Skip to main content

September 2, 2026

Port and Protocol Requirements for Horizon Cloud on Nutanix Edge

Ensure that the required ports and protocols for your Horizon Cloud on Nutanix deployment allow communication as necessary. Use the following table to ensure your network configuration and firewalls will allow the communication traffic that is required for a successful deployment and for daily operations.

Note: Horizon Cloud on Nutanix is currently available in Limited Availability (LA) mode only.

For the Horizon Cloud on Nutanix provider type, the following table lists the required ports and protocols, along with the destination for the network traffic from the Horizon Edge.

SourceTargetPortsProtocolPurpose
Horizon EdgeNutanix Prism Central443HTTPSThis port is used by the edge to communicate with Nutanix Prism Central for UAG/desktop lifecycle management and inventory discovery.
Horizon EdgeUnified Access Gateway VMs9443HTTPSThis port is used by the Edge VM over the Management subnet to configure settings in the Edge's Unified Access Gateway (UAG) configuration.
This port requirement applies when initially deploying a Unified Access Gateway configuration and when editing an Edge to add a Unified Access Gateway configuration or update settings for that Unified Access Gateway configuration. It is also used to monitor session statistics from the Unified Access Gateway.
Horizon EdgeDomain controllerKerberos: 88 (TCP, UDP); LDAP: 389, 3268 (TCP); LDAPS: 636, 3269 (TCP)TCP / UDPRegistering your Horizon Cloud with Domain and for SSO login and periodic discovery of domain controllers.
These ports are required for LDAP or LDAPS services when LDAP/LDAPS will be specified in that workflow. LDAP is the default for most tenants. Target is the server that contains a domain controller role in the Active Directory configuration.
Horizon EdgeAD Certificate Services135 and a port within the range 49152–65535TCP (RPC)Connecting to the Microsoft Enterprise Certificate Authority (AD CS) to obtain short-lived certificates for True SSO. The Horizon Edge uses TCP port 135 for the initial RPC communication, then a port within the range 49152–65535 to communicate with Azure Directory Certificate Services.
Horizon EdgeDNS server53 and 853TCP / UDPDNS services.
Horizon Edge*.blob.core.windows.net / *.blob.storage.azure.net443TCPUsed for programmatic access to the Azure Blob Storage and to upload the Horizon Edge logs as and when required. Also used for downloading Docker images to create the required Horizon Edge modules, which are useful for monitoring, SSO, UAG updates, and so on.
Horizon EdgeAzure Container Registry / Microsoft Azure443TCPUsed for authentication while downloading Docker images to create the required Horizon Edge modules, which are useful for monitoring, SSO, UAG updates, and so on.
Horizon Edge*.azure-devices.net443TCPAppliance used to communicate with the cloud control plane, download configurations for the appliance's module, and update the appliance's module's runtime status. Current concrete endpoints are:
North America: edgehubprodna.azure-devices.net
Europe: edgehubprodeu.azure-devices.net
Japan: edgehubprodjp.azure-devices.net
Horizon Edge*.data.workspaceone.com (Omnissa)443TCPTo send events or metrics to Workspace ONE Intelligence for monitoring data.
Endpoints are:
eventproxy.na1.data.workspaceone.com, eventproxy.eu1.data.workspaceone.com, eventproxy.eu2.data.workspaceone.com, eventproxy.uk1.data.workspaceone.com, eventproxy.ca1.data.workspaceone.com, eventproxy.ap1.data.workspaceone.com, eventproxy.ap2.data.workspaceone.com, eventproxy.au1.data.workspaceone.com, eventproxy.in1.data.workspaceone.com
Horizon Edge*.horizon.omnissa.com — Region-specific MQTT endpoints are:
US: cloud-sg-us-hdc-mqtt.horizon.omnissa.com
EU: cloud-sg-eu-hdc-mqtt.horizon.omnissa.com
APAC: cloud-sg-jp-hdc-mqtt.horizon.omnissa.com
443TCP / MQTTThis port is required for Horizon Edge communication with the control plane for desktop lifecycle management and inventory discovery.
Horizon Edge*.horizon.omnissa.com
Region-specific endpoints are:
US: cloud-sg-us-r-westus2.horizon.omnissa.com, cloud-sg-us-r-eastus2.horizon.omnissa.com, cloud-sg-us.horizon.omnissa.com
EU: cloud-sg-eu-r-northeurope.horizon.omnissa.com, cloud-sg-eu-r-germanywestcentral.horizon.omnissa.com, cloud-sg-eu.horizon.omnissa.com, cloud-sg-eu-r-uksouth.horizon.omnissa.com
APAC: cloud-sg-jp-r-japaneast.horizon.omnissa.com, cloud-sg-jp.horizon.omnissa.com, cloud-sg-jp-r-australiaeast.horizon.omnissa.com, cloud-sg-jp-r-centralindia.horizon.omnissa.com
443TCPAppliance used to communicate with the cloud control plane and for Day 2 operations.
Horizon Edge Gateway (single VM type)NTP server123UDPNTP services.
Horizon EdgeUnified Access Gateway load balancer IP addresses (front end)443HTTPSHorizon Edge periodically checks that public and private load balancer IP addresses or URLs are reachable by querying the following URL: https://{LB_IP}/favicon.ico
Horizon Edgerepo.omnissa.com443HTTPSOmnissa UAG image repository.

Was this page helpful?

Provide feedback for this topic

Was this topic helpful?

Please do not include any personal or confidential information.

Generating link…