Search icon
Arrow left icon
All Products
Best Sellers
New Releases
Books
Videos
Audiobooks
Learning Hub
Newsletters
Free Learning
Arrow right icon
VMWare Horizon Workspace Essentials
VMWare Horizon Workspace Essentials

VMWare Horizon Workspace Essentials: Manage and deliver a secure, unified workspace to embrace any time, any place, anywhere access to corporate apps, data, and virtual desktops securely from any device.

eBook
£22.99 £15.99
Print
£28.99
Subscription
£13.99 Monthly

What do you get with Print?

Product feature icon Instant access to your digital eBook copy whilst your Print order is Shipped
Product feature icon Black & white paperback book shipped to your address
Product feature icon Download this book in EPUB and PDF formats
Product feature icon Access this title in our online reader with advanced features
Product feature icon DRM FREE - Read whenever, wherever and however you want
Buy Now

Product Details


Publication date : Mar 20, 2014
Length 158 pages
Edition : 1st Edition
Language : English
ISBN-13 : 9781782172376
Vendor :
VMware
Table of content icon View table of contents Preview book icon Preview Book

VMWare Horizon Workspace Essentials

Chapter 1. Getting Started with VMware Horizon Workspace

In this chapter, we will introduce you to VMware Horizon Workspace, where it is positioned in the market, and then give you an overview of all the components you need before starting to deploy the technology.

We will also cover where you can download the software from, outline the time requirements to install and configure a successful deployment, and give tips on what to think about for a full production environment. This book is primarily geared towards a test environment, as that's where most projects start. However, we will provide hints, tips, and best practices on building, delivering, and administering a full production environment as well.

Introduction to VMware Horizon Workspace


Horizon Workspace is a new type of solution that is commonly referred to as Workspace Aggregator. A solution that provides end users with a single point of access to their corporate data, applications, and other IT resources, as well as providing IT administrators with a single point of administration.

Let's first discuss the background and challenges that exist in most corporations today.

There are some ongoing technology trends that will affect us all and how we deliver IT services to our end users. A few of these are as follows:

  • BYOD

  • Software-as-a-Service

  • Mobile applications

  • Mobile/tablet devices

  • Always on network connectivity

  • Consumerization

In the last few years, the market has exploded with new devices, applications, and services that have been focused on being easy to pick up and consume with little technical knowledge.

Companies such as Google, Apple, Facebook, Twitter, and Dropbox have had enormous adoption with consumers; all of these services offer a great user experience and is easy to use.

For a long time, corporate IT companies have been able to withstand the pressure from these trends by locking environments down and mandating what users can access by way of applying policies, but we have reached a point where users are starting to circumnavigate these policies and utilize these services directly and not involving the corporate IT department and its policies. This is commonly referred to as shadow IT.

The traditional approach has been to deploy Windows on physical machines, and use some form of a distribution system for deploying applications and securing data. Users typically work between 8 a.m. and 5 p.m., usually from the office, and as the computers are physically attached to the desk, it's been considered secure.

Corporate IT risks turning into a slow moving dinosaur that does not contribute, but rather hinders innovation and users' ability to be productive. Users are starting to avoid involving IT since it takes a long time and is slow moving. There is now a real threat that corporate IT becomes irrelevant thanks to the competition from these outside trends.

Some real examples we have seen is when a business unit goes out and buys a solution somewhere from the Internet and is not even involving corporate IT since it would make the process slower and less productive.

Another common example is when users are using consumer-based file sharing applications to be able to share information or collaborate with partners, internal or external, to their organization.

When exposed to these threats, the following are the three common typical reactions:

  • Ignore it!

    Pretending that your users are not using these services and devices is a sure way of getting a false sense of security and comfort

  • Lock it down!

    Tightening the control even more usually forces people to find ways around the systems and will make the users unhappy

  • Implement a point solution

    Just solving one of the challenges might buy you some time, but in the end will actually increase the complexity since there will be many point solutions to solve all the challenges

Another approach is to embrace the advances in technology and to listen to the users' requests. This is where VMware Horizon Workspace can help.

Horizon Workspace addresses these new challenges, such as delivering web applications, mobile applications, and data collaboration to any device. The key point to highlight is that you can give the users the tools and the modern approach that they have become used to as a consumer, but still retain security and control.

Horizon Workspace 1.5 provides the following functionalities:

  • A single workspace for apps and data

  • Anywhere, anytime access

  • Data synchronization

  • Separate personal and corporate data

  • A virtualized container for Android devices

  • Native application support

  • Detailed policy management

  • Simple user and application management

  • Share files seamlessly and securely

  • Enterprise-grade security

  • Complete on-premise solutions

  • Access controls

So what is the business value for a customer when they deploy this solution? We can divide this into two aspects: one for end users and one for corporate IT.

  • For end users:

    • Easy access to applications, files, and virtual desktops

    • Single Sign-On to internal and external web-based applications

    • One place to access all services

    • A service catalog where the users can quickly get access to new services

    • Own choice of device and networks to work from

    • Use multiple devices without complex configurations or VPN

    • Sanctioned way to share files and collaborate with internal and external parties

  • For corporate IT:

    • Common model on how to entitle and disentitle users to services

    • Faster time to market for new services

    • Stop worrying about devices and start managing users

    • Extensible platform that can be integrated into existing services

    • Common reporting for all types of applications

Ease of deployment

Horizon Workspace comes packaged as a vApp, which means that it's a number of preconfigured virtual machines in a container with the extension .ova. Open Virtual Appliance (OVA) is a standard way of packaging a vApp.

It needs to be deployed using VMware vCenter Server on to a VMware vSphere virtualization platform. We will cover the prerequisites later in this chapter.

The benefits with this type of deployment is many, since the vApp is preinstalled with the operating system (Horizon Workspace is based on Suse Linux Enterprise Server) and all components that make up Horizon Workspace. The only thing you need to do is to configure the unique settings for your environment. There is no complicated operating system to install and configure, and no installer to run.

Just download and deploy.

Another benefit of being deployed within a virtual environment is that we can take advantage of all the features that the virtual infrastructure platform provides for, which are high availability, load balancing, backup, and disaster recovery.

Proving the technology

Before embarking on a Proof of Concept (POC) or Pilot of Horizon Workspace, the following are a few things that we have learned from our experience in working with the technology:

  • Do not run a POC/Pilot on production systems

    • This could possibly interfere with your running systems

  • Do not run a POC/Pilot using production applications.

    • Horizon Workspace can take over the authentication for web-based applications that it integrates with and can disable other ways of authenticating, potentially locking out other users

  • Make sure that you have clearly defined the success criteria. It's hard to know whether you have succeeded if there are no clear goals or objectives defined

Now that we have introduced you to VMware Horizon Workspace, we are going to cover what you need to get your environment up and running in the following sections.

Prerequisites


The first thing we are going to cover are the prerequisites in more details. We will start with the test environment first.

Infrastructure requirements for an initial test setup

You will need the following hardware and virtual infrastructure components:

  • 1 vCenter Server

  • 1 ESXi host server with:

    • A minimum of 8 cores

    • 14 GB RAM

    • 412 GB of local disk or SAN attached storage

The installation and configuration of vCenter and ESXi is beyond the scope of this book and therefore we assume that you already will have this in place.

Note

Using VMware Workstation or VMware Fusion natively does not work since the vApp requires a vCenter to be able to deploy. As an alternative, you could use something known as nested hypervisors. This means that you can use VMware Workstation or Fusion and create a virtual vCenter and virtual instance of ESXi. Be aware though that this will cause considerable overhead and require a powerful CPU, plenty of memory, and a fast disk system.

Infrastructure requirements for production deployment

For production environments, you will need the following minimum hardware and virtual infrastructure components:

  • 1 vCenter-server, redundant

  • 2 ESXi-hosts (3 ESXi hosts are recommended)

  • 500 GB of SAN storage

  • Network Load balancer

  • NFS-storage for Horizon Files

Horizon Workspace supports a number of VMware vSphere versions listed as follows:

  • vCenter: 5.0 U2, 5.1, and 5.5

  • ESXi: 5.0 U2, 5.1, and 5.5

When setting up your ESXi hosts, ensure that you configure them to use the Network Time Protocol (NTP). Correct time synchronization is critical for a successful installation since the SAML-based authentication is based on short-lived assertions of 60 seconds. If there is a time difference, logins will fail.

Network, DNS, and Active Directory requirements

The initial deployment of Horizon Workspace will require 5 IP addresses. If you need redundancy and external access, you will need additional IP addresses. Each of the IP's need a static DNS host record as well as reverse pointer-records (PTR record).

DNS name resolution needs to be fully implemented for both forward and reverse lookups. Horizon Workspace will not function without reverse lookups configured.

For this book, we have used Windows Server 2008 R2 Active Directory and DNS; however, Horizon Workspace supports Windows 2003 Active Directory or later. Using Bind DNS will work just as well as using Microsoft DNS.

As we go through the setup of the Active Directory (AD) infrastructure to support our installation, it's worth making a note of some of the key information that you will be prompted for during the actual configuration process. Make a note of the following information:

  • Name of the Active Directory controller

  • Fully qualified domain name (FQDN) of the Active Directory controller

  • Base DN— the container from where to start searching for users; in our example, this would be something like ou=horizon, dc=domain_name, or dc=local

  • The Bind DN username and password

  • Administrator account or an account with rights to add computers to the domain

Note

The Bind DN username is an account that will be used to communicate with Active Directory to read user information and their attributes. The Bind DN will become the first administrator in your Horizon Workspace installation. In our examples, we have set up a Horizon Administrator account to do this. You need to enter the details in the following format:

cn=horizonadmin,ou=horizon,dc=domain_name,dc=local

vCenter Server requirements

Before installing the vApp, you need to configure an IP pool for the Horizon Workspace vApp that contains the correct IP address range along with details of your DNS server (you can only specify one DNS server). You also need the name of the domain into which you will deploy your VMs.

Note

IP pools are used by vCenter to provide a network identity to vApps. The IP pool itself is a network configuration that you assign to a network used by the vApp. Once set up, the vApp can use vCenter to provide the IP configuration to the virtual machines it contains.

External access

For users to log on to their Workspace, you will need to make sure certain network ports are open. For external access, you will need to ensure that the TCP port 443 is open for the connector-va appliance to communicate. For a production environment with a demilitarized zone (DMZ)—a term for a network between internal and external networks—and connection to external services such as Active Directory and RSA SecureID, additional ports may need to be opened. If you are also integrating with Horizon View, you will need to make sure that those ports are also open.

Certificates

For a production environment, you will need publicly signed certificates from a trusted certificate provider. For a test environment, you can use a self-signed certificate. The certificate must have the FQDN of your Horizon Workspace installation as the Subject Alternative Name (SAN) of the certificate or you can use a Wildcard certificate.

Horizon Workspace vApp


Horizon Workspace comes packaged as a vApp, which means that it's a number of preconfigured virtual machines in a single file with the extension OVA. (The OVA extension is a standard way of packaging a vApp).

There are many benefits with this type of deployment. The vApp is preinstalled with the operating system (Horizon Workspace is based on SUSE Enterprise Linux (SLES)) along with all the components that make up Horizon Workspace. The only thing you need to do is to configure the unique settings in your environment. There is no operating system to install and no installer to run.

Use a naming convention that makes sense to you and is consistent throughout your environment. For a test environment you can keep the default appliance names, but for production, it would make sense to name them, so that they are meaningful to your environment and also as one of the appliances will be the address that your users will use to connect.

Choose your hostnames and enter them into your DNS server along with the associated IP addresses. During the installation process, the appliances will perform a reverse lookup in DNS to determine (resolve) what their hostname is.

An overview of vApp

As we previously discussed, Horizon Workspace is comprised of five virtual appliances as shown in the following diagram:

The five virtual appliances (va) are described in the following list:

  • gateway-va

    The Horizon Workspace Gateway is the single entity for all end user communication. All user requests hit the gateway-va virtual machine, which then routes the request to the appropriate virtual appliance. The Gateway appliance offers a single namespace for accessing the Horizon Workspace implementation.

  • configurator-va

    Horizon Workspace is configured using this virtual appliance, so this appliance configures all the other appliances. It has both a console and a web interface. Any configuration changes you make with the configurator are then distributed to the other virtual appliances within the vApp automatically, for example, SSL-certificates and root passwords.

  • service-va

    Horizon Workspace uses a standard named SAML for authentication of users and to extend the identities, which is explained in more detail in Chapter 4, Integrating SaaS Applications. The service-va controls this function and also provides the frontend for the Administrator Web interface.

  • connector-va

    The Horizon Workspace Connector provides the following services: user authentication (identity provider), directory synchronization, ThinApp synchronization, and View pool synchronization.

  • data-va

    This virtual appliance controls file storage and sharing service, stores users' files and folders, and synchronizes them across multiple devices. The data-va also hosts the end user web portal. We will cover the functionality of this appliance in Chapter 3, Horizon Files.

Users


For a test environment, select a mixed group of users and provide them with the necessary equipment such as a tablet or an extra phone during the test phase. To get a good understanding of the solution and how users will consume the services, it is important to expose a few users from different departments to the solution. Try to restrict the user groups to something that is manageable; we recommend at least five, but no more than 10 in the first phase. Once you move into production, Horizon Workspace will affect all of your users as it becomes the central place they log on to in order to access the tools, data, and applications to get their job done. This is likely to be a major change from how they work today.

Allow time and resources for user training and use your Pilot users as Horizon Workspace Champions. They can then manage the initial user issues.

Downloading the software


An easy way of finding the software is to browse the VMware's official portal at https://my.vmware.com.

Now, navigate to Downloads | All Products. From there, scroll down to Desktop & End-User Computing and find the VMware Horizon Workspace entry.

Simply click on View Download Components | Product Downloads | VMware Horizon Workspace | Go to Downloads. From there, find the VMware Horizon Workspace and click on Download Now.

Unless you are already logged in, you will be asked to provide your username and password for your My VMware account. If you do not have one, register a new account.

If you receive a message saying that you are not entitled to this download, it means that no licenses are registered to your account. If you have not purchased any licenses, you can request an evaluation license instead. To do this, perform the following steps:

  1. Click on Download Trial.

  2. Click on Register and complete the required information and then click on Continue.

Take a note of your license information and then proceed to the download.

Note

Since it's a big download, about 5.2 GB, please verify the MD5SUM or SHA1SUM once the download is complete with the one published on the download page. An incomplete/corrupt download could cause unpredictable problems later.

Summary


In this chapter, we have introduced you to Horizon Workspace and the major trends for end-user computing and the challenges associated with them.

We have also learned about the major components of VMware Horizon Workspace and the prerequisites and pieces you need to deploy the solution.

In the next chapter, we will cover the installation of the Horizon Workspace vApp and the configuration steps.

Left arrow icon Right arrow icon

Key benefits

What you will learn

What do you get with Print?

Product feature icon Instant access to your digital eBook copy whilst your Print order is Shipped
Product feature icon Black & white paperback book shipped to your address
Product feature icon Download this book in EPUB and PDF formats
Product feature icon Access this title in our online reader with advanced features
Product feature icon DRM FREE - Read whenever, wherever and however you want
Buy Now

Product Details


Publication date : Mar 20, 2014
Length 158 pages
Edition : 1st Edition
Language : English
ISBN-13 : 9781782172376
Vendor :
VMware

Table of Contents

16 Chapters
VMware Horizon Workspace Essentials Chevron down icon Chevron up icon
Credits Chevron down icon Chevron up icon
About the Authors Chevron down icon Chevron up icon
About the Reviewers Chevron down icon Chevron up icon
www.PacktPub.com Chevron down icon Chevron up icon
Preface Chevron down icon Chevron up icon
Getting Started with VMware Horizon Workspace Chevron down icon Chevron up icon
Design, Install, and Configure Chevron down icon Chevron up icon
Horizon Files Chevron down icon Chevron up icon
Integrating SaaS Applications Chevron down icon Chevron up icon
Mobile Management Chevron down icon Chevron up icon
Integrating ThinApp Packages Chevron down icon Chevron up icon
Horizon View Integration Chevron down icon Chevron up icon
Troubleshooting Chevron down icon Chevron up icon
Useful Links Chevron down icon Chevron up icon
Index Chevron down icon Chevron up icon

Customer reviews

Filter icon Filter
Top Reviews
Rating distribution
Empty star icon Empty star icon Empty star icon Empty star icon Empty star icon 0
(0 Ratings)
5 star 0%
4 star 0%
3 star 0%
2 star 0%
1 star 0%

Filter reviews by


No reviews found
Get free access to Packt library with over 7500+ books and video courses for 7 days!
Start Free Trial

FAQs

What is the delivery time and cost of print book? Chevron down icon Chevron up icon

Shipping Details

USA:

'

Economy: Delivery to most addresses in the US within 10-15 business days

Premium: Trackable Delivery to most addresses in the US within 3-8 business days

UK:

Economy: Delivery to most addresses in the U.K. within 7-9 business days.
Shipments are not trackable

Premium: Trackable delivery to most addresses in the U.K. within 3-4 business days!
Add one extra business day for deliveries to Northern Ireland and Scottish Highlands and islands

EU:

Premium: Trackable delivery to most EU destinations within 4-9 business days.

Australia:

Economy: Can deliver to P. O. Boxes and private residences.
Trackable service with delivery to addresses in Australia only.
Delivery time ranges from 7-9 business days for VIC and 8-10 business days for Interstate metro
Delivery time is up to 15 business days for remote areas of WA, NT & QLD.

Premium: Delivery to addresses in Australia only
Trackable delivery to most P. O. Boxes and private residences in Australia within 4-5 days based on the distance to a destination following dispatch.

India:

Premium: Delivery to most Indian addresses within 5-6 business days

Rest of the World:

Premium: Countries in the American continent: Trackable delivery to most countries within 4-7 business days

Asia:

Premium: Delivery to most Asian addresses within 5-9 business days

Disclaimer:
All orders received before 5 PM U.K time would start printing from the next business day. So the estimated delivery times start from the next day as well. Orders received after 5 PM U.K time (in our internal systems) on a business day or anytime on the weekend will begin printing the second to next business day. For example, an order placed at 11 AM today will begin printing tomorrow, whereas an order placed at 9 PM tonight will begin printing the day after tomorrow.


Unfortunately, due to several restrictions, we are unable to ship to the following countries:

  1. Afghanistan
  2. American Samoa
  3. Belarus
  4. Brunei Darussalam
  5. Central African Republic
  6. The Democratic Republic of Congo
  7. Eritrea
  8. Guinea-bissau
  9. Iran
  10. Lebanon
  11. Libiya Arab Jamahriya
  12. Somalia
  13. Sudan
  14. Russian Federation
  15. Syrian Arab Republic
  16. Ukraine
  17. Venezuela
What is custom duty/charge? Chevron down icon Chevron up icon

Customs duty are charges levied on goods when they cross international borders. It is a tax that is imposed on imported goods. These duties are charged by special authorities and bodies created by local governments and are meant to protect local industries, economies, and businesses.

Do I have to pay customs charges for the print book order? Chevron down icon Chevron up icon

The orders shipped to the countries that are listed under EU27 will not bear custom charges. They are paid by Packt as part of the order.

List of EU27 countries: www.gov.uk/eu-eea:

A custom duty or localized taxes may be applicable on the shipment and would be charged by the recipient country outside of the EU27 which should be paid by the customer and these duties are not included in the shipping charges been charged on the order.

How do I know my custom duty charges? Chevron down icon Chevron up icon

The amount of duty payable varies greatly depending on the imported goods, the country of origin and several other factors like the total invoice amount or dimensions like weight, and other such criteria applicable in your country.

For example:

  • If you live in Mexico, and the declared value of your ordered items is over $ 50, for you to receive a package, you will have to pay additional import tax of 19% which will be $ 9.50 to the courier service.
  • Whereas if you live in Turkey, and the declared value of your ordered items is over € 22, for you to receive a package, you will have to pay additional import tax of 18% which will be € 3.96 to the courier service.
How can I cancel my order? Chevron down icon Chevron up icon

Cancellation Policy for Published Printed Books:

You can cancel any order within 1 hour of placing the order. Simply contact customercare@packt.com with your order details or payment transaction id. If your order has already started the shipment process, we will do our best to stop it. However, if it is already on the way to you then when you receive it, you can contact us at customercare@packt.com using the returns and refund process.

Please understand that Packt Publishing cannot provide refunds or cancel any order except for the cases described in our Return Policy (i.e. Packt Publishing agrees to replace your printed book because it arrives damaged or material defect in book), Packt Publishing will not accept returns.

What is your returns and refunds policy? Chevron down icon Chevron up icon

Return Policy:

We want you to be happy with your purchase from Packtpub.com. We will not hassle you with returning print books to us. If the print book you receive from us is incorrect, damaged, doesn't work or is unacceptably late, please contact Customer Relations Team on customercare@packt.com with the order number and issue details as explained below:

  1. If you ordered (eBook, Video or Print Book) incorrectly or accidentally, please contact Customer Relations Team on customercare@packt.com within one hour of placing the order and we will replace/refund you the item cost.
  2. Sadly, if your eBook or Video file is faulty or a fault occurs during the eBook or Video being made available to you, i.e. during download then you should contact Customer Relations Team within 14 days of purchase on customercare@packt.com who will be able to resolve this issue for you.
  3. You will have a choice of replacement or refund of the problem items.(damaged, defective or incorrect)
  4. Once Customer Care Team confirms that you will be refunded, you should receive the refund within 10 to 12 working days.
  5. If you are only requesting a refund of one book from a multiple order, then we will refund you the appropriate single item.
  6. Where the items were shipped under a free shipping offer, there will be no shipping costs to refund.

On the off chance your printed book arrives damaged, with book material defect, contact our Customer Relation Team on customercare@packt.com within 14 days of receipt of the book with appropriate evidence of damage and we will work with you to secure a replacement copy, if necessary. Please note that each printed book you order from us is individually made by Packt's professional book-printing partner which is on a print-on-demand basis.

What tax is charged? Chevron down icon Chevron up icon

Currently, no tax is charged on the purchase of any print book (subject to change based on the laws and regulations). A localized VAT fee is charged only to our European and UK customers on eBooks, Video and subscriptions that they buy. GST is charged to Indian customers for eBooks and video purchases.

What payment methods can I use? Chevron down icon Chevron up icon

You can pay with the following card types:

  1. Visa Debit
  2. Visa Credit
  3. MasterCard
  4. PayPal
What is the delivery time and cost of print books? Chevron down icon Chevron up icon

Shipping Details

USA:

'

Economy: Delivery to most addresses in the US within 10-15 business days

Premium: Trackable Delivery to most addresses in the US within 3-8 business days

UK:

Economy: Delivery to most addresses in the U.K. within 7-9 business days.
Shipments are not trackable

Premium: Trackable delivery to most addresses in the U.K. within 3-4 business days!
Add one extra business day for deliveries to Northern Ireland and Scottish Highlands and islands

EU:

Premium: Trackable delivery to most EU destinations within 4-9 business days.

Australia:

Economy: Can deliver to P. O. Boxes and private residences.
Trackable service with delivery to addresses in Australia only.
Delivery time ranges from 7-9 business days for VIC and 8-10 business days for Interstate metro
Delivery time is up to 15 business days for remote areas of WA, NT & QLD.

Premium: Delivery to addresses in Australia only
Trackable delivery to most P. O. Boxes and private residences in Australia within 4-5 days based on the distance to a destination following dispatch.

India:

Premium: Delivery to most Indian addresses within 5-6 business days

Rest of the World:

Premium: Countries in the American continent: Trackable delivery to most countries within 4-7 business days

Asia:

Premium: Delivery to most Asian addresses within 5-9 business days

Disclaimer:
All orders received before 5 PM U.K time would start printing from the next business day. So the estimated delivery times start from the next day as well. Orders received after 5 PM U.K time (in our internal systems) on a business day or anytime on the weekend will begin printing the second to next business day. For example, an order placed at 11 AM today will begin printing tomorrow, whereas an order placed at 9 PM tonight will begin printing the day after tomorrow.


Unfortunately, due to several restrictions, we are unable to ship to the following countries:

  1. Afghanistan
  2. American Samoa
  3. Belarus
  4. Brunei Darussalam
  5. Central African Republic
  6. The Democratic Republic of Congo
  7. Eritrea
  8. Guinea-bissau
  9. Iran
  10. Lebanon
  11. Libiya Arab Jamahriya
  12. Somalia
  13. Sudan
  14. Russian Federation
  15. Syrian Arab Republic
  16. Ukraine
  17. Venezuela