Applies To:
Show VersionsBIG-IP APM
- 13.1.5, 13.1.4, 13.1.3, 13.1.1
Using APM as a Proxy with Workspace One
Overview: Using APM as a proxy with Workspace One
This implementation describes how to set up Workspace One Cloud as an Identity Provider (IDP) in front of F5 Access Policy Manager (APM) as a Service Provider (SP) using APM as a gateway for VMware Horizon. The configuration creates the single pane of glass that Workspace One/Identity Manager provides with the DMZ security and scalability that F5 PCoIP/Blast Proxy brings with VMware Horizon.
About Workspace One Cloud
Workspace One and VMware Identity Manager combine applications and desktops into a single, aggregated workspace. Employees can then access the desktops and applications regardless of where they are based.
Workspace One Cloud deployment
Instead of being deployed on-premise within a datacenter, Workspace One Cloud is deployed in the cloud. Organizations can centralize assets, devices, and applications, and manage users and data securely. The system also gains access to upgrades in real-time preventing maintenance outages during upgrades.
Workspace One Cloud workflow
Together, VMware and F5 integrate additional layers of security and provide gateway access using Workspace One Cloud and Identity Manager.
About VMware Identity Manager on-premise
VMware Identity Manager combines applications and desktops in a single, aggregated workspace. Employees can then access the desktops and applications regardless of where they are based. With fewer management points and flexible access, Identity Manager reduces the complexity of IT administration.
VMware Identity Manager deployment
Identity Manager is delivered as a virtual appliance that is easy to deploy onsite and integrate with existing enterprise services or can be deployed on a Windows platform. Organizations can centralize assets, devices, and applications and manage users and data securely behind the firewall. Users can share and collaborate with external partners and customers securely when policy allows.
VMware Identity Manager workflow
F5 and VMware have developed an integration to add additional layers of security and provide gateway access with VMware Identity Manager.
Prerequisites for using Workspace One with APM
The following prerequisites must be completed before proceeding with the APM and Workspace One configuration. For additional information on BIG-IP system tasks, refer to the BIG-IP documentation on support.f5.com.
- Create and import an SSL certificate that contains the load-balanced FQDN to use for Identity Manager Portal. (VIDM deployments only)
- Upload the following to the BIG-IP system: (VIDM deployments
only).
- SSL certificate
- Private Key for the load-balanced FQDN certificate
- Primary CA or Root CA for the SSL certificate you
uploaded to the BIG-IP systemNote: The Primary or Root CA for the FQDN certificate is also uploaded to the BIG-IP system and must be loaded onto each Identity Manager appliance.
- Deploy and configure Workspace One and VMware Identity
Manager.
- For VMware Identity Manager, configure a (3-Node) behind a LTM FQDN VIP on the BIG-IP system and set up VIDM in the domain and Horizon environment.
- For Workspace One Cloud, set up the environment with connectors to the domain and Horizon environment.
- Set up and configure VMware Horizon behind an APM VIP on the BIG-IP system (the VIP can be deployed using the iAPP).
Although you can use wildcard certificates, due to wildcard certificate formats, SAN support is not typically available with wildcards from public CAs; public CAs may complain about supplying an internal FQDN as a SAN value even if they do support SAN values. Additionally, some VMware Identity Manager features may not be available with wildcard certificates when SAN support is not defined.
For additional details on VIDM LTM configuration, refer to the F5 integration guide Load Balancing VMware Identity Manager located at https://f5.com/Portals/1/PDF/Partners/f5-big-ip-vmware-workspaceone-integration-guide.pdf.
For additional details on Horizon APM configuration, refer to the F5 Deployment guide Deploying F5 with VMware View and Horizon View located at https://www.f5.com/pdf/deployment-guides/vmware-horizon-view-dg.pdf.
vIDM LTM configuration
Refer to the screen shots to confirm that the prerequisites for vIDM LTM configuration have been completed.
Virtual server list
Virtual server configuration
Virtual server resources
For additional details on vIDM LTM configuration, refer to the F5 integration guide Load Balancing VMware Identity Manager located at https://f5.com/Portals/1/PDF/Partners/f5-big-ip-vmware-workspaceone-integration-guide.pdf.
Horizon APM configuration
Refer to the screen shots to confirm that the prerequisites for Horizon APM configuration have been completed.
Application Service list
Virtual server list for Horizon
For additional details on Horizon APM configuration, refer to the F5 Deployment guide Deploying F5 with VMware View and Horizon View located at https://www.f5.com/pdf/deployment-guides/vmware-horizon-view-dg.pdf.
vIDM/WS1 configuration: Enabling JWT
Disabling strict updates on APM
Creating OAUTH Resources
Modifying the Horizon access policy
vIDM/WS1 configuration: Verifying JWT tokens
Troubleshooting Workspace One integration
If you see the following error or a similar one, check the DNS settings on your vIDM servers. Make sure they point to the LTM VIP not the APM VIP or you may receive an error.