Horizon Client on a home PC must not talk directly to Connection Server on the internal VLAN. How should the access path be described?
Select an answer to reveal the explanation.
Short Explanation
Connection Server belongs inside, like the records room. Home Horizon Client should hit Unified Access Gateway in the DMZ, and the firewall should only allow that path. Do not hang the broker on the internet or aim Client at vCenter.
Full Explanation
Basic Horizon networking places Unified Access Gateway in the DMZ so external Horizon Client traffic does not land directly on Connection Server. Firewalls restrict inbound paths to that access tier. Publishing Connection Server to the internet, exposing App Volumes Manager, or pointing Client at vCenter violates that associate design.