Vmware Horizon 7 7.10 Horizon 7 Installation
Total Page:16
File Type:pdf, Size:1020Kb
Horizon 7 Installation SEP 2019 VMware Horizon 7 7.10 Horizon 7 Installation You can find the most up-to-date technical documentation on the VMware website at: https://docs.vmware.com/ If you have comments about this documentation, submit your feedback to [email protected] VMware, Inc. 3401 Hillview Ave. Palo Alto, CA 94304 www.vmware.com © Copyright 2011-2019 VMware, Inc. All rights reserved. Copyright and trademark information. VMware, Inc. 2 Contents Horizon 7 Installation 8 1 System Requirements for Server Components 9 Horizon Connection Server Requirements 9 Hardware Requirements for Horizon Connection Server 10 Supported Operating Systems for Horizon Connection Server 10 Virtualization Software Requirements for Horizon Connection Server 11 Network Requirements for Replicated Horizon Connection Server Instances 11 Horizon Administrator Requirements 11 View Composer Requirements 12 Supported Operating Systems for View Composer 12 Hardware Requirements for Standalone View Composer 13 Database Requirements for View Composer and the Events Database 13 2 System Requirements for Guest Operating Systems 15 Supported Operating Systems for Horizon Agent 15 Supported Operating Systems for Standalone Horizon Persona Management 16 Remote Display Protocol and Software Support 16 PCoIP 17 Microsoft RDP 19 VMware Blast Extreme 19 3 Installing Horizon 7 in an IPv6 Environment 24 Setting Up Horizon 7 in an IPv6 Environment 24 Supported vSphere, Database, and Active Directory Versions in an IPv6 Environment 25 Supported Operating Systems for Horizon 7 Servers in an IPv6 Environment 26 Supported Windows Operating Systems for Desktops and RDS Hosts in an IPv6 Environment 26 Supported Clients in an IPv6 Environment 26 Supported Remoting Protocols in an IPv6 Environment 27 Supported Authentication Types in an IPv6 Environment 27 Other Supported Features in an IPv6 Environment 28 4 Installing Horizon 7 in FIPS Mode 30 Overview of Setting Up Horizon 7 in FIPS Mode 30 System Requirements for FIPS Mode 31 5 Preparing Active Directory 32 Configuring Domains and Trust Relationships 32 VMware, Inc. 3 Horizon 7 Installation Trust Relationships and Domain Filtering 33 Creating an OU for Remote Desktops 34 Creating OUs and Groups for Kiosk Mode Client Accounts 34 Creating Groups for Users 34 Creating a User Account for vCenter Server 35 Creating a User Account for a Standalone View Composer Server 35 Create a User Account for View Composer AD Operations 35 Create a User Account for Instant-Clone Operations 36 Configure the Restricted Groups Policy 37 Using Horizon 7 Group Policy Administrative Template Files 38 Prepare Active Directory for Smart Card Authentication 39 Add UPNs for Smart Card Users 39 Add the Root Certificate to Trusted Root Certification Authorities 40 Add an Intermediate Certificate to Intermediate Certification Authorities 41 Add the Root Certificate to the Enterprise NTAuth Store 41 Disable Weak Ciphers in SSL/TLS 42 6 Installing View Composer 43 Prepare a View Composer Database 43 Create a SQL Server Database for View Composer 44 Create an Oracle Database for View Composer 48 Configuring an SSL Certificate for View Composer 52 Install the View Composer Service 52 Enable TLSv1.0 on vCenter and ESXi Connections from View Composer 54 Configuring Your Infrastructure for View Composer 55 Configuring the vSphere Environment for View Composer 55 Additional Best Practices for View Composer 56 7 Installing Horizon Connection Server 57 Installing the Horizon Connection Server Software 57 Installation Prerequisites for Horizon Connection Server 58 Install Horizon Connection Server with a New Configuration 59 Install Horizon Connection Server Silently 62 Silent Installation Properties for a Horizon Connection Server Standard Installation 65 Enable TLSv1.0 on vCenter Connections from Connection Server 66 Install a Replicated Instance of Horizon Connection Server 67 Install a Replicated Instance of Horizon Connection Server Silently 70 Silent Installation Properties for a Replicated Instance of Horizon Connection Server 72 Configure a Security Server Pairing Password 74 Install a Security Server 74 Install a Security Server Silently 78 VMware, Inc. 4 Horizon 7 Installation Silent Installation Properties for a Security Server 80 Remove IPsec Rules for the Security Server 82 Unified Access Gateway Appliance Advantages over VPN 83 Firewall Rules for Horizon Connection Server 85 Configuring a Back-End Firewall to Support IPsec 86 Reinstall Horizon Connection Server with a Backup Configuration 87 Microsoft Windows Installer Command-Line Options 88 Uninstalling Horizon 7 Components Silently by Using MSI Command-Line Options 90 8 Configuring TLS Certificates for Horizon 7 Servers 93 Understanding TLS Certificates for Horizon 7 Servers 93 Overview of Tasks for Setting Up TLS Certificates 95 Obtaining a Signed TLS Certificate from a CA 96 Obtain a Signed Certificate from a Windows Domain or Enterprise CA 97 Configure Horizon Connection Server, Security Server, or View Composer to Use a New TLS Certificate 98 Add the Certificate Snap-In to MMC 99 Import a Signed Server Certificate into a Windows Certificate Store 100 Modify the Certificate Friendly Name 101 Import a Root Certificate and Intermediate Certificates into a Windows Certificate Store 102 Bind a New TLS Certificate to the Port Used by View Composer 103 Configure Client Endpoints to Trust Root and Intermediate Certificates 104 Configure Horizon Client for Mac to Trust Root and Intermediate Certificates 106 Configure Horizon Client for iOS to Trust Root and Intermediate Certificates 106 Configuring Certificate Revocation Checking on Server Certificates 107 Configure the PCoIP Secure Gateway to Use a New TLS Certificate 108 Verify That the Server Name Matches the PSG Certificate Subject Name 109 Configure a PSG Certificate in the Windows Certificate Store 110 Set the PSG Certificate Friendly Name in the Windows Registry 111 Force a CA-Signed Certificate to Be Used for Connections to the PSG 112 Setting Horizon Administrator to Trust a vCenter Server or View Composer Certificate 113 Benefits of Using TLS Certificates Signed by a CA 113 Troubleshooting Certificate Issues on Horizon Connection Server and Security Server 114 9 Enabling Horizon 7 for Subscription Licenses 116 VMware Horizon 7 Cloud Connector 116 Deploy the Horizon 7 Cloud Connector Virtual Appliance with Horizon 7 117 Static IP and Proxy Configuration for the Horizon 7 Cloud Connector Virtual Appliance 120 Update the Static IP for the Horizon 7 Cloud Connector Virtual Appliance 120 Set a Password Expiry Policy for the Horizon 7 Cloud Connector Root User 121 Configure a CA-Signed Certificate for the Horizon 7 Cloud Connector Virtual Appliance 121 VMware, Inc. 5 Horizon 7 Installation 10 Configuring Horizon 7 for the First Time 125 Configuring User Accounts for vCenter Server, View Composer, and Instant Clones 125 Where to Use the vCenter Server User and View Composer Users 126 Configure a vCenter Server User for Horizon 7 and View Composer 126 Privileges Required for the vCenter Server User 128 View Composer and Instant Clone Privileges Required for the vCenter Server User 129 Configuring Horizon Connection Server for the First Time 130 Horizon Administrator and Horizon Connection Server 130 Log In to Horizon Administrator 131 Install the Product License Key 132 Add vCenter Server Instances to Horizon 7 133 Configure View Composer Settings 135 Configure View Composer Domains 136 Add an Instant-Clone Domain Administrator 137 Allow vSphere to Reclaim Disk Space in Linked-Clone Virtual Machines 137 Configure View Storage Accelerator for vCenter Server 139 Concurrent Operations Limits for vCenter Server and View Composer 141 Setting a Concurrent Power Operations Rate to Support Remote Desktop Logon Storms 142 Accept the Thumbprint of a Default TLS Certificate 142 Configuring Horizon Client Connections 144 Configure the PCoIP Secure Gateway and Secure Tunnel Connections 145 Configure the Blast Secure Gateway 146 Configuring External URLs for Secure Gateway and Tunnel Connections 147 Set the External URLs for a Connection Server Instance 149 Modify the External URLs for a Security Server 150 Give Preference to DNS Names When Horizon Connection Server Returns Address Information 151 Allow HTML Access Through a Load Balancer 152 Allow HTML Access Through a Gateway 152 Replacing Default Ports for Horizon 7 Services 153 Replace the Default HTTP Ports or NICs for Horizon Connection Server Instances and Security Servers 153 Replace the Default Ports or NICs for the PCoIP Secure Gateway on Horizon Connection Server Instances and on Security Servers 154 Replace the Default Control Port for PCoIP Secure Gateway on Connection Server Instances and on Security Servers 156 Replace the Default Port for View Composer 156 Change the Port Number for HTTP Redirection to Connection Server 157 Prevent HTTP Redirection for Client Connections to Connection Server 158 Enable Remote Access to Horizon 7 Performance Counters on Connection Servers 158 Sizing Windows Server Settings to Support Your Deployment 159 Sizing Memory for Horizon Connection Server 159 VMware, Inc. 6 Horizon 7 Installation Configure the System Page-File Settings 160 11 Configuring Event Reporting 161 Add a Database and Database User for Horizon 7 Events 161 Prepare an SQL Server Database for Event Reporting 162 Configure the Event Database 163 Configure Event Logging for Syslog Servers 164 VMware, Inc. 7 Horizon 7 Installation ® Horizon 7 Installation explains how to install the VMware