Skip to main content

Make Appropriate Destination URLs Reachable to Deploy a Horizon Edge Gateway in a Horizon 8 Environment

To create a Horizon Edge deployment and install or update appliance modules, you must allow the appropriate URLs on the respective ports.

Important: For the table that follows, the listed purposes are in the context of a Horizon Edge Gateway with Horizon Connection Server.

Allow URLs for the Management Subnet

Allow the appropriate URLs and wildcard subdomains according to your site location and needs. More specifically, perform the following tasks.

  • Allow the URLs and wildcard subdomains in the table that follows. For example, by adding the URLs and wildcard subdomain to an allow list for the firewall.
  • Bypass SSL deep packet inspection as follows.
    • In the firewall for the URLs and wildcard subdomains in the table that follows.

    • In the proxy server, if applicable.

      If the Horizon Edge Gateway is connected to the Horizon Cloud control plane through a proxy server, bypass SSL deep packet inspection in the proxy server for the URLs and wildcard subdomains in the table that follows.

Destination (DNS name)PortProtocolPurpose
registry.k8s.io443TCPUsed for programmatic access to allow images to download as and when required. Used for downloading Docker images to create the required Horizon Edge modules, which are useful for monitoring, SSO, UAG updates, and such.

Note: Applies to Horizon Edge Gateway deployment 2412 only.
*.blob.core.windows.net443TCPUsed for programmatic access to the Azure Blob Storage and to upload the Horizon Edge logs as and when required. Used for downloading Docker images to create the required Horizon Edge modules, which are useful for monitoring, SSO, UAG updates, and such.
horizonedgeprod.azurecr.io443TCPUsed for authentication while downloading Docker images to create the required Horizon Edge modules, which are useful for monitoring, SSO, UAG updates, and such.
*.azure-devices.net, or one of the region-specific names that follows, depending on which regional control plane applies to your tenant account

North America:
  • edgehubprodna.azure-devices.net
Europe:
  • edgehubprodeu.azure-devices.net
Japan:
  • edgehubprodjp.azure-devices.net
443TCP (requirement means HTTP, HTTPS, and WSS)Used to connect the appliance to the Horizon Cloud control plane, to download configurations for the appliance's module, and to update the appliance's module's runtime status.
*.data.workspaceone.com, or one of the region-specific names that follow, depending on which regional Workspace ONE Intelligence target applies to your tenant account:
  • eventproxy.na1.data.workspaceone.com
  • eventproxy.eu1.data.workspaceone.com
  • eventproxy.eu2.data.workspaceone.com
  • eventproxy.uk1.data.workspaceone.com
  • eventproxy.ca1.data.workspaceone.com
  • eventproxy.ap1.data.workspaceone.com
  • eventproxy.ap2.data.workspaceone.com
  • eventproxy.au1.data.workspaceone.com
  • eventproxy.in1.data.workspaceone.com
443TCPUsed for sending events or metrics to Workspace ONE Intelligence.

Using IP Addresses Instead of URLs

For situations where using URLs is not possible, see KB 6000374 - IP Addresses for Service Components.

Was this page helpful?

Provide feedback for this topic

Was this topic helpful?

Please do not include any personal or confidential information.

Generating link…