To create a Horizon Edge deployment and install or update appliance modules in your Horizon Cloud environment, you must allow the appropriate URLs on the respective ports.
Important: For the tables that follow, the purposes listed are in the context of a Horizon Edge deployment.
Allow URLs for the Management Subnet and Check URL Access
To allow the appropriate URLs and wildcard sub-domains according to your site location and needs, perform the following tasks:
- Allow the URLs and wildcard sub-domains in the table that follows. For example, by adding the URLs and wildcard sub-domain to an allow list for the firewall and network security group.
- Bypass SSL deep packet inspection as follows.
- In the firewall for the URLs and wildcard sub-domains in the table that follows.
- In the proxy server, if applicable.
If the Horizon Edge Gateway is connected to the Horizon Agent through a proxy server, bypass SSL deep packet inspection in the proxy server for the URLs and wildcard sub-domains in the following table.
| Destination (DNS name) | Port | Protocol | Proxy Traffic (if configured on the deployment) | Purpose |
|---|---|---|---|---|
| registry.k8s.io | 443 | TCP | Yes | Used for programmatic access to allow images to download as and when required. Used for downloading Docker images to create the required Horizon Edge modules, which are useful for monitoring, SSO, UAG updates, and such. Note: Applies to Horizon Edge Gateway VM-based deployment 2412 only |
| *.blob.core.windows.net | 443 | TCP | Yes | Used for programmatic access to the Azure Blob Storage and to upload the Horizon Edge logs as and when required. Used for downloading Docker images to create the required Horizon Edge modules, which are useful for monitoring, SSO, UAG updates, and such. |
| horizonedgeprod.azurecr.io | 443 | TCP | Yes | Used for authentication while downloading Docker images to create the required Horizon Edge modules, which are useful for monitoring, SSO, UAG updates, and such. |
|
*.azure-devices.net, or one of the region-specific names that follows, depending on which regional control plane applies to your tenant account: North America:
| 443 | TCP | Yes | Used to connect the appliance to the Horizon Cloud control plane, to download configurations for the appliance's module, and to update the appliance's module's runtime status. |
*.data.workspaceone.com, or one of the region-specific names that follow, depending on which regional Workspace ONE Intelligence target applies to your tenant account:
| 443 | TCP | Yes | Used for sending events or metrics to Workspace ONE Intelligence. See Workspace ONE Intelligence. |
If your firewall or network security group (NSG) supports the use of service tags, apply Azure service tag AzureCloud. If your firewall or NSG does not support the use of service tags, use the host name:monitor.horizon.omnissa.com | 1514 and 1515 | TCP | No | Used for system monitoring. |
| azcopyvnext.azureedge.net | 443 | TCP | Yes | Used to upload deployment logs to Azure Blob Storage for troubleshooting purposes. |
| 443 | HTTPS | Yes | Used for patching Microsoft components of the Horizon Edge Gateway. |
| time.google.com | 123 | UDP | Yes | Used for time synchronization. |
| 80 | HTTP | Yes | Used for patching Ubuntu components. |
| *.file.core.windows.net | 445 | TCP | No | Access to fileshares provisioned for the App Volumes workflows of importing packages and replicating the packages across fileshares. |
| softwareupdate.omnissa.com | 443 | TCP | No | Software package server. Used for downloading updates of the agent-related software used in the system's image-related operations and automated agent update process. |
| download.falco.org | 443 | HTTPS | No | Used by the security monitoring tool Falco for checking and downloading the latest resources required for it to function properly. |
| *.cloudfront.net | 443 | HTTPS | No | Used by the security monitoring tool Falco for checking and downloading the latest resources required for it to function properly. |
Allow URL for Tenant (Desktop) Subnet
You can allow a URL for a tenant (desktop) subnet at the global VM hub level or at the regional VM hub level.
To allow pool creation in Horizon Cloud with a proxy specified, then in the tenant’s deployed subnet to the control plane, perform the following:
-
Allow the URLs and wildcard sub-domains in the tables that follow. For example, by adding the URLs and wildcard sub-domain to an allow list for the firewall and network security group.
-
Bypass SSL deep packet inspection as follows.
- In the firewall for the URLs and wildcard sub-domains in the table that follows.
- In the proxy server, if applicable.
If the Horizon Edge Gateway is connected to the Horizon Agent through a proxy server, bypass SSL deep packet inspection in the proxy server for the URLs and wildcard sub-domains in the following table.
Allow URL for Tenant (Desktop) Subnet - Global VM Hub DNS Hostname
If using a global VM Hub instance suits the needs of your site, when you deploy a Horizon Edge Gateway, allow the following URL and its settings.
| Destination (DNS Name) | Port | Protocol | Purpose |
|---|---|---|---|
| *.horizon.omnissa.com | 443 | TCP | For agent related operations, such as certificate signing using VM Hub and renewal. |
Allow URLs for the Tenant (Desktop) Subnet - Regional VM Hub DNS Hostnames
If using regional VM Hub instances suits the needs of your site, when you deploy a Horizon Edge Gateway in a given region, use the two corresponding URLs, as indicated.
The port, protocol, and purpose for each regional VM Hub instance matches those for a global VM Hub instance, as such.
| Port | 443 |
| Protocol | TCP |
| Purpose | For agent related operations, such as certificate signing using VM Hub and renewal. |
| For the Following Azure Regions | Allow the Following Destination (DNS Name) URLs |
|---|---|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
Allow URLs for Proxy Enablement
If you plan to use a proxy server to control the traffic flow from your environment, open the required ports to allow the Horizon Edge Gateway to reach the proxy server. When the format of your Microsoft Azure Edge is Edge Gateway (AKS), see Outbound network and FQDN rules for Azure Kubernetes Service (AKS) clusters.
Using IP Addresses Instead of URLs
For situations where using URLs is not possible, see KB 6000374 - IP Addresses for Service Components.
Was this page helpful?