VMware Horizon Community
hurdle
Enthusiast
Enthusiast

PCOIP Secure Gateway

I have a basic setup Security Server in the DMZ and the CS in our back end network

I notice that in order to set the IP URL on our security server, you have to have the Gateway option checked on the Connection Server

Ideally I wanted it so my external users had to use the Gateway and my internal users could use direct connect, is this not an option since I have to have the Gateway checked in order to have it accessible for external users?

Reply
0 Kudos
3 Replies
roneng
Enthusiast
Enthusiast

nope, you will have to use 2 connections servers

1 for internal users

the second will be configured for tunnel and paired with a security server

Reply
0 Kudos
Gaurav_Baghla
VMware Employee
VMware Employee

You can pair 1 connection server and security server I dont think you would need 2 of them.

Check the Dns and Cname Entries and have a look at this

http://kb.vmware.com/selfservice/microsites/search.do?language=en_US&cmd=displayKC&externalId=103620...

Regards Gaurav Baghla Opinions are my own and not the views of my employer. https://twitter.com/garry_14
Reply
0 Kudos
markbenson
VMware Employee
VMware Employee

The problem with only having 1 CS is that internal users would then have their PCoIP sessions gateway'd and this is not as efficient as direct. Just install a replica Connection Server for internal users as has been previously suggested. This gives further benefits such as being able to add 2-factor authentication for external users and using tagging for different external/internal entitlements.

Mark

Reply
0 Kudos