Skip to main content

September 2, 2026

Port and Protocol Requirements for Deploying a vSphere Edge

Ensure that the required ports and protocols for your Horizon Cloud on vSphere deployment allow communication as necessary. Use the following tables to ensure your network configuration and firewalls will allow the communication traffic that is required for a successful deployment and for day-to-day operations.

The following table lists the ports and protocols that are required for deploying a Horizon Edge for the vSphere provider type.

Ports and Protocols Required by Horizon Edge for vSphere

When you activate Horizon Infrastructure Monitoring, Horizon Edge is deployed and configured in the associated subscription. The following table lists the ports and protocols that are needed during the activation process which deploys the appliance and configures the manager VMs so the appliance can collect the monitoring data it is designed to collect from those components. This table also lists the ports and protocols that are needed during steady-state operations of collecting the data the appliance is designed to collect.

SourceTargetPortsProtocolsPurpose
Horizon EdgevCenter and ESXi Host443HTTPSThis port is used by the Horizon Edge to communicate with the vCenter and ESXi hosts for Unified Access Gateway and desktop lifecycle management and vCenter inventory discovery.
Horizon EdgeUnified Access Gateway VMs

Note: You must also allowlist port 8445 when using the Advanced UAG deployment method.
9443 (and 8445 when using Advanced UAG deployment)HTTPSThis port is used by the Edge VM over the Management subnet to configure settings in the Edge's Unified Access Gateway configuration.

This port requirement applies when initially deploying a Unified Access Gateway configuration and when editing an Edge to add a Unified Access Gateway configuration or update settings for that Unified Access Gateway configuration, and also to monitor the session statistics from the Unified Access Gateway.
Horizon EdgeDomain controllerKerberos: 88 ( TCP,UDP )
LDAP: 389, 3268 (TCP)
LDAPS: 636, 3269 (TCP)
TCP UDPRegistering your Horizon Cloud domain and for SSO login and periodic discovery of domain controllers. These ports are required for LDAP or LDAPS services when LDAP/LDAPS will be specified in that workflow. LDAP is the default for most tenants. Target is the server that contains a domain controller role in the Active Directory configuration.
Horizon EdgeAD Certificate Services135 and a port within the range of 49152 to 65535TCP (RPC)Connecting to the Microsoft Enterprise Certificate Authority (AD CS) to obtain short-lived certificates for True SSO. The Horizon Edge uses TCP port 135 for the initial RPC communication, then a port within the range 49152 - 65535 to communicate with AD CS (Active Directory Certificate Services).
Horizon EdgeDNS server53 and 853TCP UDPDNS services
Horizon Edge*.blob.core.windows.net
*.blob.storage.azure.net
443TCPUsed for programmatic access to the Azure Blob Storage and to upload the Horizon Edge logs as and when required. Used for downloading Docker images to create the required Horizon Edge modules, which are useful for monitoring, SSO, UAG updates, and such.
Horizon Edgehorizonedgeprod.azurecr.io443TCPUsed for authentication while downloading Docker images to create the required Horizon Edge modules, which are useful for monitoring, SSO, UAG updates, and so on.
Horizon Edge*.azure-devices.net443TCPAppliance used to communicate with the Horizon Cloud control plane, download configurations for the appliance's module, and update the appliance's module's runtime status.

Current concrete endpoints for North America are edgehubprodna.azure-devices.net.

Concrete endpoints for Europe are edgehubprodeu.azure-devices.net.

Concrete endpoints for Japan are edgehubprodjp.azure-devices.net.
Horizon Edge*.data.workspaceone.com443TCPTo send events or metrics to Workspace ONE Intelligence for monitoring data. See Workspace ONE Intelligence product documentation.

Concrete endpoints are: eventproxy.na1.data.workspaceone.com, eventproxy.eu1.data.workspaceone.com, eventproxy.eu2.data.workspaceone.com, eventproxy.uk1.data.workspaceone.com, eventproxy.ca1.data.workspaceone.com, eventproxy.ap1.data.workspaceone.com, eventproxy.ap2.data.workspaceone.com, eventproxy.au1.data.workspaceone.com, eventproxy.in1.data.workspaceone.com
Horizon Edge*.horizon.omnissa.com
Region specific:

US: cloud-sg-us-hdc-mqtt.horizon.omnissa.com

EU: cloud-sg-eu-hdc-mqtt.horizon.omnissa.com

APAC: cloud-sg-jp-hdc-mqtt.horizon.omnissa.com
443TCP MQTTThis port is required for Horizon Edge communication with control plane for desktop lifecycle management and vCenter inventory discovery.
Horizon Edge*.horizon.omnissa.com
Region specific:

US: cloud-sg-us-r-westus2.horizon.omnissa.com, cloud-sg-us-r-eastus2.horizon.omnissa.com, cloud-sg-us.horizon.omnissa.com

EU: cloud-sg-eu-r-northeurope.horizon.omnissa.com, cloud-sg-eu-r-germanywestcentral.horizon.omnissa.com, cloud-sg-eu.horizon.omnissa.com, cloud-sg-eu-r-uksouth.horizon.omnissa.com

APAC: cloud-sg-jp-r-japaneast.horizon.omnissa.com, cloud-sg-jp.horizon.omnissa.com, cloud-sg-jp-r-australiaeast.horizon.omnissa.com, cloud-sg-jp-r-centralindia.horizon.omnissa.com
443TCPAppliance used to communicate with the cloud control plane and for Day2 operations.
Horizon Edge Gateway (single VM type)NTP server123UDPNTP services
Horizon EdgeUnified Access Gateway load balancer IP addresses - front end.443HTTPSHorizon Edge periodically checks that public and private load balancer IP addresses or URLs are reachable by querying the following URL: https://{LB_IP}/favicon.ico
Horizon Edgerepo.omnissa.com443HTTPSOmnissa UAG image repository

Unified Access Gateway VM Ports and Protocols Requirements

In addition to the primary ports and protocols requirements listed in the table above, the ports and protocols in the following tables are related to the gateways that you have configured to operate for ongoing operations after deployment.

For connections configured with Unified Access Gateway instances, traffic must be allowed to and from the Unified Access Gateway instances to targets listed in the table below.

For these service-deployed Unified Access Gateway instances, the UDP ports require both forward and reply UDP datagrams to be allowed. For example, Unified Access Gateway services use DNS to resolve hostnames. DNS requests to the instances are made on UDP port 53 and so it is important that an external firewall does not block these requests or replies.

The Unified Access Gateway is deployed on a multi-NIC configuration. The Source Network column in the table that follows details which network the traffic comes from.

SourceTargetPortSource NetworkProtocolPurpose
Unified Access Gateway*.horizon.omnissa.com
Region specific:

US: cloud-sg-us.horizon.omnissa.com, cloud-sg-us-r-westus2.horizon.omnissa.com, cloud-sg-us-r-eastus2.horizon.omnissa.com

EU: cloud-sg-eu.horizon.omnissa.com, cloud-sg-eu-r-northeurope.horizon.omnissa.com, cloud-sg-eu-r-germanywestcentral.horizon.omnissa.com, cloud-sg-eu-r-uksouth.horizon.omnissa.com

APAC: cloud-sg-jp.horizon.omnissa.com, cloud-sg-jp-r-japaneast.horizon.omnissa.com, cloud-sg-jp-r-australiaeast.horizon.omnissa.com, cloud-sg-jp-r-centralindia.horizon.omnissa.co
443DMZ networkTCP UDPUnified Access Gateway needs to be able to resolve these addresses at any time or the user will not be able to launch the session, because the Unified Access Gateway fetches the JWK set.
Unified Access GatewayDNS server53 and 853AnyTCP UDPDNS services
Unified Access GatewayHorizon agent in the desktop or farm RDSH VMs22443Desktop NetworkTCP UDPBlast Extreme By default, when using Blast Extreme, client-drive redirection (CDR) traffic and USB traffic are side-channeled in this port. If preferred, the CDR traffic can be separated onto the TCP 9427 port and the USB redirection traffic can be separated onto the TCP 32111 port.
Unified Access GatewayHorizon agent in the desktop or farm RDSH VMs9427Desktop NetworkTCPOptional for CDR and multimedia redirection (MMR) traffic.
Unified Access GatewayHorizon agent in the desktop or farm RDSH VMs32111Desktop NetworkTCPOptional for USB redirection traffic.
Unified Access GatewayNTP server - The default value is time.google.com. However, you can freely change this value.123DMZ NetworkUDPNTP services
Unified Access GatewayOther Unified Access Gateways8445Management NetworkUDP(Advanced Mode only) Communication between UAG VMs.
Unified Access Gateway*.blob.core.windows.net
*.blob.storage.azure.net
443DMZ NetworkTCPUsed for programmatic access to the Azure Blob Storage to upload the Unified Access Gateway logs as and when required.
Unified Access GatewayCRL distribution point (CDP)
Example: http://*.digicert.com

OR

crl3.digicert.com/ DigiCertGlobalRootCA.crl
crl3.digicert.com/DigiCertTLSRSASHA2562020CA1-4.crl
crl4.digicert.com/DigiCertTLSRSASHA2562020CA1-4.crl
ocsp.digicert.com
80DMZ NetworkTCPOnly applicable for 1 NIC UAG deployments.

VDI Ports and Protocols Requirements

The following table provides the ports and protocols that are required for the desktop (VDI or tenant) subnets configured in your environment.

SourceTargetPortProtocolPurpose
Desktop SubnetExample: *.horizon.omnissa.com
Region specific:

US: cloud-sg-us-r-westus2.horizon.omnissa.com, cloud-sg-us-r-westus2-mqtt.horizon.omnissa.com, cloud-sg-us-r-eastus2.horizon.omnissa.com, cloud-sg-us-r-eastus2-mqtt.horizon.omnissa.com

EU: cloud-sg-eu-r-northeurope.horizon.omnissa.com, cloud-sg-eu-r-northeurope-mqtt.horizon.omnissa.com, cloud-sg-eu-r-germanywestcentral.horizon.omnissa.com, cloud-sg-eu-r-germanywestcentral-mqtt.horizon.omnissa.com, cloud-sg-eu-r-uksouth.horizon.omnissa.com, cloud-sg-eu-r-uksouth-mqtt.horizon.omnissa.com

JP: cloud-sg-jp-r-japaneast.horizon.omnissa.com, cloud-sg-jp-r-japaneast-mqtt.horizon.omnissa.com, cloud-sg-jp-r-australiaeast.horizon.omnissa.com, cloud-sg-jp-r-australiaeast-mqtt.horizon.omnissa.com, cloud-sg-jp-r-centralindia.horizon.omnissa.com, cloud-sg-jp-r-centralindia-mqtt.horizon.omnissa.com
443TCP MQTTFor agent-related operations, such as certificate signing using VM Hub and renewal.
Desktop SubnetDomain controllerKerberos: 88 ( TCP,UDP )
LDAP: 389, 3268 (TCP)
LDAPS: 636, 3269 (TCP)
TCP UDPKerberos services.
The target is the server that contains a domain controller role in an Active Directory configuration.
Registering the Edge an Active Directory is a requirement. These ports are required for LDAP or LDAPS services for VM to domain controller connectivity, in case the VDI is unable to reach any domain controller, then session launch is not possible.
Desktop SubnetDNS Server53 and 853TCP UDPDNS services
Desktop SubnetNTP server123UDPNTP services
Desktop Subnet*.blob.core.windows.net443TCPDCT log bundle upload. When a customer admin clicks on the DCT log collection for any VM after request processing, the bundle will be uploaded from VDI to blob to make that bundle available to download from the Horizon Universal Console.
Desktop SubnetHorizon Edge31883TCP MQTT UDPHorizon agent running on VM to MQTT running on Edge.
Desktop SubnetAzure DNS Zone value

Facilitates desktop communication to the Horizon Control Plane when using aggregate mode.

When the aggregated agent communication capability is enabled, a public Azure DNS record is auto-generated for desktops to connect to the Edge Gateway on port 443.
This DNS record uses the following format:
hcs-edgeid-mqtt-bridge.'regional_dns_zone'.

Replace the 'regional_dns_zone' entry with the correct regional district zone as below:

US: proddnsus.horizon.omnissa.com

EU:proddnseu.horizon.omnissa.com

JP:proddnsjp.horizon.omnissa.com

Also replace 'edgeid-mqtt' in 'hcs-edgeid-mqtt-bridge' with your actual Edge ID.

Include DNS records in your allowlists.

While the DNS value to allowlist can be obtained from the Horizon Edge Gateway UI in the “Aggregated Connection Endpoint Address” field, API users can fetch it from the GET edge-deployments API. The field is 'edgeServices.agentBridge.bridgeFqdn' in the edgegw response.
443HTTPSThis port is used to facilitate aggregated agent communication between the Horizon Edge Gateway Appliance and the Horizon Control Plane when using the MQTT Bridge mode.
Desktop SubnetHorizon Edge32443TCPSingle Sign-On
Desktop Subnetsoftwareupdate.omnissa.com443TCPSoftware package server. Used for downloading updates of the agent-related software used in the system's image-related operations and automated agent update process.
Desktop Subnet and Management SubnetAD Certificate Services135 and 445 and a port within the range of 49152 to 65535TCP (RPC)To add desktops to domain.
Desktop SubnetCRL distribution point (CDP)
Example: http://*.digicert.com

OR

crl3.digicert.com/ DigiCertGlobalRootCA.crl
crl3.digicert.com/DigiCertTLSRSASHA2562020CA1-4.crl
crl4.digicert.com/DigiCertTLSRSASHA2562020CA1-4.crl
ocsp.digicert.com
80TCPThe bootstrapping process for the VM involves sending an HTTP POST request to the Horizon Cloud endpoint. To establish a secure connection, a Certificate Revocation List (CRL) check is performed. If this check is not permitted through the internet, VM customization fails.
Desktop Subneteventproxy.na1.data.workspaceone.com, eventproxy.eu1.data.workspaceone.com, eventproxy.eu2.data.workspaceone.com, eventproxy.uk1.data.workspaceone.com, eventproxy.ca1.data.workspaceone.com, eventproxy.ap1.data.workspaceone.com, eventproxy.ap2.data.workspaceone.com, eventproxy.au1.data.workspaceone.com, eventproxy.in1.data.workspaceone.com443TCPUsed by Digital Employee Experience (DEX) telemetry agent to send data to Omnissa Intelligence. This is required only for DEX-enabled desktops.

End-User Connection Traffic Ports and Protocols Requirements

For detailed information about the various Horizon Clients that your end users might use with your Horizon Edge Virtual Appliance, see the Horizon Client product documentation. Which ports must be opened for traffic from the end users’ connections to reach their virtual desktops and remote applications depends on the choice you make for how your end users will connect.

SourceTargetPortProtocolPurpose
Horizon ClientLoad balancer for the Unified Access Gateway instances443TCPTo carry CDR, MMR, USB redirection, and tunneled RDP traffic. SSL (HTTPS access) is enabled by default for client connections. Port 80 (HTTP access) can be used in some cases.
Horizon ClientLoad balancer for the Unified Access Gateway instances8443 or 443TCPBlast Extreme via Blast Secure Gateway on Unified Access Gateway for data traffic from Horizon Client. The port used, 8443 or 443, is defined when the Horizon Edge Gateway is deployed.
Horizon ClientLoad balancer for the Unified Access Gateway instances443UDPBlast Extreme via the Unified Access Gateway for data traffic.
Horizon ClientLoad balancer for the Unified Access Gateway instances8443UDPBlast Extreme via Blast Secure Gateway on Unified Access Gateway for data traffic (adaptive transport).
BrowserLoad balancer for the Unified Access Gateway instances443TCPTo carry CDR, MMR, USB redirection, and tunneled RDP traffic. SSL (HTTPS access) is enabled by default for client connections. Port 80 (HTTP access) can be used in some cases.
BrowserLoad balancer for the Unified Access Gateway instances8443 or 443TCPBlast Extreme via Blast Secure Gateway on Unified Access Gateway for data traffic from the Horizon Web Client.
Horizon Client/BrowserExample: *.horizon.omnissa.com
Region specific:

US: cloud-sg-us-r-westus2.horizon.omnissa.com, cloud-sg-us-r-westus2-mqtt.horizon.omnissa.com, cloud-sg-us-r-eastus2.horizon.omnissa.com, cloud-sg-us-r-eastus2-mqtt.horizon.omnissa.com

EU: cloud-sg-eu-r-northeurope.horizon.omnissa.com, cloud-sg-eu-r-northeurope-mqtt.horizon.omnissa.com, cloud-sg-eu-r-germanywestcentral.horizon.omnissa.com, cloud-sg-eu-r-germanywestcentral-mqtt.horizon.omnissa.com, cloud-sg-eu-r-uksouth.horizon.omnissa.com, cloud-sg-eu-r-uksouth-mqtt.horizon.omnissa.com

JP: cloud-sg-jp-r-japaneast.horizon.omnissa.com, cloud-sg-jp-r-japaneast-mqtt.horizon.omnissa.com, cloud-sg-jp-r-australiaeast.horizon.omnissa.com, cloud-sg-jp-r-australiaeast-mqtt.horizon.omnissa.com, cloud-sg-jp-r-centralindia.horizon.omnissa.com, cloud-sg-jp-r-centralindia-mqtt.horizon.omnissa.com
443TCPAfter logging in and listing the launch items, when an end user clicks to launch a desktop, the redirection of the protocol traffic to Unified Access Gateway occurs from one of these URLs based on the region in which the specified VM is located. You must allowlist URLs listed based on the global regions from which you deliver desktops and applications. The client needs access to the Service Gateway URL for each relevant region, such as cloud-sg-us-r-westus2.horizon.omnissa.com .
Horizon Client/Browserhttps://cloud.omnissahorizon.com443TCPIf you have a restricted network, you must allowlist the appropriate URLs to enable end users to access their applications and desktops. If you have customized the Client Access URL, ensure that your custom URL is also added to your allowlist.

Was this page helpful?

Provide feedback for this topic

Was this topic helpful?

Please do not include any personal or confidential information.

Generating link…