<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: VMware Horizon View via Load-Balancer in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/vmware-horizon-view-via-load-balancer/m-p/396932#M91436</link>
    <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/158674"&gt;@evangoulden1990&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;It definitely sounds like asymmetric routing as&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/27580"&gt;@OtakarKlier&lt;/a&gt;&amp;nbsp;brought up. Just to verify though, have you gone through the firewall logs and verified that you aren't dropping any of the Horizon View traffic? The PCoIP connection doesn't always get identified correctly via app-id and you could be dropping the 4172 traffic if it's being identified as standard ssl.&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Fri, 09 Apr 2021 16:47:00 GMT</pubDate>
    <dc:creator>BPry</dc:creator>
    <dc:date>2021-04-09T16:47:00Z</dc:date>
    <item>
      <title>VMware Horizon View via Load-Balancer</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/vmware-horizon-view-via-load-balancer/m-p/396783#M91407</link>
      <description>&lt;P&gt;Hi All, First time posting here. We have a fairly large deployment of VMware Horizon View and we're recently migrated from our old firewalls (Fortigate) to Palo Alto and since then inbound connections to our View Platform at this site have stopped working. The basic inbound connection follows this flow:&lt;BR /&gt;&lt;BR /&gt;External Client --&amp;gt; Palo Alto External --&amp;gt; Palo NAT to VIP on F5 LB --&amp;gt; F5 LB balance traffic to VMware UAGs --&amp;gt; Internal F5 LB --&amp;gt; F5 LB Balance Traffic to VMware Connection servers --&amp;gt; VMware VDI Desktops.&lt;BR /&gt;&lt;BR /&gt;I have done various packet captures and it looks as though traffic is being passed through the load balancers and the return traffic is going back through the load balancers so the session should still be open on the Palo. When we connect to VDI we are presented with an RSA login prompt, this goes through successfully, the next step is to add the username and password, this just hangs and then eventually errors out.&lt;BR /&gt;&lt;BR /&gt;Packet captures on the client workstation show that there is 2-way communication until the point where the client errors out.&lt;BR /&gt;&lt;BR /&gt;2x things to note here, the ISP where the inbound connections enter is not the default gateway, the default gateway is another firewall (soon to be migrated to the same Palo) so inbound source translation is needed for the return traffic to work. The other is the VMware UAG's are not in a DMZ they are on the LAN/ server network.&lt;BR /&gt;&lt;BR /&gt;Has anyone experienced similar issues or know of a way around this?&lt;/P&gt;</description>
      <pubDate>Fri, 09 Apr 2021 08:29:01 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/vmware-horizon-view-via-load-balancer/m-p/396783#M91407</guid>
      <dc:creator>evangoulden1990</dc:creator>
      <dc:date>2021-04-09T08:29:01Z</dc:date>
    </item>
    <item>
      <title>Re: VMware Horizon View via Load-Balancer</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/vmware-horizon-view-via-load-balancer/m-p/396798#M91408</link>
      <description>&lt;P&gt;The error that is shown on the client is 'Could not establish tunnel connection'.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 09 Apr 2021 08:30:50 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/vmware-horizon-view-via-load-balancer/m-p/396798#M91408</guid>
      <dc:creator>evangoulden1990</dc:creator>
      <dc:date>2021-04-09T08:30:50Z</dc:date>
    </item>
    <item>
      <title>Re: VMware Horizon View via Load-Balancer</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/vmware-horizon-view-via-load-balancer/m-p/396897#M91424</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;So lots of hops and different devices there. My mind goes to asymmetric routing somewhere. I would say follow the packet paths and see where they lead.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;BTW good move on migrating away from the Forti's.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;</description>
      <pubDate>Fri, 09 Apr 2021 15:06:19 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/vmware-horizon-view-via-load-balancer/m-p/396897#M91424</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2021-04-09T15:06:19Z</dc:date>
    </item>
    <item>
      <title>Re: VMware Horizon View via Load-Balancer</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/vmware-horizon-view-via-load-balancer/m-p/396932#M91436</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/158674"&gt;@evangoulden1990&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;It definitely sounds like asymmetric routing as&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/27580"&gt;@OtakarKlier&lt;/a&gt;&amp;nbsp;brought up. Just to verify though, have you gone through the firewall logs and verified that you aren't dropping any of the Horizon View traffic? The PCoIP connection doesn't always get identified correctly via app-id and you could be dropping the 4172 traffic if it's being identified as standard ssl.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 09 Apr 2021 16:47:00 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/vmware-horizon-view-via-load-balancer/m-p/396932#M91436</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2021-04-09T16:47:00Z</dc:date>
    </item>
  </channel>
</rss>

