Architecture Planning

Table Of Contents
n
Tunneled Client Connections with Microsoft RDP on page 70
When users connect to a remote desktop with the Microsoft RDP display protocol, Horizon Client can
make a second HTTPS connection to the View Connection Server host. This connection is called the
tunnel connection because it provides a tunnel for carrying RDP data.
n
Direct Client Connections on page 71
Administrators can configure View Connection Server settings so that remote desktop and application
sessions are established directly between the client system and the remote application or desktop
virtual machine, bypassing the View Connection Server host. This type of connection is called a direct
client connection.
Client Connections Using the PCoIP Secure Gateway
When clients connect to a remote desktop or application with the PCoIP display protocol from VMware,
Horizon Client can make a second connection to the PCoIP Secure Gateway component on a View
Connection Server instance or a security server. This connection provides the required level of security and
connectivity when accessing remote desktops and applications from the Internet.
Security servers include a PCoIP Secure Gateway component, which offers the following advantages:
n
The only remote desktop and application traffic that can enter the corporate data center is traffic on
behalf of a strongly authenticated user.
n
Users can access only the resources that they are authorized to access.
n
This connection supports PCoIP, which is an advanced remote display protocol that makes more
efficient use of the network by encapsulating video display packets in UDP instead of TCP.
n
PCoIP is secured by AES-128 encryption by default. You can, however, change the encryption cipher to
AES-256.
n
No VPN is required, as long as PCoIP is not blocked by any networking component. For example,
someone trying to access their remote desktop or application from inside a hotel room might find that
the proxy the hotel uses is not configured to pass PCoIP.
For more information, see “Firewall Rules for DMZ-Based Security Servers,” on page 79.
Security servers with PCoIP support run on Windows Server 2008 R2 and Windows Server 2012 R2
operating systems and take full advantage of the 64-bit architecture. This security server can also take
advantage of Intel processors that support AES New Instructions (AESNI) for highly optimized PCoIP
encryption and decryption performance.
Tunneled Client Connections with Microsoft RDP
When users connect to a remote desktop with the Microsoft RDP display protocol, Horizon Client can make
a second HTTPS connection to the View Connection Server host. This connection is called the tunnel
connection because it provides a tunnel for carrying RDP data.
The tunnel connection offers the following advantages:
n
RDP data is tunneled through HTTPS and is encrypted using SSL. This powerful security protocol is
consistent with the security provided by other secure Web sites, such as those that are used for online
banking and credit card payments.
n
A client can access multiple desktops over a single HTTPS connection, which reduces the overall
protocol overhead.
n
Because View manages the HTTPS connection, the reliability of the underlying protocols is significantly
improved. If a user temporarily loses a network connection, the HTTP connection is reestablished after
the network connection is restored and the RDP connection automatically resumes without requiring
the user to reconnect and log in again.
View Architecture Planning
70 VMware, Inc.