The steps and diagram below depict a LoadMaster deployment with a VMware Horizon Workspace environment:

  1. After client traffic is passed through the LoadMaster to the appropriate Gateway-VA as detailed in the Load Balancing VMware Horizon Gateway-VAs section, the Gateway looks at the X-Forwarded-For header to determine which Connectors to use for authentication.
  2. The client request is then redirected to the appropriate Connector iDP URL. The LoadMaster hosting the Connector Virtual Service sends the response to the best suited Connector-VA.
  3. The Connector sends an HTTPS redirect to the client so that the client now connects directly to its FQDN.
  4. Using Kerberos, the Connector authenticates the client request against Active Directory.