Preserving Network Isolation When Moving from Hardware-Based to Software-Based Remote Workstation Connectivity

For years, a dedicated hardware host card gave IT teams something software has struggled to replicate: a remote workstation that was completely invisible to the corporate data network. As more organizations move to software-based remoting agents, that isolation doesn't have to disappear — a dual-NIC network topology reproduces it, with no connection broker required. This guide explains how the architecture works, and how legacy and modern endpoints can run on the same backend at the same time. Get the full white paper, free.

Get the Full Guide

Enter your name and email below and the complete white paper will be sent to you immediately — no sales call required.

Moving From Hardware to Software-Based Remote Workstation Connectivity

For a long stretch of enterprise IT history, the most secure way to deliver a remote workstation was to give it its own dedicated hardware — a host card with its own network interface, its own IP address, and its own management plane, entirely separate from the corporate data network. The ClearCube/Teradici TERA2 PCoIP host card is the best-known example of this model, and for organizations in healthcare, finance, government, and defense, that hardware-enforced separation wasn’t a nice-to-have. It was the reason the architecture was trusted at all.

The industry has since shifted toward host-based software agents — the Omnissa Horizon Blast Extreme agent with the Virtual Direct-Connect Agent (VADC) chief among them — which run inside the host operating system rather than on dedicated hardware. That shift raises a fair architectural question, one every IT team eventually has to answer as they modernize: if the agent runs in software, does the host OS now have to be reachable from the endpoint network — and does that mean giving up the isolation the hardware model provided?

What Made the Hardware Model Secure

The Three Security Properties of a Dedicated Host Card

A card like TERA2 wasn’t a remote display adapter — it functioned as a separate computer embedded in the host workstation. That gave it three specific security properties worth naming individually, because they’re exactly what any software replacement has to reproduce: the display protocol network was physically separate from the data network; the host OS had no connection to the endpoint and couldn’t be reached from the user-facing network; and the card itself could be managed, rebooted, or replaced independently of the host OS.

What Changes When the Agent Runs in Software

A software agent runs inside the host operating system, which means that OS now needs to be network-reachable from the endpoint for a session to establish. At first glance, that looks like it collapses the separation the hardware model relied on — the OS is now technically on the same network as the display protocol traffic. It’s the right question to ask, and the answer lives in network design, not in the agent software itself.

The Solution: Dual-NIC Network Topology

The isolation a dedicated host card provided in hardware can be reproduced through a dedicated network interface on the host machine instead. By equipping the host with two NICs — one handling corporate data traffic, one reserved exclusively for display protocol traffic — the same fundamental security model carries forward into a software-based deployment.

How Dual-NIC Segmentation Replicates Hardware Isolation

In this model, the primary NIC connects to the corporate LAN and keeps the default gateway, handling internet access, file servers, authentication, and all other data-plane traffic. The secondary NIC connects only to a dedicated switch — or directly to client devices — and is assigned no default gateway, so it can receive endpoint connections but cannot route packets back to the corporate LAN. The result: endpoints and users interact only with the display protocol interface, and the host’s data network remains as invisible to them as it was under the original hardware model.

Three Validated Network Scenarios

Not every environment needs the same level of segmentation, and the right topology depends on what the environment actually requires. The white paper documents three network scenarios validated in production — a simple shared-network setup suited to low-security or proof-of-concept deployments, a fully segmented dual-NIC model recommended for regulated industries and any organization moving off a hardware host card, and a point-to-point direct connection for SCIFs, trading floors, and other environments with zero shared infrastructure. All three achieved full session success across legacy and modern endpoints alike.

Legacy and Modern Endpoints, One Backend

One of the more practical implications of this architecture: existing PCoIP zero clients — including TERA2 units already in the field — don’t need to be replaced to make this move. They keep connecting via PCoIP with no firmware changes, while modern Linux-based thin clients connect via Blast Extreme, all against the same VADC backend simultaneously. That decouples the endpoint refresh cycle from the backend architecture decision entirely — each can move on its own timeline.

A Flexible Migration Path

Because endpoints and backend infrastructure can move independently, this doesn’t have to be a single, high-risk cutover. A typical path starts with a pilot on a single host, adds dual-NIC segmentation once session quality is validated, introduces modern thin clients alongside any remaining legacy units, and finishes with a full rollout on the organization’s own schedule — with legacy and modern endpoints coexisting on the same backend throughout.

What’s Inside the Full White Paper

This overview covers the architecture — the full white paper provides the implementation detail:

  • Full technical breakdown of the dual-NIC configuration, including registry-level binding and routing behavior
  • Complete specification tables for all three validated network scenarios, with use cases and ideal-fit guidance for each
  • A side-by-side comparison of the hardware host card model against the VADC dual-NIC software model
  • Supported endpoint and backend infrastructure options, including VM/hypervisor, rackmount/blade workstation, and high-density mini-PC deployments
  • A four-phase migration roadmap with specific actions for each stage
  • Port and protocol quick-reference appendix

Frequently Asked Questions

What is dual-NIC network isolation? It’s a network architecture where a host machine uses two network interfaces — one for corporate data traffic, one dedicated solely to display protocol traffic with no default gateway — so the display session stays isolated from the data network even though the remoting agent runs in software rather than on dedicated hardware.

Does moving from a hardware host card to a software agent mean losing network isolation? No. A dual-NIC network topology on the replacement host reproduces the same isolation a dedicated hardware card provided — display protocol traffic stays on a dedicated, non-routable network interface, separate from the corporate data network.

Do existing PCoIP zero clients need to be replaced to adopt this architecture? No. Existing PCoIP zero clients, including TERA2 units, continue to to function with minimal configuration change once the backend host is running the Omnissa VADC agent. Endpoint replacement can happen on its own timeline, independent of the backend.

What is the Omnissa Virtual Direct-Connect Agent (VADC)? VADC is host-based software that runs the Omnissa Horizon Blast Extreme protocol while also supporting legacy PCoIP connections from existing zero clients, without requiring a connection broker.

Is TERA2 actually end of life? The TERA2 end of life has been announced for 2029 and is in it’s maintenance only phase.  Focus has moved to software-based alternatives. That’s part of why this architecture matters, but the dual-NIC approach itself is relevant to any organization moving from a hardware-based to a software-based remote workstation model, not only those responding to an end-of-life notice.

Can legacy and modern endpoints run on the same backend at the same time? Yes. Legacy PCoIP zero clients and modern Blast Extreme thin clients are both supported simultaneously on the same VADC backend infrastructure.


Get the Full Guide

Enter your name and email above for immediate access to the complete white paper download — no sales call required.

Need assistance or have a question?
Schedule one-on-one time with a ClearCube professional.

No matter where you are in the buying process, let our team of highly knowledgable staff assist you in your journey.

Explore Additional White Papers & Case Studies
Why ClearCube for CAD/CAM/GIS Computing Solutions
A brief discussion of why ClearCube is a good partner for CAD / CAM / CAE / GIS / AV / 3D Engineering Workstation solutions.
Read More
Building “IP Fluid” Cyber Command Centers
Activu and ClearCube, both innovative technology companies with respective solutions that lead their technology sectors, present a turnkey “best in class” visualization and collaboration solution that empowers mission-critical operators with a dynamic flow of visuals and data over IP to increase their response efficiency to unprecedented levels.
Read More
The Value of Centralized and Virtualized Desktop Infrastructure (CVDI)
A Whitepaper discussing the value of ClearCube’s Centralized and Virtualized Desktop Infrastructure.
Read More

Click the button below to begin your download.

close this window after downloading to continue browsing