Skip to main content

April 20, 2026

Horizon TCP and UDP Ports

Horizon uses TCP and UDP ports for network access between its components.

During installation, Horizon can optionally configure Windows firewall rules to open the ports that are used by default. If you change the default ports after installation, you must manually reconfigure Windows firewall rules to allow access on the updated ports. See "Replacing Default Ports for Horizon Services" in the Horizon Installation and Upgrade document.

For a list of ports that Horizon uses for a certificate login associated with the TrueSSO solution, see Horizon TrueSSO Ports.

SourcePortTargetPortProtocolDescription
Connection broker or Unified Access Gateway appliance55000Horizon Agent4172UDPPCoIP (not SALSA20) if PCoIP Secure Gateway is used.
Connection broker or Unified Access Gateway appliance4172Horizon Client*UDPPCoIP (not SALSA20) if PCoIP Secure Gateway is used. Note: Because the target port varies, see the note following this table.
Connection broker or Unified Access Gateway appliance*Horizon Agent3389TCPMicrosoft RDP traffic to Horizon desktops when tunnel connections are used.
Connection broker or Unified Access Gateway appliance*Horizon Agent9427TCPWindows multimedia redirection, client drive redirection, Microsoft Teams optimization, HTML5 multimedia redirection, printer redirection, and USB redirection when tunnel connections are used.
Connection broker or Unified Access Gateway appliance*Horizon Agent32111TCPUSB redirection and time zone synchronization when tunnel connections are used.
Connection broker or Unified Access Gateway appliance*Horizon Agent4172TCPPCoIP if PCoIP Secure Gateway is used.
Connection broker or Unified Access Gateway appliance*Horizon Agent22443TCPHorizon Blast Extreme if Blast Secure Gateway is used.
Connection broker or Unified Access Gateway appliance*Horizon Agent22443TCPHTML Access if Blast Secure Gateway is used.
Horizon Agent4172Horizon Client*UDPPCoIP, if PCoIP Secure Gateway is not used. Note: Because the target port varies, see the note following this table.
Horizon Agent4172Connection broker or Unified Access Gateway appliance55000UDPPCoIP (not SALSA20) if PCoIP Secure Gateway is used.
Horizon Agent4172Unified Access Gateway appliance*UDPPCoIP. Horizon desktops and applications send PCoIP data back to an Unified Access Gateway appliance from UDP port 4172 . The destination UDP port will be the source port from the received UDP packets and so as this is reply data, it is normally unnecessary to add an explicit firewall rule for this.
Horizon Agent (unmanaged)*Connection broker instance389TCPAD LDS access during unmanaged agent installation. Note: For other uses of this port, see the note following this table.
Horizon Client*Connection broker or Unified Access Gateway appliance80TCPTLS (HTTPS access) is enabled by default for client connections, but port 80 (HTTP access) can be used in certain cases. See HTTP Redirection in Horizon.
Horizon Client*Connection broker or Unified Access Gateway appliance443TCPHTTPS for logging in to Horizon. (This port is also used for tunneling when tunnel connections are used.)
Horizon Client*Connection broker or Unified Access Gateway appliance4172TCP and UDPPCoIP if PCoIP Secure Gateway is used.
Horizon Client*Horizon Agent3389TCPMicrosoft RDP traffic to Horizon desktops if direct connections are used instead of tunnel connections.
Horizon Client*Horizon Agent9427TCPWindows multimedia redirection, client drive redirection, Microsoft Teams optimization, HTML5 multimedia redirection, printer redirection, and USB redirection, if direct connections are used instead of tunnel connections.
Horizon Client*Horizon Agent32111TCPUSB redirection and time zone synchronization if direct connections are used instead of tunnel connections.
Horizon Client*Horizon Agent4172TCP and UDPPCoIP if PCoIP Secure Gateway is not used. Note: Because the source port varies, see the note following this table.
Horizon Client*Horizon Agent22443TCP and UDPHorizon Blast
Horizon Client*Connection broker or Unified Access Gateway appliance4172TCP and UDPPCoIP (not SALSA20) if PCoIP Secure Gateway is used. Note: Because the source port varies, see the note below this table.
Web Browser*Unified Access Gateway appliance8443TCPHTML Access.
Connection broker*Connection broker48080TCPFor internal communication between Connection broker components.
Connection broker*vCenter Server80TCPSOAP messages if TLS is disabled for access to vCenter Servers.
Connection broker*vCenter Server443TCPSOAP messages if TLS is enabled for access to vCenter Servers.
Connection broker*Connection broker4100TCPJMS inter-router traffic.
Connection broker*Connection broker4101TCPJMS TLS inter-router traffic.
Connection broker*Connection broker8472TCPFor inter-pod communication in Cloud Pod Architecture.
Connection broker*Connection broker22389TCPFor global LDAP replication in Cloud Pod Architecture.
Connection broker*Connection broker32111TCPKey sharing traffic.
Connection broker*Certificate Authority*HTTP, HTTPSCRL or OCSP queries
Unified Access Gateway appliance*Connection broker or load balancer443TCPHTTPS access. Unified Access Gateway appliances connect on TCP port 443 to communicate with a Connection broker instance or load balancer in front of multiple connection broker instances.
Horizon Help Desk Tool*Horizon Agent3389TCPMicrosoft RDP traffic to Horizon desktops for Remote Assistance.

Note: The UDP port number that clients use for PCoIP might change. If port 50002 is in use, the client will pick 50003. If port 50003 is in use, the client will pick port 50004, and so on. You must configure firewalls with ANY where an asterisk (*) is listed in the table.

Note: Microsoft Windows Server requires a dynamic range of ports to be open between all connection brokers in the Horizon environment. These ports are required by Microsoft Windows for the normal operation of Remote Procedure Call (RPC) and Active Directory replication. For more information about the dynamic range of ports, see the Microsoft Windows Server documentation.

Note: On a connection broker instance, port 389 is accessible for infrequent, ad hoc connections. It is accessed when installing an unmanaged agent as shown in the table, and also when using an LDAP editor to directly edit the database, and when issuing commands using a tool such as repadmin. A firewall rule is created for these purposes when AD LDS is installed, but it can be disabled if access to the port is not required.

Note: Horizon Blast Extreme Adaptive Transport reserves some ports starting from ephemeral port range 49152-65535, by default. See KB 52558.

Was this page helpful?

Provide feedback for this topic

Was this topic helpful?

Please do not include any personal or confidential information.

Generating link…