Ensure that the required ports, protocols, and destination URLs for your Horizon Cloud on Horizon 8 deployment allow communication as necessary between Horizon Edge and Horizon Connection Server. Use the following tables to verify that your network configuration and firewalls will allow the communication traffic required for a successful deployment and for day-to-day operations.
The specific ports and protocols required for your deployment will in part depend on which features you select to use. If you do not plan to use Splunk Enterprise for monitoring, you can ignore the ports associated with Splunk Enterprise.
Important: To allow the appropriate URLs and wildcard subdomains, add them to an allow list for your firewall and bypass SSL deep packet inspection in both the firewall and, if applicable, the proxy server. If the Horizon Edge Gateway is connected to the Horizon Cloud control plane through a proxy server, bypass SSL deep packet inspection in the proxy server for the URLs and wildcard subdomains listed below. For situations where using URLs is not possible, see KB 6000374 — IP Addresses for Service Components.
Ports and Protocols Required by Horizon Edge
When you activate Horizon Infrastructure Monitoring, Horizon Edge is deployed and configured in the associated subscription.
The following table lists the ports and protocols needed during the activation process — in which the appliance deploys and configures the manager VMs so the appliance can collect monitoring data — as well as the ports and protocols needed during steady-state operations.
Horizon Edge Outbound
| Source | Target | Ports | Protocols | Purpose |
|---|---|---|---|---|
| Horizon Edge | Unified Access Gateway VMs | 9443 | HTTPS | This port is used when monitoring is enabled for the Unified Access Gateways from the Horizon Control Plane. |
| Horizon Edge | Horizon Connection Server | 443 | HTTPS | License configuration. |
| Horizon Edge | Splunk Enterprise | 8000 and 8088 | HTTP, HTTPS | Monitoring data collection. |
| Horizon Edge | DNS server | 53 and 853 | TCP, UDP | DNS services. |
| Horizon Edge | *.blob.core.windows.net | 443 | TCP | Used for programmatic access to the Azure Blob Storage to replicate images across Horizon 8 Edges. Note that any proxy access restrictions for this endpoint must be relaxed to allow for image replication. |
| Horizon Edge | horizonedgeprod.azurecr.io | 443 | TCP | Used for authentication while downloading Docker images to create the required Horizon Edge modules, which are useful for monitoring, SSO, UAG updates, and such. |
| Horizon Edge | *.azure-devices.netRegion-specific names: North America: - edgehubprodna.azure-devices.netEurope: - edgehubprodeu.azure-devices.netJapan: - edgehubprodjp.azure-devices.net | 443 | TCP | Appliance used to communicate with the cloud control plane, download configurations for the appliance's module, and update the appliance's module's runtime status. |
| Horizon Edge | *.data.workspaceone.comRegion-specific names: - eventproxy.na1.data.workspaceone.com- eventproxy.eu1.data.workspaceone.com- eventproxy.eu2.data.workspaceone.com- eventproxy.uk1.data.workspaceone.com- eventproxy.ca1.data.workspaceone.com- eventproxy.ap1.data.workspaceone.com- eventproxy.ap2.data.workspaceone.com- eventproxy.au1.data.workspaceone.com- eventproxy.in1.data.workspaceone.com | 443 | TCP | To send events or metrics to Workspace ONE Intelligence for monitoring data. See Workspace ONE Intelligence. |
| Horizon Edge | NTP server | 123 | UDP | NTP services. |
| Horizon Edge | Horizon Connection Server | 4002 | TCP | Horizon Edge to Horizon Connection Server over Java Messaging Service (JMS). |
| Horizon Edge | softwareupdate.omnissa.com | 443 | TCP | Used to access the CDN to download the required Horizon Agent installer for image management operations. |
| Horizon Edge | cloud-sg-us-hdc-mqtt.horizon.omnissa.com | 443 | TCP | Used by Horizon 8 Edge components to communicate bidirectionally with Horizon Cloud for image management operations and license consumption tracking. Also required for Universal Broker. |
| Horizon Edge | cloud-sg-eu-hdc-mqtt.horizon.omnissa.com | 443 | TCP | Used by Horizon 8 Edge components to communicate bidirectionally with Horizon Cloud for image management operations and license consumption tracking. Also required for Universal Broker. |
| Horizon Edge | cloud-sg-jp-hdc-mqtt.horizon.omnissa.com | 443 | TCP | Used by Horizon 8 Edge components to communicate bidirectionally with Horizon Cloud for image management operations and license consumption tracking. Also required for Universal Broker. |
Horizon Edge Inbound
| Source | Target | Ports | Protocols | Purpose |
|---|---|---|---|---|
| Horizon Agent | Horizon Edge | 32198 | TCP, UDP | Horizon Agent running on a VM can forward diagnostic logs to the Omnissa-managed Azure Blob Storage through the Horizon Edge Gateway. |
| Horizon Agent | Horizon Edge | 31883 | TCP, UDP | Horizon Agent running on VM to MQTT running on Edge. |
VDI Ports and Protocols Requirements
The following table provides the ports and protocols required for the desktop (VDI or tenant) subnets configured in your environment.
Note: In addition to the ports listed below, ensure that the URLs and wildcard subdomains required for Horizon Edge are also reachable from your environment. For details, see Allow URLs for the Management Subnet below.
| Source | Target | Port | Protocol | Purpose |
|---|---|---|---|---|
| Desktop (tenant) Subnet | - eventproxy.na1.data.workspaceone.com- eventproxy.eu1.data.workspaceone.com- eventproxy.eu2.data.workspaceone.com- eventproxy.uk1.data.workspaceone.com- eventproxy.ca1.data.workspaceone.com- eventproxy.ap1.data.workspaceone.com- eventproxy.ap2.data.workspaceone.com- eventproxy.au1.data.workspaceone.com- eventproxy.in1.data.workspaceone.com | 443 | TCP | Used by Digital Employee Experience (DEX) telemetry agent to send data to Omnissa Intelligence. Required only for DEX-enabled desktops. |
| Desktop (tenant) Subnet | - auth.na1.data.workspaceone.com- auth.eu1.data.workspaceone.com- auth.eu2.data.workspaceone.com- auth.uk1.data.workspaceone.com- auth.ca1.data.workspaceone.com- auth.ap1.data.workspaceone.com- auth.ap2.data.workspaceone.com- auth.au1.data.workspaceone.com- auth.in1.data.workspaceone.com | 443 | TCP | Used by Digital Employee Experience (DEX) telemetry agent to authenticate with Omnissa Intelligence. Required only for DEX-enabled desktops. |
Allow URLs for the Management Subnet
Allow the appropriate URLs and wildcard subdomains according to your site location and needs. More specifically, perform the following tasks:
- Allow the URLs and wildcard subdomains in the table below by adding them to an allow list for your firewall.
- Bypass SSL deep packet inspection in the firewall for the URLs and wildcard subdomains listed below.
- If applicable, bypass SSL deep packet inspection in the proxy server. If the Horizon Edge Gateway is connected to the Horizon Cloud control plane through a proxy server, bypass SSL deep packet inspection in the proxy server for the URLs and wildcard subdomains in the table below.
Important: The listed purposes are in the context of a Horizon Edge Gateway with Horizon Connection Server.
| Destination (DNS name) | Port | Protocol | Purpose |
|---|---|---|---|
registry.k8s.io | 443 | TCP | Used for programmatic access to allow images to download as and when required. Used for downloading Docker images to create the required Horizon Edge modules, which are useful for monitoring, SSO, UAG updates, and such. |
*.blob.core.windows.net | 443 | TCP | Used for programmatic access to the Azure Blob Storage and to upload the Horizon Edge logs as and when required. Used for downloading Docker images to create the required Horizon Edge modules, which are useful for monitoring, SSO, UAG updates, and such. |
horizonedgeprod.azurecr.io | 443 | TCP | Used for authentication while downloading Docker images to create the required Horizon Edge modules, which are useful for monitoring, SSO, UAG updates, and such. |
*.azure-devices.netRegion-specific names: North America: - edgehubprodna.azure-devices.netEurope: - edgehubprodeu.azure-devices.netJapan: - edgehubprodjp.azure-devices.net | 443 | TCP (HTTP, HTTPS, and WSS) | Used to connect the appliance to the Horizon Cloud control plane, to download configurations for the appliance's module, and to update the appliance's module's runtime status. |
*.data.workspaceone.comRegion-specific names: - eventproxy.na1.data.workspaceone.com- eventproxy.eu1.data.workspaceone.com- eventproxy.eu2.data.workspaceone.com- eventproxy.uk1.data.workspaceone.com- eventproxy.ca1.data.workspaceone.com- eventproxy.ap1.data.workspaceone.com- eventproxy.ap2.data.workspaceone.com- eventproxy.au1.data.workspaceone.com- eventproxy.in1.data.workspaceone.com | 443 | TCP | Used for sending events or metrics to Workspace ONE Intelligence. |
Note: Horizon Cloud has a localized active-active deployment in Japan to ensure infrastructure resiliency remains entirely within the region, adhering to local compliance policies. Traffic dynamically routes between the Horizon Cloud 1 instance (Japan East) and the Horizon Cloud 2 instance (Japan West) based on geographic affinity. If your organization enforces IP-based allowlisting, ensure your firewall rules include entries for both of the Horizon Cloud instances in Japan as listed in KB6000374 — IP Addresses for Service Components.
Requirements for Universal Broker
For the Universal Broker use-case, the Unified Access Gateway instances must maintain connectivity to the Horizon Cloud Service Gateway endpoints to fetch the JSON Web Key (JWK) set used for JWT (JSON Web Token) authentication. This connectivity is critical for session brokering and client protocol redirection to function correctly across pods.
Ensure that your network configuration and firewalls allow the Unified Access Gateway instances to communicate with the destinations as shown below:
- Source: Unified Access Gateway
- Target:
cloud-sg.horizon.omnissa.com - Port: 443
- Source Network: DMZ network
- Protocols: TCP, UDP
- Purpose: Because the Unified Access Gateway fetches the JWK set from
cloud-sg.horizon.omnissa.com, Unified Access Gateway must be able to resolve these addresses at any time or the user will not be able to launch the session.
Was this page helpful?