Skip to main content

May 28, 2026

TCP and UDP Ports for Clients and Agents

Note: Horizon Web Client is available with Horizon 8 versions 2412 and later. For Horizon 8 versions 2406 and earlier, Horizon Web Client is called "HTML Access." This documentation page uses the name "Horizon Web Client" to refer to both Horizon Web Client and HTML Access.

Horizon Agent and Horizon Client use TCP and UDP ports for network access between each other and certain server components.

You can find addtional information on this topic in Network Ports in Horizon 8.

TCP and UDP Ports That Horizon Agent Uses

SourcePortTargetPortProtocolDescription
Horizon Client*Horizon Agent3389TCPMicrosoft RDP traffic to remote desktops when direct connections are used instead of tunnel connections.
Horizon Client*Horizon Agent9427TCPWindows multimedia redirection, client drive redirection, Microsoft Teams optimization, HTML5 multimedia redirection, Horizon printer redirection, and USB redirection when direct connections are used instead of tunnel connections. Note: Not needed for client drive redirection when using Horizon Blast.
Horizon Client*Horizon Agent32111TCPUSB redirection and time zone synchronization when direct connections are used instead of tunnel connections.
Horizon Client*Horizon Agent4172TCP and UDPPCoIP when PCoIP Secure Gateway is not used. Note: Because the source port varies, see the note below this table.
Horizon Client*Horizon Agent22443TCP and UDPHorizon Blast when direct connections are used instead of tunnel connections. Note: UDP is not used on Linux desktops.
Browser*Horizon Agent22443TCPHorizon Web Client when direct connections are used instead of tunnel connections.
Connection Server or Unified Access Gateway appliance*Horizon Agent3389TCPMicrosoft RDP traffic to remote desktops when tunnel connections are used.
Connection Server or Unified Access Gateway appliance*Horizon Agent9427TCPWindows multimedia redirection, client drive redirection, Microsoft Teams optimization, HTML5 multimedia redirection, Horizon printer redirection, and USB redirection when tunnel connections are used.
Connection Server or Unified Access Gateway appliance*Horizon Agent32111TCPUSB redirection and time zone synchronization when tunnel connections are used.
Connection Server or Unified Access Gateway appliance55000Horizon Agent4172UDPPCoIP (not SALSA20) when PCoIP Secure Gateway is used.
Connection Server or Unified Access Gateway appliance*Horizon Agent4172TCPPCoIP when PCoIP Secure Gateway is used.
Connection Server or Unified Access Gateway appliance*Horizon Agent22443TCP and UDPHorizon Blast when Blast Secure Gateway is used. Note: UDP is not used on Linux desktops.
Connection Server or Unified Access Gateway appliance*Horizon Agent22443TCPHorizon Web Client when Blast Secure Gateway is used.
Horizon Agent*Connection Server4001, 4002TCPJMS SSL traffic.
Horizon Agent4172Horizon Client*UDPPCoIP when PCoIP Secure Gateway is not used. Note: Because the target port varies, see the note below this table.
Horizon Agent4172Connection Server or Unified Access Gateway appliance55000UDPPCoIP (not SALSA20) when PCoIP Secure Gateway is used.

Note: The UDP port number that agents use for PCoIP might change. If port 50002 is in use, the agent uses port 50003. If port 50003 is in use, the agent uses port 50004, and so on. You must configure firewalls with ANY where an asterisk (*) is listed in the table.

TCP and UDP Ports That Horizon Client Uses

SourcePortTargetPortProtocolDescription
Horizon Client*Connection Server or Unified Access Gateway appliance443TCPHTTPS for logging in to Horizon. This port is also used for tunneling when tunnel connections are used. Note: Horizon Client supports UDP port 443.
Horizon Client*Unified Access Gateway appliance443UDP HTTPS for logging into Horizon when Blast Secure Gateway is used and UDP Tunnel Server is enabled. This port is also used for tunneling when tunnel connections are used.
Unified Access Gateway appliance443Horizon Client*UDP HTTPS for logging into Horizon when Blast Secure Gateway is used and UDP Tunnel Server is enabled. This port is also used for tunneling when tunnel connections are used.
Horizon Client*Horizon Agent22443TCPHorizon Web Client and Horizon Blast when Blast Secure Gateway is not used.
Horizon Client*Horizon Agent22443UDP Horizon Blast when Blast Secure Gateway is not used. Note: Not used when connecting to Linux desktops.
Horizon Agent22443Horizon Client*UDP Horizon Blast when Blast Secure Gateway is not used. Note: Not used when connecting to Linux desktops.
Horizon Client*Horizon Agent3389TCPMicrosoft RDP traffic to remote desktops if direct connections are used instead of tunnel connections.
Horizon Client*Horizon Agent9427TCPWindows multimedia redirection, client drive redirection, Microsoft Teams optimization, HTML5 multimedia redirection, Horizon printer redirection, and USB redirection when direct connections are used instead of tunnel connections. Note: Not needed for client drive redirection when using Horizon Blast.
Horizon Client*Horizon Agent32111TCPUSB redirection and time zone synchronization when direct connections are used instead of tunnel connections.
Horizon Client*Horizon Agent4172TCP and UDPPCoIP if PCoIP Secure Gateway is not used. Note: Because the source port varies, see the note below this table.
Horizon Client*Connection Server or Unified Access Gateway appliance4172TCP and UDPPCoIP (not SALSA20) when PCoIP Secure Gateway is used. Note: Because the source port varies, see the note below this table.
Horizon Agent4172Horizon Client*UDPPCoIP if PCoIP Secure Gateway is not used. Note: Because the target port varies, see the note below this table.
Connection Server or Unified Access Gateway appliance4172Horizon Client*UDPPCoIP (not SALSA20) when PCoIP Secure Gateway is used. Note: Because the target port varies, see the note below this table.
Horizon Client*Connection Server or Unified Access Gateway appliance8443TCPHorizon Web Client and Horizon Blast when Blast Secure Gateway is used.
Horizon Client*Connection Server or Unified Access Gateway appliance8443UDPHorizon Blast when Blast Secure Gateway is used. Note: Not used when connecting to a Linux desktop.
Connection Server or Unified Access Gateway appliance8443Horizon Client*UDPHorizon Blast when Blast Secure Gateway is used. Note: Not used when connecting to a Linux desktop.

Note: The UDP port number that clients use for PCoIP and Horizon Blast might change. If port 50002 is in use, the client selects port 50003, and if port 50003 is in use, the client selects port 50004, and so on. You must configure firewalls with ANY where an asterisk (*) is listed in the table.

Was this page helpful?

Provide feedback for this topic

Was this topic helpful?

Please do not include any personal or confidential information.

Generating link…