the deployment failure. I hope others find these pointers as useful as I have in getting the access point into production using 2FA. Kind regards Andrew
Hi Mark, We've been having problems configuring RSA integration despite following your excellent Video VMware Access Point RSA SecurID Authentication Setup on Vimeo‌ . Put simply, the applianc... See more...
Hi Mark, We've been having problems configuring RSA integration despite following your excellent Video VMware Access Point RSA SecurID Authentication Setup on Vimeo‌ . Put simply, the appliance will not start correctly when we specify the inclusion of the sdconf.rec file (having extracted it directly from the zip file from the Auth Manager). If we configure the INI file with everything else apart from the referenced file, the appliance starts up, but understandably doesn't perform auth. GSS seem to be scratching their heads too, even stating that SecurID needed to be configured on the connection servers and that I should be using the Fling for the Access Point OVA Deployment Utility which doesn't cater for RSA integration. I even tried sending the JSON requests directly to a non RSA deployed appliance, but this fails too. Seems like a bit of a black art to get the appliance working properly. Best regards Andrew
Hi, We originally deployed the access point with single factor and were then asked to append two factor. Rather then redeploy, we considered adding the two factor to an existing deployment. Th... See more...
Hi, We originally deployed the access point with single factor and were then asked to append two factor. Rather then redeploy, we considered adding the two factor to an existing deployment. This appeared to be nothing more than a couple of JSON requests, correctly formed to make the changes. Initially, we successfully issued a PUT to : https://accesspoint.domain.com:9443/rest/v1/config/edgeservice/view with a JSON request of : "authMethods:" "securid-auth && sp-auth" and all the other required parameters, however when we are attempting to issue the commands needed for the securid components via a PUT to https://accesspoint.domain.com:9443/rest/v1/config/authmethod/securid-auth as per documentation (replacing the HostNames and serverConfig with the sdconf.rec Base64 Encode (single line) it always fails:- VMware Access Point 2.7 Documentation Center { "enabled": "true", "name": "securid-auth", "numIterations": "5", "externalHostName": "10.20.30.40", "internalHostName": "10.20.30.40", "nameIdSuffix": "" "serverConfig": ""OwYFI7owv5UrAdlfnOsW2nVesmbkLRjNOYxqm" } "Error - failed to set adapter configuration" A SecurID Connectivity or configuration error has occured" Does anyone know which part I'm doing wrong? Best regards Andrew
Hi i would like to ask a couple of questions regarding our deployment to integrate access points and wondered if anyone could please provide some guidance. ‌ We are currently load balancing ... See more...
Hi i would like to ask a couple of questions regarding our deployment to integrate access points and wondered if anyone could please provide some guidance. ‌ We are currently load balancing (behind Kemp) two Horizon 7 view connection servers using an internal CA cert via horizon.domain.com. The plan has been to use a different fqdn of login.domain.com which will use public certs, deployed to the access points, configured to connect to horizon.domain.com Is there any issue using two different fqdns for internal/external access for shared view connection servers? When it comes to using two factor auth, given that the configuration is enabled on the connection servers, does this mean I need two separate connection servers for the access points to provide the two factor auth as internally for thin clients etc, this is not a requirement. Many thanks Andrew
Hey gmtx, Apex, apex apex ;o) I've had many a discussion on these devices and in their day (i.e. before double digit multi-core processors), they were pretty good. The thing is, now that CPUs ... See more...
Hey gmtx, Apex, apex apex ;o) I've had many a discussion on these devices and in their day (i.e. before double digit multi-core processors), they were pretty good. The thing is, now that CPUs are so powerful, the density problem it aims to improve is easily addressed with a better CPU at a comparable cost. There is a lot of misleading information that suggests Apex will reduce CPU problems, but in reality, multimedia rich content isn't one of them and invariably this is the problem that causes the biggest headache. We've thrown more compute at individual use cases, but the processes will just consume whatever you give them so you end up no better off. Like you, I have many clients who use Bloomberg, FT etc complaining of performance problems and we see IE and Chrome hitting the highest level of compute demands on a day to day basis. Offloading these demands to the local device seems to be the most cost effective solution, so Content redirection would be of great benefit if it integrates with an active session in a seamless way. The nVidia cards whilst a possible option, a) don't work in the blade compute (BL460s) I find in many VDI shops b) have extortionate support/licensing costs c) reduce the density of users per server due to the reduced number of users per Tesla card (16 in an MXM module) vs users per server at 75. Given the lack of responses to this thread, it seems that it hasn't picked up much traction in the field for genuine use cases. Thanks Andrew
Hi, I thought I'd reach out to the community to get a view on the feasibility of using a feature such as URL Content Redirection in Horizon 7. Whilst on paper, it sounds like a benefit to offl... See more...
Hi, I thought I'd reach out to the community to get a view on the feasibility of using a feature such as URL Content Redirection in Horizon 7. Whilst on paper, it sounds like a benefit to offload URL clicks/entries to sites such as YouTube so as to place the overhead on a ThinClient for example, there are many user experience caveats/complexities. For example, if you are using a full screen VDI session, upon attempts to access YouTube, the local browser does successfully appear in front of your active session to continue use of the redirected site, but if you minimize the window, you are helpless to bring it back as the ALT-TAB you issue is sent to the VDI session, not the underlying device and therefore your users have no method of regaining control of the local browser the VDI session called. Making a comparison to Citrix, their local application access technique successfully integrates the locally run application into the taskbar of the VDI session, allowing you to transparently use the application as if it was genuinely hosted within the Virtual Desktop. Perhaps I'm missing something, but unless you operate a Windowed virtual desktop (and therefore present two taskbars/start menus, which brings a whole new level of complexity for the end user), I'm struggling to understand how the feature at this stage of development would even stand the test of time in a production environment. I look forward to hearing other peoples views or successes/failures with this "feature". Thanks Andrew
Hi, I was wondering if there was a way to create multiple pools, all referencing the same Parent VM, but automatically adjusting the compute resource of the VMs within the target Pool as part ... See more...
Hi, I was wondering if there was a way to create multiple pools, all referencing the same Parent VM, but automatically adjusting the compute resource of the VMs within the target Pool as part of the compose/recompose process (on the assumption that any compute change wouldn't be drastic enough to invoke a HAL change or prompt to restart the OS)? For example, to keep master images down to one to reduce administrative overhead for patching etc, is there any way to specify the following three pools to all use Parent VM X but with slight variations to CPU/RAM: Pool (Small) - 2GB RAM, 1vCPU Pool (Medium) - 4GB RAM, 2vCPU Pool (Large) - 8GB RAM, 4vCPU I realise you could quite easily patch Parent VM X and clone it to Y and Z and adjust the specification of X, Y and Z as the new Parent VMs to meet the compute requirements of the pools, but this seems just another unnecessary administrative overhead as would need to be done at each patch cycle. I was considering leveraging the post-synchronization script as a task that shuts down the VM, sends the VM name as a variable to a PowerCLI command, adjusts the compute as dictated by the script called by the pool and subsequently powers it back on? Has anyone done anything similar, or is there a feature in the product I've simply overlooked. (VMware Horizon View 5.3.4) Thanks