Skip to main content

August 24, 2026

Firewall Rules for Omnissa Horizon Connection Server

Certain ports must be opened on the firewall for Horizon Connection Server instances.

When you install Horizon Connection Server, the installation application can optionally configure the required Windows Firewall rules for you. These rules open the ports that are used by default. If you change the default ports after installation, you must manually configure Windows Firewall to allow Omnissa Horizon Client devices to connect to Omnissa Horizon 8 through the updated ports.

The following table lists the default ports that can be opened automatically during installation. Ports are incoming unless otherwise noted.

Ports Opened During Horizon Connection Server Installation
ProtocolPortsHorizon Connection Server Instance Type
JMSTCP 4001Standard and replica
JMSTCP 4002Standard and replica
JMSIRTCP 4100Standard and replica
JMSIRTCP 4101Standard and replica
AJP13TCP 8009Standard and replica
HTTPTCP 80Standard, replica
HTTPSTCP 443Standard, replica
PCoIPTCP 4172 in; UDP 4172 both directionsStandard, replica
HTTPSTCP 8443 UDP 8443Standard, replica After the initial connection to Horizon 8 is made, the Web browser or client device connects to the Blast Secure Gateway on TCP port 8443. The Blast Secure Gateway must be enabled on a Horizon Connection Server instance to allow this second connection to take place.
HTTPSTCP 8472Standard and replica For the Cloud Pod Architecture feature: used for inter-pod communication.
HTTPTCP 22389Standard and replica For the Cloud Pod Architecture feature: used for global LDAP replication.

Was this page helpful?

Provide feedback for this topic

Was this topic helpful?

Please do not include any personal or confidential information.

Generating link…