Forum Discussion

scottmwa's avatar
scottmwa
Icon for Nimbostratus rankNimbostratus
Dec 12, 2017

Horizon Client 2FA using APM

Hello!

 

We are setting up 2FA for external users, but not internal users.

 

I have set up the iApp for VMWare Horizon and we've been working fairly well. External access is through the F5 directly to a pair of VMWare connection servers. You can either log into the APM webtop the iApp creates, or with the Horizon Client. I have successfully set up Duo's 2 factor authentication for the Webtop for external access. This just uses RADIUS.

 

However, this does not cover the Horizon client access from the internet. When attempting the same configuration to the client (APM - AD View Client section), the client fails because it doesn't understand the request.

 

When configuring RADIUS on the horizon server directly it will prompt 2FA for both internal and external users. The connection server does not pass any IP information to a RADIUS server to be able to have the RADIUS proxy identify trusted networks.

 

I'm a bit at a loss here. Has anyone run into this? If so, how did you fix it?

 

3 Replies

  • Still looking for a way to make this work for the Horizon thick Client through APM with RADIUS. I am using iApp version 1.5.3, and the RADIUS portion of the 2FA is working with the webtop, but not the client.

     

    Any help would be appreciated.

     

  • I have solved this issue by creating a separate Duo application, separate AAA server, and a different port for the Horizon Client. I did not configure VPE through the iApp, but created separate rules for it.

     

  • I have solved this issue by creating a separate Duo application, separate AAA server, and a different port for the Horizon Client. I did not configure VPE through the iApp, but created separate rules for it.