It appears to me, while Security Server is still being supported, UAG (Unified Access Gateway) is now the way to go. It is a really nice gateway with really intuitive web interface. It has a few levels of networking with regards to external and internal NICs. You need it as it acts as the security layer between internet and Horizon desktops. It should be load balanced though to ensure connections are being distributed among the Connection Servers correctly. Also use multiple UAGs for high availability. Basically, it sits in the DMZ and passes shakes and connections long.
We're just going through spinning up the various services and things for VMware Horizon 7.10 in our Dev environment with a view to upgrade Prod in a few months time. I'm just starting to look at load balancing so have requested the free trial to start playing around.