Files
2026-04-18 10:12:10 -05:00

75 lines
3.3 KiB
Markdown

# Omnissa Horizon View — NSX Security Blueprint
Automates NSX tags, security groups, and Distributed Firewall (DFW) policy for an Omnissa Horizon View (formerly VMware Horizon) VDI deployment.
## Application Overview
Omnissa Horizon View provides virtual desktop and published application delivery. This blueprint segments the Horizon infrastructure and desktop pools using NSX micro-segmentation.
## Tiers & Tags
| Tag | Scope | Purpose |
|---|---|---|
| `Horizon\|ConnectionServer` | `AppName` | Horizon Connection Servers |
| `Horizon\|EnrollmentServer` | `AppName` | Enrollment/True SSO servers |
| `Horizon\|UAG` | `AppName` | Unified Access Gateways (external access) |
| `Horizon\|Composer` | `AppName` | Horizon Composer / Instant Clone domain join servers |
| `Horizon\|VDI` | `AppName` | Virtual desktop pool VMs |
| `Horizon\|RDSH` | `AppName` | Published application / RDSH session hosts |
| `Horizon\|Mgmt` | `AppName` | Horizon management / admin jump hosts |
## Security Groups
| Group | Membership Criteria | Purpose |
|---|---|---|
| `SG-Horizon-ConnectionServer` | Tag: `Horizon\|ConnectionServer` | Connection Server VMs |
| `SG-Horizon-EnrollmentServer` | Tag: `Horizon\|EnrollmentServer` | Enrollment Server VMs |
| `SG-Horizon-UAG` | Tag: `Horizon\|UAG` | Unified Access Gateway VMs |
| `SG-Horizon-Composer` | Tag: `Horizon\|Composer` | Composer / IC join VMs |
| `SG-Horizon-VDI` | Tag: `Horizon\|VDI` | Virtual desktop VMs |
| `SG-Horizon-RDSH` | Tag: `Horizon\|RDSH` | RDSH session host VMs |
| `SG-Horizon-Mgmt` | Tag: `Horizon\|Mgmt` | Management / admin VMs |
| `SG-Horizon-All` | All groups above | All Horizon workloads — used in lockdown rules |
## DFW Policy: `Policy-Horizon`
| # | Rule Name | Source | Destination | Service | Action |
|---|---|---|---|---|---|
| 1 | Allow-HTTPS-UAG | Any | SG-Horizon-UAG | HTTPS (443) | Allow |
| 2 | Allow-Blast-UAG | Any | SG-Horizon-UAG | Blast (8443, 443) | Allow |
| 3 | Allow-UAG-to-CS | SG-Horizon-UAG | SG-Horizon-ConnectionServer | HTTPS (443) | Allow |
| 4 | Allow-Client-to-CS | Any | SG-Horizon-ConnectionServer | HTTPS (443), Blast (8443) | Allow |
| 5 | Allow-CS-to-VDI | SG-Horizon-ConnectionServer | SG-Horizon-VDI | Blast (22443), PCoIP (4172) | Allow |
| 6 | Allow-CS-to-RDSH | SG-Horizon-ConnectionServer | SG-Horizon-RDSH | Blast (22443), RDP (3389) | Allow |
| 7 | Allow-SSH-Mgmt | SG-Horizon-Mgmt | SG-Horizon-All | SSH (22) | Allow |
| 8 | Allow-Enrollment-CS | SG-Horizon-ConnectionServer | SG-Horizon-EnrollmentServer | HTTPS (443) | Allow |
| 9 | Lockdown-Horizon | Any | SG-Horizon-All | Any | Deny |
> Rule 9 (Lockdown) has **Applied To** set to `SG-Horizon-All` to scope the deny to Horizon workloads only.
## Files
```
horizon_view/
├── README.md
├── deploy.py # Main entry point — orchestrates tags, groups, policy
├── tags.py # Tag creation logic
├── security_groups.py # Security group creation logic
└── policy.py # DFW policy and rule creation logic
```
## Usage
```bash
python horizon_view/deploy.py \
--nsx-manager <IP_OR_FQDN> \
--username <admin_user> \
--password <password>
```
### Optional flags
| Flag | Default | Description |
|---|---|---|
| `--dry-run` | False | Print planned changes without applying them |
| `--verify-ssl` | True | Disable with `--no-verify-ssl` for lab environments |