Security-related server settings are accessible under Settings > Servers in the Horizon Console.

Table 1. Security-Related Server Settings
Setting Description
Use PCoIP Secure Gateway for PCoIP connections to machine

Determines whether Horizon Client makes a further secure connection to the connection broker host when users connect to VMware Horizon 8 desktops and applications with the PCoIP display protocol.

If this setting is deactivated, the desktop or application session is established directly between the client and the VMware Horizon 8 desktop or the Remote Desktop Services (RDS) host, bypassing the connection broker host.

This setting is deactivated by default.

Use Secure Tunnel connection to machine

Determines whether Horizon Client makes a further HTTPS connection to the connection broker host when users connect to an VMware Horizon 8 desktop or an application.

If this setting is deactivated, the desktop or application session is established directly between the client and the VMware Horizon 8 desktop or the Remote Desktop Services (RDS) host, bypassing the connection broker host.

This setting is activated by default.

Use Blast Secure Gateway for Blast connections to machine Determines whether clients that use a Web browser or the Blast Extreme display protocol to access desktops use Blast Secure Gateway to establish a secure tunnel to the connection broker.

If not activated, clients using a Blast Extreme session and Web browsers make direct connections to VMware Horizon 8 desktops, bypassing the connection broker.

This setting is deactivated by default.

For more information about these settings and their security implications, see the Horizon 8 Administration document.