Horizon Cloud Service Next Gen Apis – Chapter 2

Immagine che contiene testo, Neon, Segnali luminosi, Insegna al neon Il contenuto generato dall'IA potrebbe non essere corretto.

Set Syslog settings across UAG deployments

In this second article on working with APIs in Horizon Cloud Services, we will focus on a practical, security-relevant use case: configuring Syslog on Unified Access Gateways (UAGs) deployed through Horizon Cloud.

Whether you are running Horizon Cloud Service on Microsoft Azure or Horizon Cloud Service on vSphere, centralized logging is a fundamental component of any secure and well-governed environment. Proper Syslog configuration ensures that security events, authentication logs, and operational data generated by UAG appliances are forwarded to your SIEM or log management platform for monitoring, auditing, and incident response.

Instead of performing manual configuration tasks, we will explore how to leverage Horizon Cloud APIs to automate and standardise Syslog settings across UAG deployments, improving consistency, scalability, and operational efficiency.

Now when can explain the API we need to use and how to apply the syslog configuration on UAG (In this case, I used an HCS on vSphere, the new solution where we don’t deploy the Connection Server, but we use the HCS control panel to configure Pools, Entitlements and other…)

The first step is always the authentication process; I explained how to create the API token in my previous post (Horizon Cloud Service Next Gen Apis – Chapter 1), and now I won’t explain it again.

Let’s go…..

How to show UAG information

This command displays the UAG’s information

Invoke-RestMethod -Uri https://cloud-sg.horizon.omnissa.com/admin/v2/uag-deployments Method Get -Headers $Header

 We have two UAG deployments connected to HCS, and the output displays two deployment ids:

Immagine che contiene testo, schermata, Carattere Il contenuto generato dall'IA potrebbe non essere corretto.

The UAG id for HCS on vSphere is the second id.

Immagine che contiene testo, schermata, Carattere Il contenuto generato dall'IA potrebbe non essere corretto.

Now I need to recover only the UAG IDs and OrgIDs

Invoke-RestMethod -Uri https://cloud-sg.horizon.omnissa.com/admin/v2/uag-deployments -Method Get -Headers $Header | Select-Object -ExpandProperty content | Select-Object id,OrgId

Immagine che contiene testo, schermata, Carattere Il contenuto generato dall'IA potrebbe non essere corretto.

The UAG id that I need to use for identifying the deployment for HCS on vSphere is:

6994998bcb2a7086afaddf1c 

I will use this ID to associate the syslog configuration with the UAG server.

 

How to set the correct parameters for Syslog configuration

We need to create a Body value like this:

$Body = @{
  orgId  = "8a4931b3-e6ac-44bf-9d25-723f4119e46f"
  projectId = "Pollaio-Project"
  name = "Pollaio-Configuration2"
  syslogEventCategory = "ALL_EVENTS"
  syslogServerProtocolSettingsCreateTO = @{
    sourceToSyslogServerProtocol = "TCP"
  }
  syslogFormat = "TEXT"
  syslogURI = "192.168.111.223:514"
  includeSystemMessages = $true
  sources = @(
    @{
      type = "UAG"
      id   = "6994998bcb2a7086afaddf1c"
    }
  )
}

.

Where:

Value Description Accept value
OrgID It is the OrgId that we recovered with the previous command String
ProjectId ID of theCSP project that owns this data String
Name User defined name of the syslog server configuration String
SyslogEventCategory Events sent from the UAG appliance to the syslog server [ ALL_EVENTS, AUDIT_EVENTS ]
sourceToSyslogServerProtocol The protocol used to send data from the UAG appliance to the syslog server [ UDP, TCP, TLS, MQTT ]
syslogFormat [ JSON_TITAN, TEXT ]
syslogURI Syslog server URI String
includeSystemMessages If true, system messages are sent to the syslog server [ $True]
sources

List of sources associated with the syslog server:

Type = Source for the syslog server. For es: UAG

Id = Id of the source associated with the syslog server (The Id value that we recovered with the previous command

 

.

.

How to set the configuration for UAG
$Body = @{
  orgId  = "8a4931b3-e6ac-44bf-9d25-723f4119e46f"
  projectId = "Pollaio-Project"
  name = "Pollaio-Configuration2"
  syslogEventCategory = "ALL_EVENTS"
  syslogServerProtocolSettingsCreateTO = @{
    sourceToSyslogServerProtocol = "TCP"
  }
  syslogFormat = "TEXT"
  syslogURI = "192.168.111.223:514"
  includeSystemMessages = $true
  sources = @(
    @{
      type = "UAG"
      id   = "6994998bcb2a7086afaddf1c"
    }
  )
}

#Convert Body to JSON
$JsonBody = $Body | ConvertTo-Json -Depth 5
#Send POST request to create Syslog Server UAG configuration
Invoke-RestMethod -Uri https://cloud-sg.horizon.omnissa.com/admin/v1/syslog-server -Method Post -Headers $Header -Body $JsonBody
HOW to check SYSLOG Configuration on UAG deployment

 

Invoke-RestMethod -Uri https://cloud-sg.horizon.omnissa.com/admin/v1/syslog-server -Method Get -Headers $Header

The command output is like this:

.

 Now I can see in my SYSLOG server the UAG Log

Immagine che contiene testo, schermata, Carattere Il contenuto generato dall'IA potrebbe non essere corretto.

.

.

.

Horizon Cloud Service Next Gen Apis – Chapter 2

Replacing the Public Certificate on Your Omnissa Unified Access Gateways

.

Close-up of a screen with a lock and text

AI-generated content may be incorrect.So, you’ve got your shiny new public SSL certificate, and it’s time to make your Unified Access Gateways (UAGs) happy. Excellent choice — a properly installed certificate keeps your users safe, your browser warnings quiet, and your security team smiling.

.

In this post, I’ll walk you through how to replace or install a new public certificate on your Omnissa Unified Access Gateways.
We’ll use a
PFX (PKCS#12) certificate file, since it neatly bundles the private key, certificate, and intermediates in one convenient package.

.

My Preferred Setup

I like to keep things clean and consistent, so instead of juggling multiple certificates, I use a single public certificate for all Unified Access Gateways in my deployment.

Here’s the trick:
When generating or requesting your certificate, make sure the
Subject Alternative Name (SAN) section includes:

• The VIP used to access the UAGs through the load balancer (Normally, a public FQDN)

If you use the UAGs for internal access (for network segmentation), I suggest adding to SAN the internal UAG FQDN.

.

🔧 Step-by-Step: Installing the Certificate

(Insert screenshots of each step here)

1.Log in to the UAG admin console
Open your browser and connect to the UAG admin interface:
2.https://<UAG-FQDN>:9443/admin

A screenshot of a login form

AI-generated content may be incorrect.

Sign in with your admin credentials.

A screen shot of a computer

AI-generated content may be incorrect.

3.Go to the TLS/SSL Settings
From the left menu, navigate to:

System Configuration → TLS Server Certificate Settings

A screenshot of a computer

AI-generated content may be incorrect.

4. Prepare your PFX file
You should already have your .
pfx file ready, containing:
◦ Your public certificate
◦ Any intermediate certificates
◦ Your private key

You’ll also need the PFX password you set when exporting the file.

5 .Import the new certificate
In the TLS configuration page, click
Select PFX, browse to your certificate file, and enter the password.
Then hit
Save at the bottom of the page.

A screenshot of a computer

AI-generated content may be incorrect.

A green rectangle with black text

AI-generated content may be incorrect.

6. Wait for the magic
The Unified Access Gateway will automatically restart the Edge service to apply the new certificate.

Grab a coffee ☕ — it only takes a few seconds.
7 .Verify everything works
Once the UAG is back online, open the VIP URL in your browser
or Horizon Client and check the certificate details.
Browser

A screenshot of a computer

AI-generated content may be incorrect.

Horizon Client

A screenshot of a login screen

AI-generated content may be incorrect.

.

Bonus Tips

• Consistency is key: Replace the certificate across all your UAGs (behind the same Public FQDN).
• Backup the old cert: Always keep a copy of the previous working certificate — just in case something goes sideways.
• Keep a note of the certificate expiration date and plan your next renewal ahead of time (trust me, future-you will thank you).
IMPORTANT: Once you’ve changed the certificate, always verify that it works. Especially if you have thin clients, make sure they have loaded the necessary certificates (RootCA and SubCA) to validate the new certificate.

. That’s It!

You’ve successfully installed a new public certificate on your Omnissa Unified Access Gateways.
Your users now enjoy secure, trusted access — and you get the satisfaction of another clean green padlock in the browser.

.

Replacing the Public Certificate on Your Omnissa Unified Access Gateways

Use NSX Advanced Load Balancer for Omnissa Unified Access Gateway (Omnissa Horizon VDI)

In the various activities carried out in the year that is ending, load balancing and the other availability of Horizon solutions for both access from the Internet and from the company LAN were among the activities that required multi-handed work between the teams that deal with IT technologies within the company (Security, Network, EUC, Servers …).

While these synergies are easy to manage in the context of small companies, when working with large companies, timely planning and design become very important to avoid infrastructural changes (even minimal) that can convert into delays in the delivery of the infrastructure due to the need to re-engage a different team.

One of solutions used to balance access to Omnissa Horizon services is NSX Advanced Load Balancer.

Normally, the publication of Omnissa VDI solutions is carried out using the virtual appliances Unified Access Gateway (UAG) where “Omnissa Unified Access Gateway enables secure remote access from an external network to a variety of internal resources provided by Omnissa Workspace ONE and Horizon deployments.”

Natively UAGs have their own HA solution, but it has the requirement of having 3 Public IP Addresses and creating three public FQDNs.

The use of NSX Advanced Load balancer allows various UAG balancing solutions:

Single VIP with Two Virtual Services

Single L4 Virtual Service

(n+1) VIP

In my HomeLab I have tested the various solutions indicated above,

the most interesting is the one that I propose you try for the following reasons:

• Robust enough to handle the persistence issues

• Works well in environments where users come behind the NAT

• Ease of configuration

• Better visibility and logs

Additionally, the standard ports of the Blast and PCo protocols will not be used, as this can easily expose the solutions to potentially malicious individuals.

The infrastructure that I will propose also requires a change to the “classic” UAG configurations on the URLs used for the Blast and PCOIP protocols.

In the implementation that we will do, we will take as an example only the part of the Blast protocol

The following flow explains the step when a user tries to access Omnissa VDI, the flow has two ports opened for primary and secondary traffic:

    • Port 443 – This is for XML API traffic
    • Ports 5001 to 5002 – Horizon internal ports opened for L7 primary XML traffic to handle redirected traffic
    • Ports 30001 to 30002 – Blast

Where:

  1. Client L7 request comes to AVI LB
    https://horizon.pollaio.site/ 
  2. AVI LB chooses 1 pool member (say UAG1) and send back to client a 307 redirect Location
    https://horizon.pollaio.site:5001 
  3. Client sends request on redirected port
    https:// horizon.pollaio.site:5001 
  4. AVI LB (L7) sends requests to UAG1
    https:// horizon.pollaio.site:5001
    (Port Traslation)*
  5. UAG1 responds back with XML payload
  6. AVI LB parses the XML response and replace the L4 ports (to client)
    https:// horizon.pollaio.site:30001 (blast) 
  7. Client sends L4 request for Blast to AVI LB
  8. AVI LB sends request to UAG
    https:// horizon.pollaio.site:30001*
  9. UAG1 responds back to AVI LB
  10. AVI LB responds back to client

The main aspect is the correct configuration of TCP and UDP ports between the various corporate network segments:

Source

Destination

Protocol

Port

Unified Access Gateway

Horizon Agent

UDP

22443

Unified Access Gateway

Horizon Agent

TCP

22443

Unified Access Gateway

Horizon Connection Server

TCP

443

Horizon Client

Virtual Service AVI

TCP

443

Horizon Client

Virtual Service AVI

UDP

443

Horizon Client

Virtual Service AVI

TCP

5001

Horizon Client

Virtual Service AVI

UDP

5001

Horizon Client

Virtual Service AVI

TCP

5002

Horizon Client

Virtual Service AVI

UDP

5002

Horizon Client

Virtual Service AVI

TCP

30001

Horizon Client

Virtual Service AVI

UDP

30001

Horizon Client

Virtual Service AVI

TCP

30002

Horizon Client

Virtual Service AVI

UDP

30002

Configurazione NSX ALB

  1. Create a Virtual IP
  2. Create a Custom Health Monitor for UAG
  3. Create a UAG Pool
  4. Install the SSL certificate Required for L7 VIP
  5. Create a Virtual Service for UAG
  6. Binding DataScripts to the Virtual Service

Create a Virtual IP

  1. To create a custom health monitor, navigate to Applications > VS VIPs.
  2. Click Create.

Create a Custome Health Monitor

  1. To create a custom health monitor, navigate to Templates > Profiles > Health Monitors.
  2. Click Create.
  3. Select the VMware Cloud that was created for Horizon.

Enter the following details in the New Health Monitor screen

A screenshot of a computer

Description automatically generated

A screenshot of a computer

Description automatically generated

A screenshot of a computer

Description automatically generated

Create UAG Pool

  1. Navigate to Applications > Pools.
  2. Select the cloud from the Select Cloud window.
  3. Click Next.
  4. Click Create Pool.
  5. In the CREATE POOL screen, update the details as shown below:
A screenshot of a computer

Description automatically generated

  1. In the Servers tab, add the Server IP Address of the UAG servers.
A screenshot of a computer

Description automatically generated

A screenshot of a computer

Description automatically generated

  1. In Health Monitor tab, select the appropriate Health profile as shown below:
A screenshot of a computer

Description automatically generated

Installing the SSL certificate Required for L7 VIP

The public certificate must be imported into AVI LB it need the same imported in to UAG.

The certificate to be imported must be in PEM format.

Once imported, ensure that the CA certificate is properly linked.

Here are the steps to import the certificate

  1. To import a CA Certificate, navigate to Templates > Security > SSL/TLS Certificates.
  2. Click Create.
  3. Select Root/Intermediate CA Certificate.
  4. Provide a name to identify the certificate later
  5. Upload or Paste Certificate File

VALIDATE and SAVE

A screenshot of a certificate

Description automatically generated

A screenshot of a computer

Description automatically generated

A screenshot of a computer screen

Description automatically generated

Creating Virtual Service for UAG

To create the new virtual service,

  1. Navigate to Applications > Virtual Services.
  2. Click CREATE VIRTUAL SERVICE > Advanced Setup.
  3. Bind the virtual service VIP.
  4. Use the System-HTTP-Horizon-UAG as the Application Profile.
  5. Configure the virtual service as shown below:
A screenshot of a computer

Description automatically generated

A screenshot of a computer

Description automatically generated

A screenshot of a computer

Description automatically generated

  1. In the Service Port section, click Switch to Advanced and configure the service ports.
A screenshot of a computer

Description automatically generated

A screenshot of a computer

Description automatically generated

  1. Bind the pool and the SSL certificate added,
  2. Click Next.

Click Next and Save the configuration.

NOTE:

Two ports are opened for primary and secondary traffic:

    • Port 443 – This is for XML API traffic
    • Ports 5001 to 5002 – Horizon internal ports opened for L7 primary XML traffic to handle redirected traffic
    • Ports 30001 to 30002 – Blast

Configure DataScript

  • Binding the Horizon DataScript on the Virtual Service
  • From the UI, navigate to Applications > Virtual Services.
  • Edit the virtual service that was created.
  • Go to Policies > DataScripts.
  • Click Add DataScripts.
  • Under Script To Execute, select System-Standard-Horizon-UAG.
  • Click Save DataScript and click Save.

System-Standard-Horizon-UAG is embedded AVI Load Balancer Datascript

A screenshot of a computer

Description automatically generated

UAG Configuration

Modify each UAG’s Blast and PCoIP external URL fields to use the custom ports added in the NSX Advanced Load Balancer port map (From the UI, Edit Pool > Servers tab under New Pool or Edit Pool page).

A screenshot of a computer

Description automatically generated

Modify the Blast external URL to include the custom port for UDP.

For example, https://<ENAV_PUBLIC_FQDN>.com:<BLAST-CUSTOM-PORT>/?UDPPort=<BLAST-CUSTOM-PORT>.

https://horizon.pollaio.site/:30001?udpport=30001

https://horizon.pollaio.site/:30002?udpport=30002

A green check mark and a green box

Description automatically generated

Verify the Tunnel External URL

A green check mark and a green box

Description automatically generated

Now we are ready to test and verify the access flow to my VDI.

    • Port 443 – This is for XML API traffic
    • Ports 5001 to 5002 – Horizon internal ports opened for L7 primary XML traffic to handle redirected traffic
    • Ports 30001 to 30002 – Blast

Where:

    • Port 443 – This is for XML API traffic
    • Ports 5001 to 5002 – Horizon internal ports opened for L7 primary XML traffic to handle redirected traffic
    • Ports 30001 to 30002 – Blast
A screenshot of a login screen

Description automatically generated

A screenshot of a computer

Description automatically generated

A screenshot of a computer

Description automatically generated

A computer screen shot of a black screen

Description automatically generated

A screenshot of a computer

Description automatically generated

Refer:

NSX Advanced Load Balancer for Load Balancing UAG Servers

Use NSX Advanced Load Balancer for Omnissa Unified Access Gateway (Omnissa Horizon VDI)

NSX Advanced Load Balancer renew/replace SSL certificate

 

In the production and home lab environments, the SSL Certificate is a point of attention that is especially important when the certificate is nearing its expiration date.

Normally, the expiration date is important to note in an Outlook calendar or other tool as a reminder to renew (a few days before, because if a Public CA generates the certificate, the renew requires waiting some days to have the certificate file). It is important to renew the certificate because some applications can stop running, and for the visibility of our business, it may have a bad reputation.

 

A screenshot of a computer error

Description automatically generated

Well in my home lab, where I use the NSX Advanced Load Balancer for Omnissa Horizon, at this time (Christmas Day) my wildcard SSL expired.

Well, I use a Let’s Encrypted certificate (free certificate) and I use Cerbot tool for the renewal.

On my PC where I installed the Cerbot tool I use this command to renew and create the certificate file:

certbot certonly –manual -d *.pollaio.site -d pollaio.site –agree-tos –preferred-challenges dns –server https://acme-v02.api.letsencrypt.org/directory –key-type rsa

A screenshot of a computer program

Description automatically generated

and I need to add a new TXT record on my DNS provider.

After adding the TXT record I can continue

A computer screen with white text

Description automatically generated

Now I have in my Cerbot directory this new file:

A screenshot of a computer

Description automatically generated

Well, I will use the cer9.pem, chain9.pem and privkey9.pem for the certificate renewal on NSX ALB.

Access NSX ALB console, go to templates zone and under Security select SSL/TLS Certificates

A screenshot of a computer

Description automatically generated

We need to add the new certificate, I suggest to create a new entry and not replace the actual certificate.

Under Create select Application Certificate

A screenshot of a computer

Description automatically generated

Add the certificate name (I normally add the name and the expiration date or the creation date) and how certificate type select Import

A screenshot of a certificate

Description automatically generated

In the first import select the certificate file, in the second import the private key.

Validate and Save the change.

Now in to the certificate list we have the new SSL certificate

If the certificate has an orange warning it is probably because we don’t have the full certificate chain and we need to load the root and sub ca on NSX ALB.

In the same console page where we show the uploaded SSL certificate we have at the bottom a section where we see the Root and Sub CA and we don’t watch the R10

A screenshot of a computer

Description automatically generated

Ok, no problem we have the chain9.pem file …

A screenshot of a computer

Description automatically generated

Select Create the root/intermediate CA Certificate

A screenshot of a computer

Description automatically generated

and import the pem chain file, Validate and Save

A screenshot of a computer

Description automatically generated

Now the row with the new certificate doesn’t show any warning or error

Now we are ready to replace the SSL certificate on Virtual Service.

Go to Application Menu, Virtual Service and edit the VS where we want to change the SSL certificate

A screenshot of a computer

Description automatically generated

On the bottom select the correct certificate form menu and remove the old certificate, after Save the change.

A screenshot of a computer

Description automatically generated

Now the SSL certificate is validated and I can connect to my VDI

A screenshot of a login screen

Description automatically generated

NSX Advanced Load Balancer renew/replace SSL certificate

Omnissa Unified Access Gateway and headersToBeLogged

A close-up of a sign

Description automatically generated

About the 2312 Unified Access Gateway version there is a new log function to increase the Readable of the esmanager.log (default log level).

This function is HeadersToBeLogged and is enabled by default from 2312. The default value for this field is set to X-Forwarded-For and includes the details for Username, Client build, and Client version.

These details will be added to the esmanager.log file.

For example for connection to VDI from the Internet :

Where:

  • 4.232.131.22 is the public IP of my OS from I try to connect
  • 192.168.222.222 is the IP of My LB in front of UAG
  • pbrividi is my username
  • VMware-Horizon-Client-Win32-Windows is the type of client
  • 8.13.0-9986028157 is the Horizon Client Build

To modify the logged information I need to change the JSON or ini file:

This is the default configuration for headersToBeLogged

A screenshot of a computer

Description automatically generated

I can add this value :

And I can see more info

Omnissa Unified Access Gateway and headersToBeLogged

Horizon 2406 License and Edge Gateway

I have updated Horizon to 2406 and I see the following banner?

I upgraded Horizon to 2406 and have a subscription license, do I have to install the Edge Gateway to activate the licenses?

Well, I recommend you read this post of mine.

New features in Horizon version 2406 include changes to license management, including:

  • The ability to activate subscription Plus and HUL licenses even without deploying the EDGE Gateway (we will see the details in a future post)
  • The degraded mode

Activation without EDGE Gateway

we will have the following advantages:

  • Due to corporate or administrative policies, some customers cannot have production environments that send data to the cloud. With this new feature, they will be able to enjoy the benefits of subscription Plus licenses to HUL without sending data
  • They will not have to dedicate resources to the Edge Gateway (8 vCPUs and 32 GB RAM)

The only activity to do, if you do not have the EDGE gateway installed, is to remember to reactivate the license every 105 days in a very simple way by clicking on the button on the licenses page

Degraded Mode

When Horizon console switch to degraded mode?

  • When there are no Horizon licenses installed (see first-time installation)
  • When a perpetual customer upgrades their connection server to version 2406
  • When the term/subscription license expires

What does it involve?

Entering the degraded state involves the following situations:

  • In the Inventory -> Desktops – Add button will be disabled
  • In the Inventory -> Farms – Add button will be disabled
  • In the Inventory -> Desktops -> Automated Desktop Pool -> Edit -> Provisioning Settings -> Desktop Pool Sizing – Maximum Machines input field will be disabled
  • In the Inventory -> Farms -> Automated Farms -> Edit -> Provisioning Settings -> Farm Sizing – Maximum Machines input field will be disabled
  • In the Inventory -> Desktops -> Pools Summary -> Maintain -> Schedule button will be disabled
  • In the Inventory -> Farms -> Farms Summary -> Maintain -> Schedule button will be disabled
  • In the Inventory -> Desktops -> Duplicate button will be disabled.

The features will be re-enabled when you adjust the license

So you ask me, what happens if we upgrade the version of Horizon to version 2406 and have perpetual licenses?

The following banner appears on the first access (the status is degraded mode with the restrictions indicated above)

You will need to reactivate your license by opting for one of the following options:

In the case of perpetual licenses, select Term or Perpetual license and enter the code

A screenshot of a computer

Description automatically generated

The inclusion of the degraded mode also changes the management of the expiration of the so-called TERM licenses from version 2406:

A diagram of a number of days

Description automatically generated with medium confidence

While for subscription HUL or Plus licenses it is also necessary to think about the failure to verify licenses through the EDGE or manual reactivation without the EDGE.

A white background with red and yellow circles and black text

Description automatically generated

Horizon 2406 License and Edge Gateway

App Volumes 2406 and Unified Access Gateway 2406

All of VMware’s EUC products were continuously updated (in recent years almost always every 3 months) to add new features, fix bugs and mitigate security vulnerabilities.

The move to Broadcom and the subsequent sell of EUC products in Omnissa has brought a few months of stabilization… but I’m happy to announce that versions 2406 of the App Volumes and Unified Access Gateway products are out.

What do we find new?

A logo with text on it

Description automatically generated

App Volumes

Persistent Desktop Support

Expanded Use Cases: New support for classic Windows desktop environments, a significant enhancement to our Apps Everywhere strategy. This new feature extends our efficient one-to-many provisioning model, previously available only for non-persistent desktops, to persistent virtual desktop environments.

And more…

Replicate Application Packages in Specific Stages

We are excited to introduce the Replicate Application Packages in Specific Stages feature, designed to enhance the life cycle management of applications across multiple instances of App Volumes Manager

And more…

Select a specific Package Version when Launching an App (Technology Preview)

Writable Volumes Performance Improvements

Here the Release Notes

A logo of a cloud security system

Description automatically generated

Unified Access Gateway

Added support for Horizon Connection Server’s Home Site Redirection feature (associated with Cloud Pod Architecture)

Added support for Basic and NTLM authentications in outbound proxy configuration.

Added support in PowerShell script to enable/disable monitoring of unrecognized sessions using the new field unrecognizedSessionsMonitoringEnabled.

And more..

Here the Release Notes 

 

The 2406 version of the Connection Server ……..stay tuned!

App Volumes 2406 and Unified Access Gateway 2406

VMware Horizon 2312

As usual, every 3 months VMware releases a new version of Horizon (and also of almost all EUC applications)
The following have been available for a few days:
Horizon 8 2312
App Volumes 4 2312
Dynamic Environment Manager 2312
ThinApp 2312

Among the various features released for Horizon 8, the most interesting one is Agent Auto Upgrade:

“The agent auto upgrade feature allows customers to automatically initiate upgrades without manual intervention. To utilize this feature, on-premises systems must have access to CDS servers. Customers without CDS access can establish their webserver, host the agent components, and then register the agent build with the connection server to upgrade agents in VDI/RDSH desktops. This feature requires Horizon Plus or Horizon Universal License, and is available for Full Clone Desktops and RDSH Servers only. To upgrade Horizon Agent in Instant Clone Desktop Pools or RDS Farms, upgrade Horizon Agent on the Golden Image and schedule maintenance to push the new image.”

VMware Horizon 2312

How to test communication between UAG and CS

Many times I found myself having to demonstrate that the communication between the Unified Access Gateway and the Connection Servers was not working due to problems with poorly configured firewall rules. A very useful test is to connect to the UAG console and launch the classic CURL command:

curl -v -k https://<FQDN or IP ADDRESS CS>:443/

the outcome of which is as follows if the connection is ok (HTML output)

or the following if the connection is not enabled on the firewall

More info and tools here:

https://docs.vmware.com/en/Unified-Access-Gateway/2309/uag-deploy-config/GUID-390D3A2A-0CB7-4A82-9B0F-D525B74CF55B.html

How to test communication between UAG and CS

421 Unknow

After upgrading Horizon to 2306 2212.1 or 2111.1 we see this message when trying to connect from UAG

In the log, I see this error:

2021-09-24T22:05:34.737-07:00 ERROR (1B08-1A58) <SimpleDeamonThread> [h] (ajp:admin:Request190) Unexpected Origin: https://newname.net

2021-09-24T22:05:34.738-07:00 DEBUG (1B08-1A58) <SimpleDeamonThread> [v] (ajp:admin:Request190) Response 404 Not Found [close]

The fast solution is to set allowUnexpectedHost to true on the locked.properties file. This is located on each connection server in     c:\program files\vmware\VMware View\Server\sslgateway\conf. and restart the horizon connection services

Cross-Origin Resource Sharing (CORS) with Horizon 8 and loadbalanced HTML5 access. (85801) (vmware.com)

Error 421 while connecting to Horizon via HTML Web Console after an upgrade to 2306,2111.1 or Later (93915) (vmware.com)

421 Unknow