Professional Documents
Culture Documents
Introduction To Vmware View Manager
Introduction To Vmware View Manager
You can find the most up-to-date technical documentation on the VMware Web site at: http://www.vmware.com/support/ The VMware Web site also provides the latest product updates. If you have comments about this documentation, submit your feedback to: docfeedback@vmware.com
2008 VMware, Inc. All rights reserved. Protected by one or more U.S. Patent Nos. 6,397,242, 6,496,847, 6,704,925, 6,711,672, 6,725,289, 6,735,601, 6,785,886, 6,789,156, 6,795,966, 6,880,022, 6,944,699, 6,961,806, 6,961,941, 7,069,413, 7,082,598, 7,089,377, 7,111,086, 7,111,145, 7,117,481, 7,149,843, 7,155,558, 7,222,221, 7,260,815, 7,260,820, 7,269,683, 7,275,136, 7,277,998, 7,277,999, 7,278,030, 7,281,102, 7,290,253, 7,356,679, 7,409,487, 7,412,492, 7,412,702, 7,424,710, 7,428,636, 7,433,951, 7,434,002, and 7,447,854; patents pending. VMware, the VMware boxes logo and design, Virtual SMP, and VMotion are registered trademarks or trademarks of VMware, Inc. in the United States and/or other jurisdictions. All other marks and names mentioned herein may be trademarks of their respective companies.
Contents
Contents
IntroductiontoVMwareViewManager
Features 6 VMwareViewOverview 7 ViewUserAuthentication 11 ViewExtendedUSBDeviceRedirection 13 ViewSecureAccess 14 ViewVirtualDesktopPoolManagement 14 ViewHighAvailabilityandScalability 16 ViewConnectionServerDMZDeployment 17 ViewConnectionServerComponents 20 ViewBroker 22 ViewSecureGatewayServer 22 ViewLDAP 23 ViewMessaging 24 ViewSecurityServer 24 DeploymentOptions 26 OfflineDesktop 26 LinkedClones 27 UnifiedAccess 28
Glossary
31
VMware, Inc.
VMware, Inc.
VMwareViewisanenterpriseclassvirtualdesktopmanagerthatsecurelyconnects authorizeduserstocentralizedvirtualdesktops.Itprovidesacomplete,endtoend solutionthatimprovescontrolandmanageabilityandprovidesafamiliardesktop experience. ThebenefitsofVMwareViewincludethefollowing: ControlandmanageabilityinasingleproductAdministratorscanmoreeasily provision,manage,andmaintaindesktopsbecausethedesktopsarerunninginthe datacenter. FamiliarenduserexperienceUsersgetflexibleaccesstoapersonalized,virtual desktopthatbehavesjustliketheirPCdesktops. VMwaredesktopintegrationViewextendsthebenefitsofvirtualizationtothe desktopbyleveragingthebackup,failover,anddisasterrecoverycapabilitiesof VMwareInfrastructure3. Lowertotalcostofownership(TCO)Byreducingadministrationandenergy costsandextendingtheusefullifeofPCs,VMwareViewManagerdeliverslower TCO.
VMware, Inc.
Features
ThefeaturesofVMwareViewincludethefollowing: EnterpriseclassconnectionbrokeringVMwareViewManagermanagesthe connectionsbetweenusersandtheirvirtualdesktops.WhenuserslogintoView Manager,thevirtualdesktopstheyareauthorizedtoaccessappears.After connectingtoavirtualdesktop,usersaccesstheirapplicationsasifthe applicationsarerunninglocally. USBclientdevicesupportUSBdevicescanbelocallyconnectedtoclientsand accessedthroughavirtualdesktop. WebbasedmanagementuserinterfaceAWebbasedmanagementconsole allowsvirtualdesktopstobemanagedfromanylocation. SmartpoolingcapabilitiesArangeofpersistentandnonpersistentpooling capabilitiessimplifiestheprovisioningandmanagementofcentralizeddesktops. SecureaccessOptionalsecureencapsulationcapabilitiesallowallnetwork connectionstobeencrypted. IntegrationwithMicrosoftActiveDirectoryConnectiontoActiveDirectory, whichallowsyoutolocateuserandusergroupaccountsandusethe authenticationfeaturesinActiveDirectorytocontrolwhichuserscanaccess virtualdesktops. SupportfortwofactorauthenticationWithRSASecurID,accesscontrolis strengthened. SeamlessintegrationwithVMwareVirtualInfrastructure3Workscloselywith VMwareVirtualCentertoprovideadvancedvirtualdesktopmanagement capabilities,suchasautomaticsuspendandresume,whichreducesthememory andprocessingpowerrequiredtohostvirtualdesktops.Byleveragingthe capabilitiesofVMwareVirtualInfrastructure3,desktopscanrunevenwhen serverhardwarefailsandrecoverquicklyfromunplannedoutageswithout duplicatehardware. FlexibledeploymentoptionsCriticalcomponentscanbedeployedinavariety ofconfigurationsandtodifferentpartsofthenetwork,whichimprovesecurity, scalability,andreliability.MultipleVirtualCenterserversaresupported,and VMwareViewcanscaletosupportmanyvirtualdesktops. HighavailabilityServerscanbeclusteredforhighavailabilityandscalability withautomaticfailover.Theseserverscanalsoleverageindustrystandard loadbalancingsolutions.
VMware, Inc.
VMwareViewComposerDramaticallyreducestheamountofstorage consumed.Imagescanbeprovisionedinafewsecondsandinafullyautomated mannerbyViewManagerforrapidrolloutsorasanimmediateresponseto everydaysupportissues. SupportfornonVIsystemsphysicalmachinesorterminalservicessystemscan bealsomanagedbyViewManager,ensuringaseamlessintegrationofexisting architecturesintotheViewenvironment. Scalablevirtualinfrastructurelinkedclonetechnologyallowsmultipledesktops tobedeployedfromasinglebaseimage.Subsequentchangestothisimagecanbe automaticallyproliferatedamongstalldesktopsinlinkedclonepool. SimplifiedPrintingEnablesViewClientandViewPortaluserstoprintusing anyprinterconfiguredforusebytheViewClientorViewPortalhost.
VMware, Inc.
network network
virtual desktops VM desktop OS app app app VM VM ESX host View Agent virtual machine VM VM VM ESX hosts running Virtual Desktop VMs
VMware, Inc.
View Connection Server Thiscomponentistheconnectionbrokerthatmanagessecureaccesstovirtualdesktops andworkswithVirtualCentertoprovideadvancedmanagementcapabilities.Itisinstalled onaMicrosoftWindowsServer2003serverthatispartofanActiveDirectorydomain. ViewConnectionServerisinstalledasoneofthefollowinginstances: StandardThisinstanceappearsinFigure 1.Itprovidesstandalonefunctionality andisusedastheonlyViewConnectionServer(orthefirstofagroupofView ConnectionServersthatactaspartofahighavailability,fullyreplicatedgroup). ReplicaThisinstanceisinstalledasasecondorsubsequentViewConnection Serverinahighavailabilitygroup.Configurationdataisinitializedfroman existingViewConnectionServerserverandisautomaticallyreplicatedbetween Viewgroupmembers. SecurityServerThisinstanceimplementsasubsetoftheViewConnectionServer functionalityandisusedinademilitarizedzone(DMZ)deployment.AView SecurityServerdoesnotneedtobeinanActiveDirectorydomain.TheStandard andReplicainstancesautomaticallyincludetheSecurityServerfunctionality. TheinstancetypeisselectedduringViewConnectionServerinstallation. HighavailabilityandDMZdeploymentsofViewConnectionServerusingReplicaand SecurityServerinstancesaredescribedinViewConnectionServerDMZDeployment. ConfigurationdataisstoredinanembeddedLDAPdirectoryoneachStandardand Replicainstance. View Agent Thiscomponentrunsoneachvirtualdesktopandisusedforsessionmanagementand singlesignon.WithViewClient,thiscomponentsupportsoptionalUSBdevice redirection.Thisagentcanbeinstalledonavirtualmachinetemplatesothatvirtual desktopscreatedfromthattemplateautomaticallyincludetheViewAgent. PlacevirtualdesktopsinanActiveDirectorydomainthatisoneofthefollowing: ThesamedomaintowhichtheViewConnectionServersarejoined AdomainwithatrustagreementwiththeViewConnectionServerdomain Whenusersconnecttotheirvirtualdesktops,theyareautomaticallyloggedinusing thesamecredentialstheyusetologintotheirdomain.Thesinglesignoncapabilitycan bedisabledinViewAgentwhichmeandthatusersarealwaysrequiredtologontothe virtualdesktopmanually.Ifthevirtualdesktopisnotpartofadomainorispartofa domainwithwhichnotrustagreementexists,singlesignonisnotavailable,andthe usermustmanuallylogintothevirtualdesktop.
VMware, Inc. 9
View Client ThiscomponentrunsonaWindowsPCasanativeWindowsapplicationandallows userstoconnecttotheirvirtualdesktopsthroughView.Thiscomponentconnectstoa ViewConnectionServerandallowstheusertologonusinganyofthesupported authenticationmechanisms.Afterloggingin,userscanselectfromthelistofvirtual desktopsforwhichtheyareauthorized.Thisstepprovidesremoteaccesstotheir virtualdesktopandprovidesuserswithafamiliardesktopexperience. ViewClientalsoworkscloselywithViewAgenttoprovideenhancedUSBsupport. BasicUSBsupport(suchasUSBdrivesandUSBprinters)issupportedwithoutView USBsupport,butViewextendsthissupporttoincludeadditionalUSBdevices.Youcan specifyViewUSBsupportinViewClientduringtheinstallation. View Client with Offline Desktop OfflineDesktopoffersmobileuserstheabilitytocheckoutaclonedinstanceofcertain typesofViewManagerdesktopontoalocalsystemsuchasalaptop.Oncecheckedout, thelocalcopybehaveslikeastandalonedesktopsystemandcanbeusedwithor withoutanetworkconnection;thedesktopisnowconsideredtobeoffline. Oncedownloaded,Offlinedesktopsbehaveinthesamewayastheironlineequivalents yetcantakeadvantageoflocalresources;latencyisminimizedandperformanceis enhanced.Thepresenceofadownloadedvirtualmachinehasnoeffectontheexisting operatingsystemoftheclientsystem,whichuserscancontinuetoutilizeiftheywish. View Portal ThiscomponentissimilartoViewClientbutprovidesaViewuserinterfacethrougha Webbrowser.ViewPortalisincludedautomaticallyduringtheViewConnection Serverinstallation.ViewPortalissupportedonLinuxandMacOS/X,butthisWeb accessdoesnotsupportViewUSBextensions.AllnecessaryViewsoftwareisinstalled automaticallyontheclientthroughtheWebbrowser.ViewPortalonLinuxuses rdesktopandonMacOS/XusesMicrosoftRemoteDesktopConnectionClientforMac. ViewPortalcanalsobeusedonaWindowsclientwithViewClient.Auserobtainsthe requiredsoftwareontheirclientdevicebyaccessingaViewConnectionServerwitha Webbrowser.IftheViewClientsoftwareisinstalledwithUSBsupportbyauserwith administrativerights,ViewPortalonWindowshascompleteViewUSBsupport. View Administrator ThiscomponentprovidesViewadministrationthroughaWebbrowser.Itisusedby Viewadministratorstodothefollowing: Makeconfigurationsettings ManagevirtualdesktopsandentitlementsofdesktopsofWindowsusersandgroups
10 VMware, Inc.
ViewAdministratoralsoprovidesaninterfacetomonitorlogeventsandisinstalled withViewConnectionServer.MoreinformationabouttheViewConnectionServer componentsandtheirrelationshipwithotherViewcomponents,seeViewConnection ServerComponents. View Composer ViewComposerisusedbyViewtocreateanddeploylinkedclonedesktopsfrom VirtualCenter.ThelinkedclonefeatureenablesViewadministratorstorapidlyclone anddeploymultipledesktopsfromasinglecentralizedbaseimage,calledaParentVM. Oncethedesktopshavebeencreatedtheyremainindirectlylinkedtoasnapshot residingontheParentVM. Thelinkisindirectbecausethefirsttimeoneormoredesktopclonesarecreated,a uniquelyidentifiedcopyoftheParentVMcalledareplicaisalsocreated.Allthe desktopclonesareanchoreddirectlytothereplicaandnottotheParentVM.
VMware, Inc.
11
network
View Administrator
Microsoft Active Directory ESX hosts running Virtual Desktop virtual machines
12
VMware, Inc.
VMware, Inc.
13
NonpersistentdesktoppoolSimilartoapersistentdesktoppool,exceptinthis casethevirtualdesktopsarenotpermanentlyassignedtousers.Whenasessionis finished,thevirtualdesktopisreturnedtothepoolandmadeavailableforother users. Bydeletingthevirtualdesktopsaftereachuse,thistypeofpoolensuresthateach userreceivesanewlyprovisionedvirtualdesktopeachtimetheuserconnects (optional).Usethistypeofpoolwhereacleanmachineisneededforeachuser sessionorinhighlycontrolledenvironmentsthathasnorequirementfor customizationtobestoredonthevirtualdesktop. Thetwopooldesktopsaresizedusingthefollowingparameters: MinimumTheminimumnumberofvirtualdesktopstobecreatedwhenthepool isfirstcreated.Thepoolmanagercontinuestocreatevirtualdesktopsuntilthis minimumcountisreached.Thisprocessensuresthatapoolisappropriatelysized whenauserpopulationismovedtoView. MaximumThemaximumnumberofvirtualdesktopsthatcanexistinthepool. Usethisparametertolimitthenumberofvirtualdesktopsinthepooltoavoid overusingavailableresources. AvailableThenumberofvirtualdesktopsthatareavailableforimmediateuse. Forpersistentpools,thisparameterrelatesonlytotheunassignedvirtual desktops.Thisisusedtoensurethatthepoolmanagercreatesenoughvirtual desktopsinadvancetocopewithdemand.Useahighernumberformorevolatile environments. Whenapoolcontainstoofewvirtualdesktops,themanagerprovisionsnewvirtual desktopsfromadesignatedtemplate.Thesevirtualdesktopscanalsobeautomatically customized(forexample,namedandbecomepartofanActiveDirectorydomain)orbe leftforanadministratortomanuallyconfigure. PowermanagementisappliedtoallvirtualdesktopsunderViewcontrol,andthe followingpoliciesaresupported: Donothing(VMremainson)VMsthatarepoweredoffwillbestartedwhen requiredandwillremainon,evenwhennotinuse,untiltheyareshutdown. EnsureVMisalwayspoweredonAllVMsinthepoolremainpoweredon,even whentheyarenotinuse.Iftheyareshutdown,theywillimmediatelyrestart. SuspendAllVMsinthepoolenterasuspendedstatewhennotinuse. PoweroffAllVMsinthepoolshutdownwhennotinuse..
VMware, Inc.
15
network
load balancing
Microsoft Active Directory ESX hosts running Virtual Desktop virtual machines
VMware, Inc.
17
ViewConnectionServerfunctionalityissplitbetweenserversinthesecurenetwork andtheDMZ.ViewConnectionServersthatoperateinaDMZareknownasView SecurityServersandareinstalledusingtheViewConnectionServerinstallerand specifyingaSecurityServerinstancetype.ViewSecurityServersintheDMZoperate withViewConnectionServers(StandardorReplica)inthesecurenetwork. Figure 4showsahighavailabilityenvironmentcomprisingtwoloadbalancedView SecurityServersintheDMZworkingwithtwofullViewConnectionServers(Standard andReplicainstance)inthesecurenetwork. Figure 4. DMZ Deployment with Multiple View Connection Servers
remote View Client
external network
Microsoft Active Directory ESX hosts running Virtual Desktop virtual machines
18
VMware, Inc.
ViewSecurityServersdonotcontainanLDAPconfigurationrepositoryanddonot accessanyauthenticationrepositories(ActiveDirectoryorRSAAuthentication Manager).WhenremoteusersconnectusingaViewSecurityServer,theymust successfullyauthenticatebeforeasecureconnectionisestablished.Thismeansthey cannotattempttoaccessanyvirtualdesktopsuntiltheyaresuccessfullyauthenticated. WithappropriatefirewallrulesonbothsidesoftheDMZ,thistypeofdeploymentis suitableforaccessingvirtualdesktopsfromInternetlocatedclientdevices. TosupportremoteViewClientandViewPortalconnectingtotheenvironmentusing HTTPSfromanexternalnetwork,theonlyTCPportthatmustbeallowedintheDMZ istheHTTPSport(TCPport443).ViewSecurityServersdonotneedtobepartofan ActiveDirectorydomain,andnocommunicationoccursbetweenViewSecurity ServersandActiveDirectory. AlthoughFigure 4showsaonetoonerelationshipbetweenViewSecurityServersand ViewConnectionServers,multipleViewSecurityServerscanbeconnectedtoeach ViewConnectionServer.ADMZdeploymentcanbecombinedwithastandard deploymenttoofferViewaccessforinternalusersandexternalusers. Figure 5showsamorecomplexenvironmentwherefourViewConnectionServersact asonegroupwiththeserversintheinternalnetworkdedicatedtotheusersofthat network,andtheserversintheexternalnetworkdedicatedtousersofthatnetwork. TheserversontherightcanbeenabledforRSASecurIDauthentication,sothatall externalnetworkusersarerequiredtoauthenticateusingRSASecurIDtokens.
VMware, Inc.
19
external network
View Client
internal network
load balancing
Microsoft Active Directory ESX hosts running Virtual Desktop virtual machines
20
VMware, Inc.
browser thin client operating system RDP Client View Client RDP Client View Secure GW Client
HTTP(S)
HTTP(S)
RDP
RDP
SOAP
View Agent
Virtual Desktop VM
VMware, Inc.
21
View Broker
TheViewConnectionBrokeristhecoreofViewConnectionServer.Itisresponsiblefor alluserinteractionbetweentheclient(ViewClient,ViewPortal,andThinClient)and theViewConnectionServer. ViewBrokerprovidesthefollowing: Userauthentication UserdesktopentitlementswithViewLDAP Virtualdesktopsessionmanagement Coordinationofthesecureconnectionestablishment,virtualdesktop connection,andsinglesignon AdministrationserverusedbyViewAdministratorWebclient Virtualdesktoppoolmanagement ViewBrokeroperatescloselywithVirtualCentertoprovideadvancedmanagementof virtualdesktops.Thisincludesvirtualdesktopcreationaspartofpoolmanagement andpoweroperations,suchasautomaticsuspendandresume.
22
VMware, Inc.
View LDAP
ViewLDAPisanembeddedLDAPdirectoryoneachViewConnectionServerStandard andReplicainstances.ItisusedastheconfigurationrepositoryforallView configurationdata.ViewLDAPforWindowsServer2003usesMicrosoftActive DirectoryApplicationMode(ADAM).ThisisanembeddedLDAPdirectorybundled withView.ItinstallsthefollowingcomponentsthatareappropriateforView: SpecificViewschemadefinitions Directoryinformationtree(DIT)definitions Accesscontrollists(ACLs) ViewLDAPalsoincludesasetofViewpluginDLLstoprovideautomationand notificationservicesforotherViewcomponents. ViewLDAPcontainsentriestorepresentthefollowingconfigurationitems: VirtualdesktopentriesthatrepresenteachaccessiblevirtualdesktopThis containsreferencestoForeignSecurityPrincipalentriesofWindowsusersand WindowsusergroupsinActiveDirectorywhoareauthorizedtousethisdesktop. VirtualDesktopPoolentriesthatrepresentmultiplevirtualdesktopsmanaged together Virtualmachineentriesthatrepresenteachvirtualdesktop Viewcomponentconfigurationentriesusedtostoreconfigurationsettings WhenaStandardinstanceisinstalledduringViewConnectionServerinstallation,a new,localstandaloneADAMinstanceiscreated.Theschemadefinitions,DIT definition,ACLs,andsoonareloadedandinitialdataisadded.Configurationdatain ViewLDAPismainlymaintainedfromViewAdministrator,althoughViewBrokeralso managessomepartsautomatically.
VMware, Inc.
23
View Messaging
ThiscomponentprovidesthemessagingrouterforcommunicationbetweenView ConnectionServercomponentsandbetweenViewAgentandViewConnectionServer. ItsupportstheJavaMessageService(JMS)API,whichisusedformessaginginView.
24
VMware, Inc.
browser thin client operating system RDP Client View Client RDP Client View Secure GW Client
HTTP(S)
HTTP(S)
RDP
View Agent
Virtual Desktop VM
FormoreinformationaboutViewdeploymentwithinaDMZ,seeViewConnection ServerDMZDeployment.
VMware, Inc.
25
Deployment Options
VMwareViewoffersseveraldeploymentoptions. OfflineDesktop ViewComposer UnifiedAccess
Offline Desktop
OfflineDesktopoffersmobileuserstheabilitytocheckoutaclonedinstanceofcertain typesofViewdesktopontoalocalsystemsuchasalaptop.Oncecheckedout,thelocal copybehaveslikeastandalonedesktopsystemandcanbeusedwithorwithouta networkconnection;thedesktopisnowconsideredtobeoffline. Oncedownloaded,Offlinedesktopsbehaveinthesamewayastheironlineequivalents yetcantakeadvantageoflocalresources;latencyisminimizedandperformanceis enhanced.Thepresenceofadownloadedvirtualmachinehasnoeffectontheexisting operatingsystemoftheclientsystem,whichuserscancontinuetoutilizeiftheywish. AconsistentuserexperienceisensuredthroughuseoftheViewClientapplicationfor bothonlineandofflinesessions.Inaddition,userscandisconnectfromtheiroffline desktopandthenloginagainwithoutconnectingtotheViewConnectionServer. Oncenetworkaccessisrestored(orwhentheuserisready)thecheckedoutVMcanbe: Backeduptheonlinesystemisupdatedwithallnewdataandconfigurations, buttheofflinedesktopremainscheckedoutonthelocalsystemandtheonlinelock remainsinplace. Rolledbacktheofflinedesktopisdiscardedandtheonlinelockisreleased. Futureclientconnectionswillbedirectedtotheonlinesystemuntilthedesktopis checkedoutagain Checkedintheofflinedesktopisuploadedtotheonlinehostandtheonlinelock released.Futureclientconnectionswillbedirectedtotheonlinesystemuntilthe desktopischeckedoutagain. Theabilityofuserstodownloadanonlinedesktopforuseontheirlocalsystemis conferredthroughViewentitlementandOfflineVDIaccesspolicy.Whileadesktopis checkedout,Viewadministratorsarestillabletoaccesstheonlinesystemwhile monitoringtheofflineequivalent
26
VMware, Inc.
Linked Clones
TheLinkedClonefeatureenablesViewadministratorstocloneanddeploymultiple desktopsfromasinglecentralizedbaseimage,calledaMasterVM.Oncethedesktops havebeencreatedtheyremainindirectlylinkedtoasnapshotresidingonthismaster image. Thelinkisindirectbecausethefirsttimeoneormoredesktopclonesarecreated,a uniquelyidentifiedcopyoftheMasterVMcalledareplicaisalsocreated.Allthe desktopclonesareanchoreddirectlytothereplicaandnottotheMasterVM. TheMasterVMcanbeupdatedorreplacedwithoutdirectlyaffectingtheanchored clonesandcanthereforecanbeviewedasastandaloneVM.Thissetofrelationshipsis illustratedinFigure 8. Figure 8. Master VM, Linked Replica, and Desktop Clones
parent VM can be on a different datastore base image + snapshot
clone 1 replica
clone 2
OS data disk
OS data disk
VMware, Inc.
27
Viewadministratorscansimultaneouslyupdate(orchange)theoperatingsystemsof alldesktops,installorupdateclientapplications,ormodifythedesktophardware settingsbycarryingouttheseactivitiesontheMasterVMandthenanchoringthe desktopclonestoanewsnapshotofthisconfiguration.Thisactioniscalleddesktop recomposition. NOTEDesktopclonescanalsobeanchoredtoacompletelydifferentMasterVM. AdministratorscanalsoreturntheOSdataofeachdesktop,whichmayhaveexpanded throughongoingusage,toitsoriginalstate(thatoftheMasterVM)bycarryingoutan actioncalleddesktoprefresh. TheadministrativeinterfaceprovidedbyViewdeliversahighleveloverviewofwhat actionsarebeingcarriedout.Policiescancontrolwhatactionsareexecutedandatwhat timeinordertominimizedisruptiontotheuserbase.Connecteduserscanbenotified withcustommessagesifanupdatethatwillaffecttheirsessionisabouttotakeplace.
Unified Access
LargeenterprisesuseamixofphysicalPCs,serverbaseddesktopsorapplicationsthat arepublishedusingterminalservices;virtualdesktops;andbladePCs.Usersrequiring accesstomorethanoneplatformmustuseseveraldifferentinterfaces.UnifiedAccess enablesViewtoprovideaunifiedinterfacethroughwhichuserscanaccesstheir desktopsbeingdeliveredbymultiplebackends. Thedesktopdeploymentparadigminlargeenterprisesisamixofvariousbackend platforms.Viewsupportforbackendplatformshasbeenlimitedtovirtualmachines managedbytheVCserver.UnifiedAccessenablesViewtodeliverandmanagevirtual machinesthatarenotmanagedbytheVCserver. Thetermdesktopsourcereferstoanindividualdesktopresourceprovidedtopool users.Thiscanbeaprovisionedornonprovisionedvirtualmachine,aterminalserver sessionoraphysicalcomputer. UnifiedAccesssupportsdifferentdesktopdeliverymodelswhichcharacterizetheway adesktopiscreated,entitled,delivered,andused.Thedesktopdeliverymodels supportedbyVieware: IndividualDesktopadesktopthatallowsasingle,preexistingbackendsource andcanbeentitledtomanyusersorgroups. ManualPoolamanuallyprovisionedpoolofdesktopsourcesthatallows multipleuserstobemappedtomultipledesktops.
28
VMware, Inc.
VMware, Inc.
29
30
VMware, Inc.
Glossary
A
ActiveDirectory AMicrosoftdirectoryservicethatstoresinformationaboutthenetworkoperating systemandprovidesservices.ActiveDirectoryconfiguresandmanagesusersand groupsandenablesadministratorstosetsecuritypolicies,controlresources,and deployprogramsacrossanenterprise. ADAM(ActiveDirectoryApplicationMode) AnLDAPimplementationbasedonActiveDirectory. activesession AliveconnectionfromaclientorViewPortalusertoavirtualdesktop.An establishedconnectiontoavirtualdesktopthathasnottimedout. administratoruserinterface TheWebbasedadministratoruserinterfaceusedtoperformconfigurationand managementtasksinView.AlsoknownastheViewAdministrator. agent SeeVMwareViewAgent.
VMware, Inc.
31
desktop Seevirtualdesktop. desktopvirtualmachine Seevirtualdesktop. desktoppool Apoolofvirtualmachinesthatanadministratordesignatesforusersorgroupsof users.Seealsopersistentdesktoppool,nonpersistentdesktoppool. DMZ(demilitarizedzone) Alogicalorphysicalsubnetworkthatconnectsinternalserverstoalarger, untrustednetwork(usuallytheInternet)andprovidesanadditionallayerof securityandgivesadministratorsmorecontroloverwhocanaccessnetwork resources. DNS(DomainNameSystem) AnInternetdataqueryservicethattranslateshostnamesintoIPaddresses.Also calledDomainNameServerorDomainNameService.
32
VMware, Inc.
Glossary
highavailability Asystemdesignapproachthatensuresadegreeofoperationalcontinuity. loadbalancing Atechniqueusedfordistributingprocessesacrossserverssothatthetrafficloadis spreadmoreevenlyandserversdonotbecomeoverloaded. nonpersistentdesktoppool Adesktoppoolinwhichusersarenotassignedtoaspecificdesktop.Whenusers logofforaretimedoutofadesktop,theirdesktopsarereturnedtothepooland madeavailabletootherusers.Usersshouldnotsavedataorfilestotheirdesktops whenusinganonpersistentpool. persistentdesktoppool Adesktoppoolinwhichusersareassignedtoaspecificdesktop.Userslogonto thesamedesktopeverytimeandtheirdataispreservedwhentheylogoff.Users cansavedataandfilestotheirdesktopswhenusingapersistentpool. RDP(remotedesktopprotocol) Amultichannelprotocolthatallowsausertoconnecttoacomputerremotely. RSASecurID AproductfromRSAthatprovidesstrongtwofactorauthenticationusinga passwordandanauthenticator.
securityserver AViewConnectionServerdeploymentthataddsalayerofsecuritybetweenthe Internetandtheinternalnetwork.SecurityServerisanoptionthatyouchoose duringViewconnectionserverinstallation.SeealsoDMZ(demilitarizedzone). thinclient Adevicethatallowsausertoaccessvirtualdesktopsbutrequireslittlememoryor diskdrivespace.Applicationsoftware,data,andCPUpowerresidesonanetwork computerandnotontheclientdevice. VMwareViewAgent Installedontheguest,theViewAgentenablescommunicationbetweenthe desktopvirtualmachine,theViewConnectionServer,andenduserswhoaccess virtualdesktopsbyusingViewViewPortalorViewClients.
VMware, Inc.
33
VMwareViewClient AWindowsbasedapplicationusedforaccessingvirtualdesktops. VMwareViewConnectionServer Aconnectionbrokerthatprovidesmanagementanduserauthenticationforvirtual desktops.TheViewConnectionServerdirectsincomingremotedesktopuser requeststotheappropriatevirtualdesktop. VMwareViewPortal Webbrowserbasedapplicationforaccessingvirtualdesktops.Enduserswhorun supportedWindows,Linux,orMacintoshoperatingsystemscanaccessvirtual desktopsbyusingViewPortal. virtualdesktop Adesktopoperatingsystemthatrunsonavirtualmachine.Avirtualdesktopis indistinguishablefromanyothercomputerrunningthesameoperatingsystem. VMwareVirtualDesktopInfrastructure TheVMwaredesktopinfrastructuresolutionthatconsistsofVMwareESXServer, VMwareVirtualCenter,andVMwareVirtualDesktopManager.VDIprovidesan endtoendvirtualdesktopsolutionthatallowsadministratorstoeasilydeploy andmanagevirtualdesktopenvironments.
34
VMware, Inc.