For more information regarding the security incident at F5, the actions we are taking to address it, and our ongoing efforts to protect our customers, click here.

Forum Discussion

JSinclair_21981's avatar
JSinclair_21981
Icon for Nimbostratus rankNimbostratus
Sep 02, 2015

VMware View iApp - Disable PCoIP Traffic Proxy with APM

I am trying to get the Horizon View iApp (1.2.1) to work with our multi-View setup in our organization. Our BIG-IP is version 11.6.0 HF5. When configuring the iApp, it is set to deploy BIG-IP Access Policy Manager, securely proxy PCoIP traffic using APM as gateway, and perform SSL bridging. I modified the access policy to detect the Active Directory user's group membership and route to a different resource pool of view connection servers based on where there desktop is. This is all working great (except for our Tera 1 zero clients), but all PCoIP traffic is being tunneled through the BIG-IP. This is fine for external connectivity, but I want to deploy this to internal clients. If I connect to the internal VIP, it just does a straight proxy to the view connection server, ignores all access policies and allows the UDP traffic to go between the client and the desktop, which is what I want. Is there a way to perform the pre-authentication APM policies on the internal VIP, or configure the external VIP to only perform the pre-authentication and NOT proxy UDP PCoIP traffic? I have combed through the deployment guide and see a lot of examples, but it's not very clear if this is possible or not. Thanks in advance for any guidance or help!

 

No RepliesBe the first to reply