Register VCF Operations and Your License Server in Connected Mode

In my previous post, I walked through the process of deploying VMware vSphere Foundation (VVF) in my Home Lab using the VCF Installer, from infrastructure preparation to the initial bring-up of the environment. [If you missed it, you can find it here:

Start a New vSphere Foundation Deployment by Using the VCF Installer Deployment Wizard – BIOLNX

With the deployment up and running, the next step is licensing the environment. In this post, I cover how I activated the VVF licenses, the options available, and a few gotchas I ran into along the way — useful if you’re following the same path in your own lab and want to move from a freshly deployed environment to a fully licensed one.

 

Log in to VCF Operations

From the navigation bar at the top, click Manage and in the left navigation pane, click Licensing -> Licenses & Registration

 

In the Register & License VCF Operations pane, click Continue

 

 

The Register and License VCF Operations workflow appears.
The first step of the procedure is complete because a license server is automatically deployed during a new VCF Operations 9.1 deployment and an upgrade to VCF Operations 9.1.

In the Select Connection Mode card, select
Start, and click Continue.

 

 

Navigate to the Registration section.

Get an activation code for your registration. In the Get Activation Code from VCF Business Services console card, click Start

 


The VCF Business Services console opens in a new tab.

 

 

Log in to the VCF Business Services console by using your Broadcom Support Portal credentials.

Select the Site ID to which you want to register this VCF Operations instance, and click
Next. If you have only one site, it is selected by default.

In the VCF Business Services console, оn the Register & License VCF Operations page, navigate to the Registration part of the registration workflow.

In the Name VCF Operations pane, click Start, enter a unique display name for your
VCF Operations instance, and click Save

The FQDN is only saved if you do not enter another display name. If you change the FQDN with another display name, the connectivity between
VCF Operations
and the VCF Business Services console is not impacted. You can change the display name at any time after the registration.

In the Generate Activation Code card, click Start

 

.

A dialog box with the activation code appears.

 

 

Click Copy (and save the info into a notepad file) Verify that you copied the code, and click Finish

Navigate to the VCF Operations instance, and upload the activation code. In VCF Operations, in the Enter Activation Code card, click Start

 


A dialogue box appears.

In the text field, paste the activation code, and click Activate

 

 

 

In the Add Licenses from VCF Business Services console card, click Start

 

 

The VCF Business Services console opens in a new tab.

In the VCF Business Services console, add licenses to your license servers.

 

To complete the registration process, you must first add licenses to each license server.

In the Add Licenses section of the registration workflow, in the card for the respective license server, click Start
On the Allocate Licenses page, enter a display name for the license server.

If you want to split the default license or change a license’s capacity before assigning it, click the vertical ellipsis next to the license. To split the default license, select it from the list and click Create. Enter a name and license capacity for the split license. To change the capacity of a split license, enter the capacity for the license in the New Capacity column. Click Save.

Select licenses from the table to add to the license server, and click Confirm.
To license your environment, you must add at least one primary license to the license servers. You can add licenses during the registration process, or at any time after that.

 

   

 

Download the license file in the VCF Operations instance.

Navigate to the Licenses page.

In the Add Licenses to License Servers section, in the Download card, click
Download.

 

 

On the Register and License VCF Operations page, click Finish

 

 

 

Now we can assign the license to vCenter. Select Assign Primary License after checking the vCenter instance to assign the license.

 

 

 

Select the license to assign and click Assign

 

 

 

Now the assigned license Core Count and Host Count are Green (if you have sufficient licenses to assign)

 

 

 

From vCenter, by accessing from the vSphere client, we can show the license status under Administration -> License -> Version 9+ License

 

 

 

.

Register VCF Operations and Your License Server in Connected Mode

Start a New vSphere Foundation Deployment by Using the VCF Installer Deployment Wizard

For a long time, I wanted to get my hands on VMware vSphere Foundation (VVF) and understand closely how the deployment process has changed with the introduction of the VCF Installer. Thanks to a few days off and a desire to experiment, I decided to dedicate my Home Lab to this project, retracing the entire installation process step by step, from preparing the infrastructure to the first boot of the environment.

In this post, I tell you how I set up the deployment, what hardware and network resources I used, the configuration choices made along the way and, of course, the difficulties encountered (and how I solved them) during the installation via VCF Installer. The goal is to share a practical experience useful to those who want to approach VVF starting from a laboratory environment, without the complexity (and costs) of an enterprise deployment.

In this first post, we will see the installation; in the next posts, we will install/activate the licenses and install the Log component

.

Being a home lab, my environment will consist of nested ESXi Hosts; here are some details:

Physical HW

ESXi Nested

Two VMs where I install my ESXi to 9.1

Check the Machine Certificate for each ESXi; the certificate needs to trust the ESXi FQDN name.

Storage 

As NFS, I created a TrueNAS VM that resides on SSD disks

Network of ESXI nested:

–One connected to my physical network cards of the server where the port group (VM Network) is present, where I will put the Management and Workload VM part of my ESXi servers
–One that is not connected to physical network cards and where I create a port group for the vMotion part
–One not connected to physical network cards and where I create a port group (NFS) for the NFS part (where, in addition to ESXi, I attach a network card for my TrueNAS)

.

Required resources

.

.

.

.

.

.

As you can see, we have, in addition to the vCenter add-ons, which are:

License Server

A part of VCF Operations. Provides secure and integrated license management for your platform.

vCenter

To say that we all know him well

VCF Operation

VMware Cloud Foundation Operations® (formerly VMware Aria Operations) or VCF Operations helps your organisation build, manage, operate, and secure your private cloud infrastructure by deploying and maintaining its fleet-level components, providing visibility and enhanced performance across the workload and infrastructure stack, and helping your organisation stay compliant with regulatory standards and organisational guidelines.

VCF Management Services

VCF 9.1 introduces VCF management services to provide a unified architecture for centralised lifecycle and operational functionalities. The VCF services runtime instance of the first VCF Instance hosts the fleet-level VCF management services components that perform global operations and the instance-level components for that VCF Instance. Every VCF Instance has a VCF services runtime instance that hosts the instance-level VCF management services that run local tasks. This foundation allows for a unified architecture, simplified lifecycle management, and streamlined backup and recovery of all hosted components.

For the VVF in management servers, we have:

Fleet lifecycle

Log management (to be installed in DAY+1)

SDDC lifecycle

Software depot

Telemetry

VCF services runtime

More details: Components in VCF and vSphere Foundation

.

.

.

.

The steps we’ll take are:

1-Installing ESXi (we won’t cover it in this post)
2-Deploying the VCF installer
3-Configuring the DEPOT
4-Deploying VVF

VCF installer installation

.

Log in to Broadcom Support Portal https://support.broadcom.com/ and Download VCF Installer

.

The next step is to deploy the OVA to ESXi or VMware Workstation

.

.

.

.

.

.

 Once the installation of the OVA is finished, access the URL with the IP or FQDN and log in with the admin@local account and password you set during the deployment

.

 

Configure Depot Connection and download the installation Binaries

.

.

.

.

.

Configuration of the repository for downloading the software for installation (vCenter, ESXi, etc.)

A token must be generated from the portal vcf.broadcom.com

To log in from the Support Portal, select Version 9. Licenses can be found

.

.

.

1.Log in to the VCF Business Services console (vcf.broadcom.com)

.

.

Go to the VCF Installer and create the ID of the depot to upload to the portal

.

.

.

Return to the portal and upload the depot ID to the page that opened

.

.

Copy the Activation code and enter it on the vcf installer screen

.

Let’s download the binaries of the VMware vSphere fountadion

.

.

Once the download is complete, we will see everything “Success”

.

Now I have two ESXi Hosts (in my case, nested vvfesxi01.pollaio.lan and vvfesxi02.pollaio.lan) at version 9.1.0, just installed with no particular configuration (No Storage and more)

Deploy VVF

Let’s proceed with the deployment, selecting “Deployment Wizard” from the VCF Installer

.

.

Let’s define the FQDNs for the various components (vCenter…), and I must obviously have already entered the association with the IP in my DNS (always remember the reverse of the DNS)

.

I run the validate all

.

.

.

Now let’s save and continue

.

Select the version of VVF and DNS, NTP server and DNS suffix

.

We add the ESXi hosts

.

Caution: Verify the certificates correctly on the ESXi hosts, and that the hostname is populated correctly

.

Let’s configure the network, where we will enter the configurations for the VVF management, vMotion and NFS part.

Start a New vSphere Foundation Deployment by Using the VCF Installer Deployment Wizard

Migrating Horizon from VMware to Omnissa: Why a Parallel Connection Server Deployment Is Often the Safest Approach

The transition from VMware Horizon to Omnissa Horizon introduced more than just a branding change. Starting with Horizon 2412 and continuing with later releases such as 2503 and 2506, several architectural and configuration elements have been modified.

These changes include licensing format updates, ADAM/AD LDS database modifications, registry key renaming, folder restructuring, and updated group policy templates.

While the official upgrade path works, in many environments a parallel deployment strategy can significantly reduce risk and allow end users to validate the new platform before switching production workloads.

This article outlines the key changes introduced by Omnissa and explains why building a new Horizon pod alongside the existing one can be a practical migration strategy.

.

Key Changes Introduced with Omnissa Horizon

1. New Licensing Model

Beginning with Horizon 2412, Omnissa introduced a new licensing mechanism and licensing portal.

During the transition phase, both VMware and Omnissa license keys are temporarily accepted, but this compatibility window is limited. Later releases, such as 2503.1 ESB and 250,6 rely entirely on the Omnissa License Module (OLM).

If a valid Omnissa license key is not installed after upgrading, the Horizon Console may enter a restricted or degraded mode.

Relevant KB and documentation references include:

• KB 6000212 – Horizon licensing transition guidance
• KB 6000745 – Omnissa rebranding changes and affected components

.

2. ADAM / AD LDS Database Changes

One of the most important backend changes affects the Horizon LDAP (ADAM/AD LDS) database.

Historically, Horizon used application partitions referencing the VMware namespace.
With the Omnissa rebranding, new environments now use the
horizon namespace.

Example:

Old partition naming:

dc=vdi,dc=vmware,dc=int

dc=vdiglobal,dc=vmware,dc=int

New partition naming:

dc=vdi,dc=horizon,dc=internal

dc=vdiglobal,dc=horizon,dc=internal

Omnissa provides a migration script to update the partition names after upgrading all pods to newer versions, such as 2503.

Relevant documentation:

• KB 6000797 – ADLDS partition migration for Horizon

.

3. Registry Key and File System Changes

The rebranding also impacted multiple components of the Horizon installation:

Component

Previous Location

New Location

Installation folder

C:\Program Files\VMware\VMware View

C:\Program Files\Omnissa\Horizon

Logs

C:\ProgramData\VMware\VDM\logs

C:\ProgramData\Omnissa\Horizon\logs

Registry keys

HKLM\Software\VMware, Inc.\VMware VDM

HKLM\Software\Omnissa\Horizon

ADAM DB instance

VMwareVDMDS

OmnissaHzeDS

Because registry paths changed, Group Policy templates (ADMX) were also updated and must be replaced during upgrades.

Failure to update the ADMX files can lead to policies silently no longer applying.

.

Why a Parallel Horizon Deployment Can Be a Better Migration Strategy

Although a direct upgrade of the Connection Servers is supported, the number of changes introduced with the Omnissa transition makes a greenfield-style deployment attractive.

Instead of upgrading the existing servers, consider deploying new Connection Servers alongside the current environment.

Advantages include:

1. Opportunity to Upgrade Windows Server

New Connection Servers allow administrators to deploy a modern operating system, such as:

• Windows Server 2022 or later (Windows 2025 is a like option)

This avoids performing multiple upgrades on the same system.

.

2. User Acceptance Testing

With a parallel deployment, you can:

• publish test desktop pools
• provide pilot users access
• validate authentication flows
• verify DEM and App Volumes integration

Users can test the environment before the production switch.

.

3. Reduced Upgrade Risk

Upgrading in place modifies:

• ADAM database
• registry keys
• services
• folder paths

A clean installation avoids potential issues caused by legacy configurations.

.

Example Parallel Migration Architecture

A typical migration architecture might look like this:

Existing Environment

• Horizon Connection Servers
• Unified Access Gateways
• Instant Clone pools
• DEM and App Volumes

New Environment

• New Omnissa Connection Servers
• New Omnissa Unified Access Gateways
• Same vCenter Server
• Same Active Directory
• Same desktop images
• Same DEM*
• Same App Volumes*

*After migration, it will be upgraded.

This allows a staged migration.

Key points:

• vCenter Server can remain unchanged
• Desktop pools can be recreated or migrated
• User profiles continue to work through DEM

.

Migrating Instant Clone Desktop Pools

In environments heavily using Instant Clones, rebuilding pools manually can be time-consuming.

Automation scripts can accelerate the process by exporting and recreating pools through the Horizon APIs.

In my environment, I use a PowerShell-based migration script that reads the configuration of Instant Clone pools and recreates them on the new pod.

This allows administrators to migrate:

• pool configuration
• entitlements
• naming patterns
• provisioning settings

with minimal manual effort.

This is the link to the script

OMNISSA/OMNISSA – Export and Import Desktop and Entitlements v7.ps1 at main · fabio1975/OMNISSA

.

Reusing DEM and App Volumes

Existing deployments of

• Omnissa Dynamic Environment Manager
• Omnissa App Volumes

can usually remain unchanged during migration.

However, compatibility must always be validated using the official interoperability matrix.

Relevant documentation:

• Horizon interoperability matrix
• App Volumes compatibility with Horizon
• DEM compatibility with Horizon

Official documentation:

These matrices confirm supported combinations between:

• Horizon versions
• App Volumes
• Dynamic Environment Manager
• vCenter Server
• ESXi

.

Suggested Migration Workflow

A practical migration process could look like this:

    1. Deploy new Connection Servers with Omnissa Horizon
    2. Deploy new Unified Access Gateways
    3. Connect the new pod to the existing vCenter
    4. Validate App Volumes and DEM compatibility
    5. Recreate or migrate Instant Clone pools
    6. Perform pilot user testing
    7. Switch production access
    8. Decommission legacy Connection Servers
    9. Create the news GPO for Horizon (we need use the new GPO Templates)
    10. Upgrade the Horizon Agent, DEM and App Volumes

    .

    Final Thoughts

    The transition from VMware Horizon to Omnissa Horizon introduces several structural changes that go beyond simple branding.

    Changes in licensing, LDAP partitions, registry paths, and policy templates can complicate traditional upgrade workflows.

    For many environments, especially large VDI deployments, deploying new Connection Servers in parallel offers a safer and more flexible migration strategy.

    It provides an opportunity to modernize the infrastructure, validate compatibility with components such as App Volumes and DEM, and allow users to test the platform before the final cutover.

    .

    .

    Migrating Horizon from VMware to Omnissa: Why a Parallel Connection Server Deployment Is Often the Safest Approach

    Use NSX Advanced Load Balancer for Omnissa Unified Access Gateway (Omnissa Horizon VDI)

    In the various activities carried out in the year that is ending, load balancing and the other availability of Horizon solutions for both access from the Internet and from the company LAN were among the activities that required multi-handed work between the teams that deal with IT technologies within the company (Security, Network, EUC, Servers …).

    While these synergies are easy to manage in the context of small companies, when working with large companies, timely planning and design become very important to avoid infrastructural changes (even minimal) that can convert into delays in the delivery of the infrastructure due to the need to re-engage a different team.

    One of solutions used to balance access to Omnissa Horizon services is NSX Advanced Load Balancer.

    Normally, the publication of Omnissa VDI solutions is carried out using the virtual appliances Unified Access Gateway (UAG) where “Omnissa Unified Access Gateway enables secure remote access from an external network to a variety of internal resources provided by Omnissa Workspace ONE and Horizon deployments.”

    Natively UAGs have their own HA solution, but it has the requirement of having 3 Public IP Addresses and creating three public FQDNs.

    The use of NSX Advanced Load balancer allows various UAG balancing solutions:

    Single VIP with Two Virtual Services

    Single L4 Virtual Service

    (n+1) VIP

    In my HomeLab I have tested the various solutions indicated above,

    the most interesting is the one that I propose you try for the following reasons:

    • Robust enough to handle the persistence issues

    • Works well in environments where users come behind the NAT

    • Ease of configuration

    • Better visibility and logs

    Additionally, the standard ports of the Blast and PCo protocols will not be used, as this can easily expose the solutions to potentially malicious individuals.

    The infrastructure that I will propose also requires a change to the “classic” UAG configurations on the URLs used for the Blast and PCOIP protocols.

    In the implementation that we will do, we will take as an example only the part of the Blast protocol

    The following flow explains the step when a user tries to access Omnissa VDI, the flow has two ports opened for primary and secondary traffic:

      • Port 443 – This is for XML API traffic
      • Ports 5001 to 5002 – Horizon internal ports opened for L7 primary XML traffic to handle redirected traffic
      • Ports 30001 to 30002 – Blast

    Where:

    1. Client L7 request comes to AVI LB
      https://horizon.pollaio.site/ 
    2. AVI LB chooses 1 pool member (say UAG1) and send back to client a 307 redirect Location
      https://horizon.pollaio.site:5001 
    3. Client sends request on redirected port
      https:// horizon.pollaio.site:5001 
    4. AVI LB (L7) sends requests to UAG1
      https:// horizon.pollaio.site:5001
      (Port Traslation)*
    5. UAG1 responds back with XML payload
    6. AVI LB parses the XML response and replace the L4 ports (to client)
      https:// horizon.pollaio.site:30001 (blast) 
    7. Client sends L4 request for Blast to AVI LB
    8. AVI LB sends request to UAG
      https:// horizon.pollaio.site:30001*
    9. UAG1 responds back to AVI LB
    10. AVI LB responds back to client

    The main aspect is the correct configuration of TCP and UDP ports between the various corporate network segments:

    Source

    Destination

    Protocol

    Port

    Unified Access Gateway

    Horizon Agent

    UDP

    22443

    Unified Access Gateway

    Horizon Agent

    TCP

    22443

    Unified Access Gateway

    Horizon Connection Server

    TCP

    443

    Horizon Client

    Virtual Service AVI

    TCP

    443

    Horizon Client

    Virtual Service AVI

    UDP

    443

    Horizon Client

    Virtual Service AVI

    TCP

    5001

    Horizon Client

    Virtual Service AVI

    UDP

    5001

    Horizon Client

    Virtual Service AVI

    TCP

    5002

    Horizon Client

    Virtual Service AVI

    UDP

    5002

    Horizon Client

    Virtual Service AVI

    TCP

    30001

    Horizon Client

    Virtual Service AVI

    UDP

    30001

    Horizon Client

    Virtual Service AVI

    TCP

    30002

    Horizon Client

    Virtual Service AVI

    UDP

    30002

    Configurazione NSX ALB

    1. Create a Virtual IP
    2. Create a Custom Health Monitor for UAG
    3. Create a UAG Pool
    4. Install the SSL certificate Required for L7 VIP
    5. Create a Virtual Service for UAG
    6. Binding DataScripts to the Virtual Service

    Create a Virtual IP

    1. To create a custom health monitor, navigate to Applications > VS VIPs.
    2. Click Create.

    Create a Custome Health Monitor

    1. To create a custom health monitor, navigate to Templates > Profiles > Health Monitors.
    2. Click Create.
    3. Select the VMware Cloud that was created for Horizon.

    Enter the following details in the New Health Monitor screen

    A screenshot of a computer

Description automatically generated

    A screenshot of a computer

Description automatically generated

    A screenshot of a computer

Description automatically generated

    Create UAG Pool

    1. Navigate to Applications > Pools.
    2. Select the cloud from the Select Cloud window.
    3. Click Next.
    4. Click Create Pool.
    5. In the CREATE POOL screen, update the details as shown below:
    A screenshot of a computer

Description automatically generated

    1. In the Servers tab, add the Server IP Address of the UAG servers.
    A screenshot of a computer

Description automatically generated

    A screenshot of a computer

Description automatically generated

    1. In Health Monitor tab, select the appropriate Health profile as shown below:
    A screenshot of a computer

Description automatically generated

    Installing the SSL certificate Required for L7 VIP

    The public certificate must be imported into AVI LB it need the same imported in to UAG.

    The certificate to be imported must be in PEM format.

    Once imported, ensure that the CA certificate is properly linked.

    Here are the steps to import the certificate

    1. To import a CA Certificate, navigate to Templates > Security > SSL/TLS Certificates.
    2. Click Create.
    3. Select Root/Intermediate CA Certificate.
    4. Provide a name to identify the certificate later
    5. Upload or Paste Certificate File

    VALIDATE and SAVE

    A screenshot of a certificate

Description automatically generated

    A screenshot of a computer

Description automatically generated

    A screenshot of a computer screen

Description automatically generated

    Creating Virtual Service for UAG

    To create the new virtual service,

    1. Navigate to Applications > Virtual Services.
    2. Click CREATE VIRTUAL SERVICE > Advanced Setup.
    3. Bind the virtual service VIP.
    4. Use the System-HTTP-Horizon-UAG as the Application Profile.
    5. Configure the virtual service as shown below:
    A screenshot of a computer

Description automatically generated

    A screenshot of a computer

Description automatically generated

    A screenshot of a computer

Description automatically generated

    1. In the Service Port section, click Switch to Advanced and configure the service ports.
    A screenshot of a computer

Description automatically generated

    A screenshot of a computer

Description automatically generated

    1. Bind the pool and the SSL certificate added,
    2. Click Next.

    Click Next and Save the configuration.

    NOTE:

    Two ports are opened for primary and secondary traffic:

      • Port 443 – This is for XML API traffic
      • Ports 5001 to 5002 – Horizon internal ports opened for L7 primary XML traffic to handle redirected traffic
      • Ports 30001 to 30002 – Blast

    Configure DataScript

    • Binding the Horizon DataScript on the Virtual Service
    • From the UI, navigate to Applications > Virtual Services.
    • Edit the virtual service that was created.
    • Go to Policies > DataScripts.
    • Click Add DataScripts.
    • Under Script To Execute, select System-Standard-Horizon-UAG.
    • Click Save DataScript and click Save.

    System-Standard-Horizon-UAG is embedded AVI Load Balancer Datascript

    A screenshot of a computer

Description automatically generated

    UAG Configuration

    Modify each UAG’s Blast and PCoIP external URL fields to use the custom ports added in the NSX Advanced Load Balancer port map (From the UI, Edit Pool > Servers tab under New Pool or Edit Pool page).

    A screenshot of a computer

Description automatically generated

    Modify the Blast external URL to include the custom port for UDP.

    For example, https://<ENAV_PUBLIC_FQDN>.com:<BLAST-CUSTOM-PORT>/?UDPPort=<BLAST-CUSTOM-PORT>.

    https://horizon.pollaio.site/:30001?udpport=30001

    https://horizon.pollaio.site/:30002?udpport=30002

    A green check mark and a green box

Description automatically generated

    Verify the Tunnel External URL

    A green check mark and a green box

Description automatically generated

    Now we are ready to test and verify the access flow to my VDI.

      • Port 443 – This is for XML API traffic
      • Ports 5001 to 5002 – Horizon internal ports opened for L7 primary XML traffic to handle redirected traffic
      • Ports 30001 to 30002 – Blast

    Where:

      • Port 443 – This is for XML API traffic
      • Ports 5001 to 5002 – Horizon internal ports opened for L7 primary XML traffic to handle redirected traffic
      • Ports 30001 to 30002 – Blast
    A screenshot of a login screen

Description automatically generated

    A screenshot of a computer

Description automatically generated

    A screenshot of a computer

Description automatically generated

    A computer screen shot of a black screen

Description automatically generated

    A screenshot of a computer

Description automatically generated

    Refer:

    NSX Advanced Load Balancer for Load Balancing UAG Servers

    Use NSX Advanced Load Balancer for Omnissa Unified Access Gateway (Omnissa Horizon VDI)

    vSAN ESA and vSAN File Service

    Requirements

    Enable vSAN File Service

    Limitations and Considerations

    Limitations and Considerations of vSAN File Service

    Networking Considerations for vSAN File Service

    After deploying and configuring the vSAN ESA we are ready to enable and configure the vSAN file services.

    Enable File Service

    A screenshot of a computer

Description automatically generated

    A screenshot of a computer service

Description automatically generated

    After Enabling the service we will see on the vCenter a new Resource Pool to allocate the File Service Node VM. (One for Each host ESXi)

    A screenshot of a computer

Description automatically generated

    Configure vSAN File service

    Go to vSAN, Services and under File Service click CONFIGURE DOMAIN

    A screenshot of a computer

Description automatically generated

    A screenshot of a computer

Description automatically generated

    A screenshot of a computer

Description automatically generated

    We need to configure the Directory Service to enable SMB share and NFS Kerberos Authentication.

    The user identity for configuring the directory service must have the correct permission to do a join AD.

    A screenshot of a computer

Description automatically generated

    A screenshot of a computer

Description automatically generated

    A screenshot of a computer

Description automatically generated

    After completing the domain configuration we see the computer accounts in the OU select.

    A screenshot of a computer

Description automatically generated

    Create File Share

    Now we can create the file share

    A screenshot of a computer

Description automatically generated

    Will can create a NFS share with AUTH_SYS or Kerberos Authentication

    A screenshot of a computer

Description automatically generated

    A screenshot of a computer

Description automatically generated

    A screenshot of a computer

Description automatically generated

    A screenshot of a computer

Description automatically generated

    Will can create an SMB share

    A screenshot of a computer

Description automatically generated

    A screenshot of a computer

Description automatically generated

    Configure ACL permission

    SMB SHARE can configure ACL for access use the FSM MMC from a windows OS.

    A screenshot of a computer

Description automatically generated

    A black background with white text

Description automatically generated

    A screenshot of a computer

Description automatically generated

    From best practices Microsoft it suggest to user Everyone on Share permission

    A screenshot of a computer screen

Description automatically generated

    And set the permission on File Level (Security TAB)

    A screenshot of a computer screen

Description automatically generated

    Mount Share

    On every share proprieties, we can find the path to use for mounting the share (The SMB Export Path)

    A screenshot of a computer

Description automatically generated

    Share quota

    The quota control if a specified Share exceed the max space add for it.

    A screenshot of a computer

Description automatically generated

    We can control the state of all share quotas from the vSphere console.

    A screenshot of a computer

Description automatically generated

    A screenshot of a computer

Description automatically generated

    SMB Export Path -> The path to use for mounting the share

    MMC Command -> The command to use for configuring the ACL

    A screenshot of a computer

Description automatically generated

    vSAN ESA and vSAN File Service

    VMware vSphere Foundation for VDI (VVF for VDI)

    A blue and white logo

Description automatically generated

    A black text on a white background

Description automatically generated

    The exit of EUC services from Broadcom (after the acquisition of VMware by the US giant) has brought a situation of uncertainty for all those who have been appreciating for years the features of the VDI/Applications published with Horizon and all the products of the EUC ecosystem that were from VMware.

    The birth of Omnissa (effective from the beginning of July) bodes well for the future (more information in this post of mine from a few weeks ago).

    Of the many synergies that were natural when vSphere and Horizon were children of the same mother, the first uncertainty was the licensing issue.

    VMware gave the possibility, once a specific Horizon license was purchased, to have the vSphere virtualization infrastructure licenses, practically a solution ready to be only implemented. (I remind you that Horizon also goes on other Hypervisors… obviously exploits 10% of the potential… on this issue. I expect news from Omnissa since vSphere and Horizon are no longer brothers). The only limitation of the vSphere license included in Horizon was the need to run on the vSphere platform, licensed with Horizon, only VDI environments and the servers necessary for operation (Connection Server ,,, App Volumes Manager etc ..)

    Now that vSphere and Horizon no longer have the same mother, what happens to these licenses? Will I still be able to buy a bundle with Horizon and vSphere together?

    This link explains that the best of the matter:

    Setting the record straight: EUC to continue to offer Horizon with vSphere and vSAN (omnissa.com)

    Where it is indicated that there will be a collaboration between Omnissa and Broadcom to allow the presence of a bundle with Horizon and vSphere.

    A green and white logo

Description automatically generated

    So it is still possible to purchase one of the following licenses:

    • Horizon Enterprise term
    • Horizon Universal,
    • Horizon Enterprise Plus
    • Horizon Standard Plus
    • Horizon Apps Universal

    What is the name of the vSphere package included in Horizon Solutions?

    VMware vSphere Foundation for VDI (VVF for VDI)

    What does it include?

    • vSphere Enterprise Plus

    • vCenter Standard

    • vSAN Enterprise (100 GB) (licensed per Core)

    So how much space have I included in vSAN?

    Well, the game is quite simple: for each core of my vSphere cluster on which I host VDI and on which I have the VVF for VDI licenses, just multiply 100GB by the number of CORES. (there are no restrictions on the number of cores)

    Let’s focus on the vSAN Enterprise license… what difference do we have from the previous Bundle?

    • vSAN Enterprise includes the same features as vSAN Advanced plus all those of vSAN Enterprise which are:
      • Data-at-rest and data-intransit encryption
      • File services
      • VMware HCI Mesh™2

    In this link more information:

    VVF_VDI_SPD_July2024.pdf (broadcom.com)

    VMware vSphere Foundation for VDI (VVF for VDI)

    EUC, un futuro luminoso per Horizon

    A black and white logo

Description automatically generated A logo of a software company

Description automatically generated A logo for a company

Description automatically generated A close up of a logo

Description automatically generated

    In questi giorni c’è molto fermento nel mondo dell’EUC (‘End-User Computing) in merito alla comparsa sul mercato di un nuovo nome.

    Ma partiamo con ordine, nel lontano 2008 mi avvicino al modo delle VDI (Virtual Desktop Infrastructure) inizialmente con l’automatizzazione di aule corsi, grazie a VMware e al suo prodotto che allora era stato appena rinominato in Horizon View (se non sbaglio precedentemente si chiama VMware VDM….. ancora oggi, nelle installazioni dei Connection Server, troviamo una cartella VDM sotto c:\ProgramData).

    A diagram of a timeline

Description automatically generated with medium confidence

    Col tempo le soluzione VDI di VMware sono evolute in maniera importante con l’aggiunta prima della tecnologia linked clones e poi con le instant clone (tecnologie che permettono di semplificare notevolmente la vita dell’amministratore delle postazioni di lavoro).

    Abbiamo visto l’affiancare a Horizon soluzioni che permettono di sfruttare al meglio le VDI come App Volumes, DEM (Dynamic Environment Manager), Workspace One ecc.…

    Poi dall’on-premise è stato portato anche sul Cloud con soluzione come Horizon Cloud on Microsoft Azure.

    Anche per la mia carriera lavorativa il mondo delle VDI ha lasciato un solco importante dal 2021 sono vEXPERT (Con specificità nel mondo EUC) e dal 2024 sono EUCExpert e collaboro con VMware/Broadcom nel deploy.

    Mi direte ok sono cose che ormai conosciamo ma quindi che cosa è successo??

    Bene, sappiamo tutti che VMware è stata acquisita da Broadcom e una delle prime dichiarazioni della nuova proprietà è stata quella di non volere investire sull mondo EUC.

    Ma quindi che succede?

    Tutto i prodotti EUC di VMware sono riconosciuti tra i leader del mercato dei prodotti VDI e Desktop as a Service sono stati comprati da KKR (Fondo Americano nato nel 1977) per cui nasce Omnissa

    A blue and white logo

Description automatically generated

    Nata con persone VMware per garantire la stessa qualità e lo stesso sviluppo in innovazione che è stato garantito in questi anni.

    In cui continua o parte una nuova vita (scegliete voi) per tutti i prodotti EUC che molti noi conosciamo e apprezziamo  (Horizon ecc…)

    Ne vedremo sicuramente delle belle e ci aspetta un futuro luminoso!

    EUC, un futuro luminoso per Horizon

    Approach to updating a horizon infrastructure

    When approaching the upgrade of an infrastructure in the EUC world (as with most technologies in the IT world) it is necessary to define a roadmap of activities and follow it carefully. In many cases, IT technology vendors already have update procedures in place that should be followed carefully. When I started working as a consultant, the documentation was very scarce (we are talking about the end of the 20th century and the beginning of the 21st…) and the procedures were poorly documented and only those who took courses or had experience could approach with a certain “tranquility” updates of production environments.

    Going back to EUC infrastructures and focusing on the VMware by Broadcom world (still for a while….given the transfer of the technology in question) we have a precise update sequence, especially if we talk about + technologies that interact with each other, and the need to verify the interoperability between the various technologies.

    For example, we have this KB that gives us the upgrade sequence of a Horizon 8 infrastructure:

    Update sequence for Horizon 7, Horizon 8, and compatible VMware products (78445)

    A diagram of software

Description automatically generated

    And the ability to use the interoperability portal:

    https://interopmatrix.vmware.com/Interoperability

    A screenshot of a computer

Description automatically generated

    In my ten-year experience in updates and maintenance of vSphere and Horizon infrastructures, it has often happened that I have had to intervene and manage post-upgrade problems, where in most cases the problems were generated by the fact that I did not perform the update in the correct order or even did not complete all the upgrade steps.

    For example, I have experienced situations where, following upgrades, the copy and glue to and from VDI sessions no longer worked correctly in a Horizon infrastructure.

    In the end, the problem was solved by also performing the update step of the Horizon ADMX templates in Active Directory, something that the customer or whoever had done the update for him had not done.

    Approach to updating a horizon infrastructure

    Horizon 2312, new feature to simplify the Gold Image Linux Configuration

    A penguin and microsoft active logo

Description automatically generated

    Few people know that it is possible use Linux Distribution to create VDI desktop or Stream Application (Like RDS) to publish it with Horizon.

    The desktop pool can to be Instant Clone or Full Clone.

    In the last Horizon version (2312) there is a new functionality to configure the agent, the function have to objective to simplify the installation and also configure the OS ((Like the joined to Active Directory domain).

    In the Horizon Agent for Linux package there is a new command file:

    easyinstall_viewagent.sh

    We can use this command for:

    • Configure Linux OS template
    • Install Horizon Agent

    For complete all previous steps you can start this command (with root privileges)

    ./easyinstall_viewagent.sh

    The command do:

    Platform check

    A black screen with white text

Description automatically generated

    Now you need to insert information like DNS, Hostname, Domain and Account to join to domain

    A screenshot of a computer

Description automatically generated

    Now the script check and install missed packages (SSSD etc.…) and make the domain join

    A screen shot of a black screen

Description automatically generated

    After joined the template to AD domain the script start to install the horizon agent

    A screenshot of a computer

Description automatically generated

    A black screen with white text

Description automatically generated

    Now the Linux GoldI mage is ready to use for create a Horizon instant clone desktop pool or used for Full Clone Desktop Pool.

    It is possible to configure the OS and install Horizon Agent in two different steps

    • Configure OS
      • For configure user Linux OS use this command:

    ./easyinstall_viewagent.sh -c

    • Install Agent
      • After configure the OS we can install the Horizon agent with this command:

    ./easyinstall_viewagent.sh -i

    With this command we can to use some switch value:

    Default (Hostname, Domain FQDN, DOMAIN Join User, DOMAIN Join PASSWORD …)

    Advanced (The same option of DEFAULT with NTP, HORIZON AGENT FEATURE and other)

    Expert (The same option of Advanced with another function)

    In this link more information

    Use the Easy Setup Tool to Prepare a Linux Machine (vmware.com)

    Horizon 2312, new feature to simplify the Gold Image Linux Configuration