On-Premises Virtual Desktops with Remote Management
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Service providers face security and regulatory issues, as well as latency and connectivity problems, when hosting virtual desktops outside an enterprise's private network, due to untrusted service provider networks and significant data transfer loads between virtual desktops and enterprise resources.
Innovation Solution
Virtual desktops are hosted on remote desktop hosts within an enterprise's private network, behind a firewall, with remote management through a service provider network, using a resource management appliance and tenant appliance for centralized management, and optionally extending the service provider network into the enterprise via a dedicated router and switch, or using a DMZ gateway for proxy connections.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If virtual desktops are hosted at a service provider outside the enterprise's private network, then service providers can provide remote desktop access to end users, but security and regulatory issues arise due to untrusted service provider networks
Solution Approach 1:
A network gateway is introduced as an intermediary component deployed within the enterprise network. This gateway acts as a trusted mediator that receives requests from external service providers and forwards them to internal resources, eliminating the need for external hosts while maintaining security boundaries. The gateway translates external access requests into internal network operations without exposing the enterprise network to external threats.
Solution Approach 2:
Instead of bringing the service provider's hosting capability into the enterprise network (external to internal), the solution inverts the approach by bringing the service provider's management interface to the enterprise network through the gateway. The virtual desktop infrastructure remains internal, but the service provider can manage it remotely through the gateway, reversing the traditional hosting model while maintaining security.
2Extent of automation
If virtual desktops are hosted at a service provider outside the enterprise's private network, then remote desktop management is enabled, but latency and connectivity issues occur due to additional network hops
Solution Approach 1:
The network gateway serves as a local intermediary that eliminates the need for external network hops. By deploying the gateway within the enterprise network, all management traffic between the service provider and virtual desktops flows through this local intermediary, reducing latency caused by external network connections while maintaining centralized management capabilities.
Solution Approach 2:
The solution adds a spatial dimension by deploying the network gateway physically within the enterprise network infrastructure. This dimensional change transforms the network topology from external-hosting to internal-gateway-architecture, placing the management interface closer to the resources and eliminating the external network hop that causes latency.
3Adaptability or versatility
If virtual desktops are hosted at a service provider outside the enterprise's private network, then service providers can provision and manage virtual desktops remotely, but significant data transfer loads exist between virtual desktops and enterprise resources
Solution Approach 1:
The network gateway acts as a data transfer intermediary that localizes all communication between virtual desktops and enterprise resources. By positioning the gateway within the enterprise network, data traffic flows through local infrastructure rather than external networks, eliminating unnecessary data transfer loads while preserving remote provisioning and management capabilities through the gateway interface.
Data Source
AI summary
Virtual desktops are hosted on one or more remote desktop hosts at one or more private locations of an enterprise, remote from a service provider location, and behind a firewall on a private computer network. The desktops are remotely managed through resources at a service provider data center, optionally along with other virtual desktops hosted on desktop hosts at the service provider data center. The remote desktop hosts can be pre-configured with known storage, compute and connectivity resources. The remote desktop hosts can be remotely managed through a resource management appliance, i.e., a management system running resource management software, which can be located at either the service provider data center or the tenant data center.


