Reply to Message

View discussion in a popup

Replying to:
heloma
Contributor
Contributor

hi,

Five things to consider when you deploy loadbalancing in front of UAG.

1- make usre the secure tunnel option is checked in the UAG settings.

2- In Layer 7 mode (full ssl proxy), the certificate deployed on UAG MUST be the same as the one deployed on the haproxy.

3- In the UAG, you have to indicate the public IP address used by the clients.

4- You have to consider 3 ports (4 if you want to deploy blast). tcp/443, tcp/4172 and udp/4172. this latter is for pcoip.

5-  Use the session persistency based on source IP, so the client connection is stuck to the same backend UAG.

keep in mind that all communications between external clients and connection servers or virtual desktops are ALL going through UAG. therefore, you have to make sure that your pfsense haproxy has the required performance to handle all the traffic.

the F5 deployment may provide more insight.... https://www.f5.com/pdf/deployment-guides/vmware-horizon-view-dg.pdf

cheers.

heloma.

Reply
0 Kudos