Skip to main content

August 24, 2026

Configure Omnissa Horizon Blast Reverse Connection and Message Validation

You can configure Horizon Blast to make an outbound TCP connection (referred to as a "reverse connection") from the Agent system to a Blast Secure Gateway running on UAG. By adding a gateway certificate, you can verify that messages are authorized by UAG and have not been tampered with.

Note: This feature is supported in Omnissa Horizon 8 version 2206 and later.

Procedure

  1. Enable the feature in UAG.

    1. In the UAG appliance, go to General Settings and select Edge Service Settings > Horizon Settings.

    2. Click the Settings (gear) icon, then select Enable Horizon.

    3. In the Horizon Settings pane, turn Enable XML Signing to ON and click More to expand the pane.

    4. Select the following options: Enable Horizon Blast and Blast Reverse Connection Enabled.

    5. Select Blast Reverse Connection URL Inside and change the port numbert to 8444.

    6. Click Save.

  2. Add the certificate.

    1. Go to Omnissa Horizon > Settings > Servers.

    2. Select the Gateway Certificate tab.

    3. Click Add.

    4. In the Add Certificate dialog, enter a name you want to use to identify the certificate, and copy the certificate details in PEM format into the Certificate field. Click OK.

  3. Launch the desktop or application pool from the Client.

  4. Check the following:

    • In the registry editor, ReverseConnectionEnabled should be set to 1. This ensures that the reverse connection registry is added to the Horizon Blast configuration registry.
    • For Reverse Connection Verification, make sure that port 8444 is established from the Agent to UAG, and that the Horizon Blast Worker Log shows that the Horizon Blast Reverse Connection is enabled and upgraded successfully.

BEAT Support

  • Reverse Connection supports BEAT protocol. Both Agent and UAG must be 2512 or later for BEAT support.
  • For BEAT Reverse Connections, ensure that UDP connectivity from the Agent to the UAG is outbound-only. If UDP exchanges fail, BEAT will either fall back or fail, depending on network behavior.
  • BEAT-Specific Verification: Confirm successful BEAT transport activation on Reverse Connection in the Blast Worker log.

Was this page helpful?

Provide feedback for this topic

Was this topic helpful?

Please do not include any personal or confidential information.

Generating link…