Skip to main content

September 2, 2026

Ports, Protocols, and URL Requirements for Horizon Cloud on Horizon 8

Ensure that the required ports, protocols, and destination URLs for your Horizon Cloud on Horizon 8 deployment allow communication as necessary between Horizon Edge and Horizon Connection Server. Use the following tables to verify that your network configuration and firewalls will allow the communication traffic required for a successful deployment and for day-to-day operations.

The specific ports and protocols required for your deployment will in part depend on which features you select to use. If you do not plan to use Splunk Enterprise for monitoring, you can ignore the ports associated with Splunk Enterprise.

Important: To allow the appropriate URLs and wildcard subdomains, add them to an allow list for your firewall and bypass SSL deep packet inspection in both the firewall and, if applicable, the proxy server. If the Horizon Edge Gateway is connected to the Horizon Cloud control plane through a proxy server, bypass SSL deep packet inspection in the proxy server for the URLs and wildcard subdomains listed below. For situations where using URLs is not possible, see KB 6000374 — IP Addresses for Service Components.


Ports and Protocols Required by Horizon Edge

When you activate Horizon Infrastructure Monitoring, Horizon Edge is deployed and configured in the associated subscription.

The following table lists the ports and protocols needed during the activation process — in which the appliance deploys and configures the manager VMs so the appliance can collect monitoring data — as well as the ports and protocols needed during steady-state operations.

Horizon Edge Outbound

SourceTargetPortsProtocolsPurpose
Horizon EdgeUnified Access Gateway VMs9443HTTPSThis port is used when monitoring is enabled for the Unified Access Gateways from the Horizon Control Plane.
Horizon EdgeHorizon Connection Server443HTTPSLicense configuration.
Horizon EdgeSplunk Enterprise8000 and 8088HTTP, HTTPSMonitoring data collection.
Horizon EdgeDNS server53 and 853TCP, UDPDNS services.
Horizon Edge*.blob.core.windows.net443TCPUsed for programmatic access to the Azure Blob Storage to replicate images across Horizon 8 Edges. Note that any proxy access restrictions for this endpoint must be relaxed to allow for image replication.
Horizon Edgehorizonedgeprod.azurecr.io443TCPUsed for authentication while downloading Docker images to create the required Horizon Edge modules, which are useful for monitoring, SSO, UAG updates, and such.
Horizon Edge*.azure-devices.net
Region-specific names:
North America:
- edgehubprodna.azure-devices.net
Europe:
- edgehubprodeu.azure-devices.net
Japan:
- edgehubprodjp.azure-devices.net
443TCPAppliance used to communicate with the cloud control plane, download configurations for the appliance's module, and update the appliance's module's runtime status.
Horizon Edge*.data.workspaceone.com
Region-specific names:
- eventproxy.na1.data.workspaceone.com
- eventproxy.eu1.data.workspaceone.com
- eventproxy.eu2.data.workspaceone.com
- eventproxy.uk1.data.workspaceone.com
- eventproxy.ca1.data.workspaceone.com
- eventproxy.ap1.data.workspaceone.com
- eventproxy.ap2.data.workspaceone.com
- eventproxy.au1.data.workspaceone.com
- eventproxy.in1.data.workspaceone.com
443TCPTo send events or metrics to Workspace ONE Intelligence for monitoring data. See Workspace ONE Intelligence.
Horizon EdgeNTP server123UDPNTP services.
Horizon EdgeHorizon Connection Server4002TCPHorizon Edge to Horizon Connection Server over Java Messaging Service (JMS).
Horizon Edgesoftwareupdate.omnissa.com443TCPUsed to access the CDN to download the required Horizon Agent installer for image management operations.
Horizon Edgecloud-sg-us-hdc-mqtt.horizon.omnissa.com443TCPUsed by Horizon 8 Edge components to communicate bidirectionally with Horizon Cloud for image management operations and license consumption tracking. Also required for Universal Broker.
Horizon Edgecloud-sg-eu-hdc-mqtt.horizon.omnissa.com443TCPUsed by Horizon 8 Edge components to communicate bidirectionally with Horizon Cloud for image management operations and license consumption tracking. Also required for Universal Broker.
Horizon Edgecloud-sg-jp-hdc-mqtt.horizon.omnissa.com443TCPUsed by Horizon 8 Edge components to communicate bidirectionally with Horizon Cloud for image management operations and license consumption tracking. Also required for Universal Broker.

Horizon Edge Inbound

SourceTargetPortsProtocolsPurpose
Horizon AgentHorizon Edge32198TCP, UDPHorizon Agent running on a VM can forward diagnostic logs to the Omnissa-managed Azure Blob Storage through the Horizon Edge Gateway.
Horizon AgentHorizon Edge31883TCP, UDPHorizon Agent running on VM to MQTT running on Edge.

VDI Ports and Protocols Requirements

The following table provides the ports and protocols required for the desktop (VDI or tenant) subnets configured in your environment.

Note: In addition to the ports listed below, ensure that the URLs and wildcard subdomains required for Horizon Edge are also reachable from your environment. For details, see Allow URLs for the Management Subnet below.

SourceTargetPortProtocolPurpose
Desktop (tenant) Subnet- eventproxy.na1.data.workspaceone.com
- eventproxy.eu1.data.workspaceone.com
- eventproxy.eu2.data.workspaceone.com
- eventproxy.uk1.data.workspaceone.com
- eventproxy.ca1.data.workspaceone.com
- eventproxy.ap1.data.workspaceone.com
- eventproxy.ap2.data.workspaceone.com
- eventproxy.au1.data.workspaceone.com
- eventproxy.in1.data.workspaceone.com
443TCPUsed by Digital Employee Experience (DEX) telemetry agent to send data to Omnissa Intelligence. Required only for DEX-enabled desktops.
Desktop (tenant) Subnet- auth.na1.data.workspaceone.com
- auth.eu1.data.workspaceone.com
- auth.eu2.data.workspaceone.com
- auth.uk1.data.workspaceone.com
- auth.ca1.data.workspaceone.com
- auth.ap1.data.workspaceone.com
- auth.ap2.data.workspaceone.com
- auth.au1.data.workspaceone.com
- auth.in1.data.workspaceone.com
443TCPUsed by Digital Employee Experience (DEX) telemetry agent to authenticate with Omnissa Intelligence. Required only for DEX-enabled desktops.

Allow URLs for the Management Subnet

Allow the appropriate URLs and wildcard subdomains according to your site location and needs. More specifically, perform the following tasks:

  • Allow the URLs and wildcard subdomains in the table below by adding them to an allow list for your firewall.
  • Bypass SSL deep packet inspection in the firewall for the URLs and wildcard subdomains listed below.
  • If applicable, bypass SSL deep packet inspection in the proxy server. If the Horizon Edge Gateway is connected to the Horizon Cloud control plane through a proxy server, bypass SSL deep packet inspection in the proxy server for the URLs and wildcard subdomains in the table below.

Important: The listed purposes are in the context of a Horizon Edge Gateway with Horizon Connection Server.

Destination (DNS name)PortProtocolPurpose
registry.k8s.io443TCPUsed for programmatic access to allow images to download as and when required. Used for downloading Docker images to create the required Horizon Edge modules, which are useful for monitoring, SSO, UAG updates, and such.
*.blob.core.windows.net443TCPUsed for programmatic access to the Azure Blob Storage and to upload the Horizon Edge logs as and when required. Used for downloading Docker images to create the required Horizon Edge modules, which are useful for monitoring, SSO, UAG updates, and such.
horizonedgeprod.azurecr.io443TCPUsed for authentication while downloading Docker images to create the required Horizon Edge modules, which are useful for monitoring, SSO, UAG updates, and such.
*.azure-devices.net
Region-specific names:
North America:
- edgehubprodna.azure-devices.net
Europe:
- edgehubprodeu.azure-devices.net
Japan:
- edgehubprodjp.azure-devices.net
443TCP (HTTP, HTTPS, and WSS)Used to connect the appliance to the Horizon Cloud control plane, to download configurations for the appliance's module, and to update the appliance's module's runtime status.
*.data.workspaceone.com
Region-specific names:
- eventproxy.na1.data.workspaceone.com
- eventproxy.eu1.data.workspaceone.com
- eventproxy.eu2.data.workspaceone.com
- eventproxy.uk1.data.workspaceone.com
- eventproxy.ca1.data.workspaceone.com
- eventproxy.ap1.data.workspaceone.com
- eventproxy.ap2.data.workspaceone.com
- eventproxy.au1.data.workspaceone.com
- eventproxy.in1.data.workspaceone.com
443TCPUsed for sending events or metrics to Workspace ONE Intelligence.

Note: Horizon Cloud has a localized active-active deployment in Japan to ensure infrastructure resiliency remains entirely within the region, adhering to local compliance policies. Traffic dynamically routes between the Horizon Cloud 1 instance (Japan East) and the Horizon Cloud 2 instance (Japan West) based on geographic affinity. If your organization enforces IP-based allowlisting, ensure your firewall rules include entries for both of the Horizon Cloud instances in Japan as listed in KB6000374 — IP Addresses for Service Components.

Requirements for Universal Broker

For the Universal Broker use-case, the Unified Access Gateway instances must maintain connectivity to the Horizon Cloud Service Gateway endpoints to fetch the JSON Web Key (JWK) set used for JWT (JSON Web Token) authentication. This connectivity is critical for session brokering and client protocol redirection to function correctly across pods.

Ensure that your network configuration and firewalls allow the Unified Access Gateway instances to communicate with the destinations as shown below:

  • Source: Unified Access Gateway
  • Target: cloud-sg.horizon.omnissa.com
  • Port: 443
  • Source Network: DMZ network
  • Protocols: TCP, UDP
  • Purpose: Because the Unified Access Gateway fetches the JWK set from cloud-sg.horizon.omnissa.com, Unified Access Gateway must be able to resolve these addresses at any time or the user will not be able to launch the session.

Was this page helpful?

Provide feedback for this topic

Was this topic helpful?

Please do not include any personal or confidential information.

Generating link…