<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Horizon Infrastructure Internal Security in Horizon Desktops and Apps</title>
    <link>https://communities.vmware.com/t5/Horizon-Desktops-and-Apps/Horizon-Infrastructure-Internal-Security/m-p/2917431#M97325</link>
    <description>&lt;P&gt;Here is a good source for what talks to what and on what port.&amp;nbsp; &amp;nbsp;&lt;BR /&gt;&lt;A href="https://techzone.vmware.com/resource/network-ports-vmware-horizon" target="_blank"&gt;https://techzone.vmware.com/resource/network-ports-vmware-horizon&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Here is the architecture guide also.&amp;nbsp;&amp;nbsp;&lt;BR /&gt;&lt;A href="https://techzone.vmware.com/resource/horizon-architecture" target="_blank"&gt;https://techzone.vmware.com/resource/horizon-architecture&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Windows Firewall rules on Connection servers would be a good idea based on the network ports document above.&amp;nbsp; &amp;nbsp;If you have DMZ UAG appliances, the network ports document explains what network related FW rules for those also.&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 05 Jul 2022 14:25:52 GMT</pubDate>
    <dc:creator>StephenMassman</dc:creator>
    <dc:date>2022-07-05T14:25:52Z</dc:date>
    <item>
      <title>Horizon Infrastructure Internal Security</title>
      <link>https://communities.vmware.com/t5/Horizon-Desktops-and-Apps/Horizon-Infrastructure-Internal-Security/m-p/2917380#M97322</link>
      <description>&lt;P&gt;Hello everyone&lt;/P&gt;&lt;P&gt;Recently, I deployed a horizon environment and it has to be secured both externally and internally. My problem is that when we install an agent on each VM there is a little interaction between each VM and connection server. Meanwhile if that VM has been infected by any malicious software this infection can be speared into connection server or any other important infrastructure. In addition I don't want users to be able to access connection server admin web page internally while by installing agent to VMs they are able to visit admin page.&lt;/P&gt;&lt;P&gt;Another problem is that the recording server which VMs should be able to connect to it through port 9443 is publicly available to VMs and users can access to its web admin interface.&lt;/P&gt;&lt;P&gt;How can I isolate horizon infrastructure from internal users or at least how can I make sure that the only interaction between VMs are from horizon and not from any unwanted app.&lt;BR /&gt;&lt;BR /&gt;this is a serious issue for me and I will be so much appreciated if anyone could help me with that.&lt;/P&gt;</description>
      <pubDate>Tue, 05 Jul 2022 11:16:51 GMT</pubDate>
      <guid>https://communities.vmware.com/t5/Horizon-Desktops-and-Apps/Horizon-Infrastructure-Internal-Security/m-p/2917380#M97322</guid>
      <dc:creator>mk_mk_47</dc:creator>
      <dc:date>2022-07-05T11:16:51Z</dc:date>
    </item>
    <item>
      <title>Re: Horizon Infrastructure Internal Security</title>
      <link>https://communities.vmware.com/t5/Horizon-Desktops-and-Apps/Horizon-Infrastructure-Internal-Security/m-p/2917431#M97325</link>
      <description>&lt;P&gt;Here is a good source for what talks to what and on what port.&amp;nbsp; &amp;nbsp;&lt;BR /&gt;&lt;A href="https://techzone.vmware.com/resource/network-ports-vmware-horizon" target="_blank"&gt;https://techzone.vmware.com/resource/network-ports-vmware-horizon&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Here is the architecture guide also.&amp;nbsp;&amp;nbsp;&lt;BR /&gt;&lt;A href="https://techzone.vmware.com/resource/horizon-architecture" target="_blank"&gt;https://techzone.vmware.com/resource/horizon-architecture&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Windows Firewall rules on Connection servers would be a good idea based on the network ports document above.&amp;nbsp; &amp;nbsp;If you have DMZ UAG appliances, the network ports document explains what network related FW rules for those also.&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 05 Jul 2022 14:25:52 GMT</pubDate>
      <guid>https://communities.vmware.com/t5/Horizon-Desktops-and-Apps/Horizon-Infrastructure-Internal-Security/m-p/2917431#M97325</guid>
      <dc:creator>StephenMassman</dc:creator>
      <dc:date>2022-07-05T14:25:52Z</dc:date>
    </item>
  </channel>
</rss>

