It is important to understand what your responsibilities include and which are shared between your teams and the VMware team. Deploying Horizon Cloud Service on IBM Cloud can be divided into several basic areas of responsibility, as shown in the table below.

Phase Areas of Responsibility
Project Kickoff Your SMEs with VMware:
  • Meet (your lead and VMware lead)
  • Include desktop manager, desktop engineering, security, and network SMEs in your team
  • Review and discuss provisioning requirements
  • Collect information using the Horizon Cloud setup web form
  • Establish success criteria via the VMware-supplied template
  • Plan next steps
Capacity Order VMware:
  • Orders tenant capacity from data center infrastructure
  • Configures capacity for Horizon Cloud Service on IBM Cloud
Network Setup VMware:
  • Establishes VPN and Direct Connect configurations and access
  • Configures DHCP, DNS, VPN, and Direct Connect
Your SMEs:
  • Configure DHCP, Active Directory, and DNS
  • Provide SSL certificates
  • Provide VPN and Direct Connect information
Tenant Setup VMware:
  • Sets up Horizon Cloud Service on IBM Cloud
  • Configures storage
  • Sets up the Unified Access Gateway
  • Installs tenant appliances
  • Sets standard desktop capacity
Network Interconnect VMware:
  • Installs SSL certificates
Your SMEs with VMware:
  • Test and validate connectivity
  • Provides Horizon Cloud Service Administration Console URL
  • Provides starter image templates
Your SMEs:
  • Perform Active Directory registration
  • Perform post-test (optional) and install your apps
Final Setup and Test Your SMEs:
  • Install applications into VMware-supplied starter image templates
  • Imports and moves starter image templates to tenant
Your SMEs:
  • Create images
  • Create assignments
  • Assign test desktops and validate
  • Conducts knowledge transfer
  • Establishes support
Complete Your SMEs with VMware:
  • Agree that setup is complete
  • VMware provides advanced onboarding services (optional)
  • Verify that all success criteria are met

Your Responsibilities

Ensure that all required internal and external network traffic ports for the protocols are enabled (see Prerequisites for Firewall and Ports). You are also responsible for your organization’s side of the IPsec VPN tunnel, if you choose to deploy in that configuration. If you deploy a dedicated connection, MPLS, or Network Exchange, you are responsible for working with your preferred carrier or telecommunications provider to establish connectivity to the VMware data center.

VMware Responsibilities

Depending on the network connection option you select, VMware provides you with the information you need for success.

  • IPsec VPN – VMware provides the information required to establish the IPsec tunnel and is responsible for the VMware side of the VPN IPsec tunnel configuration.
  • Dedicated connection, MPLS, Network Exchange, or an existing rack – VMware configures the interconnect between the Network Service Provider and your networking equipment and your Horizon Cloud Service tenant in the VMware data center. You must purchase the Direct Connect with Cross Connect option or Direct Connect with Network Exchange option from VMware. For all connectivity types, VMware works with you to perform the necessary network tests to ensure a successful connection.
  • Island tenant – If you deploy an island tenant without integration between VMware and your infrastructure, VMware provides a utility server to use as an Active Directory, DNS, and DHCP server. To function properly, cloud-hosted desktops require that an Active Directory Domain controller and supporting services be deployed in the tenant.