Skip to main content

Make Appropriate Destination URLs Reachable to Deploy a Horizon Edge Gateway in a Microsoft Azure Environment

To create a Horizon Edge deployment and install or update appliance modules in your Horizon Cloud environment, you must allow the appropriate URLs on the respective ports.

Important: For the tables that follow, the purposes listed are in the context of a Horizon Edge deployment.

Allow URLs for the Management Subnet and Check URL Access

To allow the appropriate URLs and wildcard sub-domains according to your site location and needs, perform the following tasks:

  • Allow the URLs and wildcard sub-domains in the table that follows. For example, by adding the URLs and wildcard sub-domain to an allow list for the firewall and network security group.
  • Bypass SSL deep packet inspection as follows.
    • In the firewall for the URLs and wildcard sub-domains in the table that follows.
    • In the proxy server, if applicable.

If the Horizon Edge Gateway is connected to the Horizon Agent through a proxy server, bypass SSL deep packet inspection in the proxy server for the URLs and wildcard sub-domains in the following table.

Destination (DNS name)PortProtocolProxy Traffic (if configured on the deployment)Purpose
registry.k8s.io443TCPYesUsed for programmatic access to allow images to download as and when required. Used for downloading Docker images to create the required Horizon Edge modules, which are useful for monitoring, SSO, UAG updates, and such.

Note: Applies to Horizon Edge Gateway VM-based deployment 2412 only

*.blob.core.windows.net443TCPYesUsed for programmatic access to the Azure Blob Storage and to upload the Horizon Edge logs as and when required. Used for downloading Docker images to create the required Horizon Edge modules, which are useful for monitoring, SSO, UAG updates, and such.
horizonedgeprod.azurecr.io443TCPYesUsed for authentication while downloading Docker images to create the required Horizon Edge modules, which are useful for monitoring, SSO, UAG updates, and such.
*.azure-devices.net, or one of the region-specific names that follows, depending on which regional control plane applies to your tenant account:

North America:
  • edgehubprodna.azure-devices.net
Europe:
  • edgehubprodeu.azure-devices.net
Japan:
  • edgehubprodjp.azure-devices.net
443TCPYesUsed to connect the appliance to the Horizon Cloud control plane, to download configurations for the appliance's module, and to update the appliance's module's runtime status.
*.data.workspaceone.com, or one of the region-specific names that follow, depending on which regional Workspace ONE Intelligence target applies to your tenant account:
  • eventproxy.na1.data.workspaceone.com
  • eventproxy.eu1.data.workspaceone.com
  • eventproxy.eu2.data.workspaceone.com
  • eventproxy.uk1.data.workspaceone.com
  • eventproxy.ca1.data.workspaceone.com
  • eventproxy.ap1.data.workspaceone.com
  • eventproxy.ap2.data.workspaceone.com
  • eventproxy.au1.data.workspaceone.com
  • eventproxy.in1.data.workspaceone.com
443TCPYesUsed for sending events or metrics to Workspace ONE Intelligence. See Workspace ONE Intelligence.
If your firewall or network security group (NSG) supports the use of service tags, apply Azure service tag AzureCloud. If your firewall or NSG does not support the use of service tags, use the host name:
monitor.horizon.omnissa.com
1514 and 1515TCPNoUsed for system monitoring.
azcopyvnext.azureedge.net443TCPYesUsed to upload deployment logs to Azure Blob Storage for troubleshooting purposes.
  • management.azure.com
  • login.microsoftonline.com
  • mcr.microsoft.com
  • *.data.mcr.microsoft.com
  • packages.microsoft.com
  • packages.aks.azure.com
443HTTPSYesUsed for patching Microsoft components of the Horizon Edge Gateway.
time.google.com123UDPYesUsed for time synchronization.
  • security.ubuntu.com
  • azure.archive.ubuntu.com
  • changelogs.ubuntu.com
  • motd.ubuntu.com
80HTTPYesUsed for patching Ubuntu components.
*.file.core.windows.net445TCPNoAccess to fileshares provisioned for the App Volumes workflows of importing packages and replicating the packages across fileshares.
softwareupdate.omnissa.com 443 TCPNoSoftware package server. Used for downloading updates of the agent-related software used in the system's image-related operations and automated agent update process.
download.falco.org443 HTTPSNoUsed by the security monitoring tool Falco for checking and downloading the latest resources required for it to function properly.
*.cloudfront.net443 HTTPSNoUsed by the security monitoring tool Falco for checking and downloading the latest resources required for it to function properly.

Allow URL for Tenant (Desktop) Subnet

You can allow a URL for a tenant (desktop) subnet at the global VM hub level or at the regional VM hub level.

To allow pool creation in Horizon Cloud with a proxy specified, then in the tenant’s deployed subnet to the control plane, perform the following:

  • Allow the URLs and wildcard sub-domains in the tables that follow. For example, by adding the URLs and wildcard sub-domain to an allow list for the firewall and network security group.

  • Bypass SSL deep packet inspection as follows.

    • In the firewall for the URLs and wildcard sub-domains in the table that follows.
    • In the proxy server, if applicable.

If the Horizon Edge Gateway is connected to the Horizon Agent through a proxy server, bypass SSL deep packet inspection in the proxy server for the URLs and wildcard sub-domains in the following table.

Allow URL for Tenant (Desktop) Subnet - Global VM Hub DNS Hostname

If using a global VM Hub instance suits the needs of your site, when you deploy a Horizon Edge Gateway, allow the following URL and its settings.

Destination (DNS Name)PortProtocolPurpose
*.horizon.omnissa.com 443TCPFor agent related operations, such as certificate signing using VM Hub and renewal.

Allow URLs for the Tenant (Desktop) Subnet - Regional VM Hub DNS Hostnames

If using regional VM Hub instances suits the needs of your site, when you deploy a Horizon Edge Gateway in a given region, use the two corresponding URLs, as indicated.

The port, protocol, and purpose for each regional VM Hub instance matches those for a global VM Hub instance, as such.

Port443
ProtocolTCP
PurposeFor agent related operations, such as certificate signing using VM Hub and renewal.
For the Following Azure RegionsAllow the Following Destination (DNS Name) URLs
  • westus2
  • usgovarizona
  • usgovtexas
  • westus
  • westus3
  • westcentralus
  • centralus
  • Service Gateway: cloud-sg-us-r-westus2.horizon.omnissa.com
  • MQTT: cloud-sg-us-r-westus2-mqtt.horizon.omnissa.com
  • eastus2
  • eastus
  • usgovvirginia
  • southcentralus
  • northcentralus
  • canadacentral
  • canadaeast
  • brazilsouth
  • brazilsoutheast
  • mexicocentral
  • Service Gateway: cloud-sg-us-r-eastus2.horizon.omnissa.com
  • MQTT: cloud-sg-us-r-eastus2-mqtt.horizon.omnissa.com
  • northeurope
  • norwaywest
  • norwayeast
  • uaecentral
  • uaenorth
  • westeurope
  • Service Gateway: cloud-sg-eu-r-northeurope.horizon.omnissa.com
  • MQTT: cloud-sg-eu-r-northeurope-mqtt.horizon.omnissa.com
  • uksouth
  • ukwest
  • Service Gateway: cloud-sg-eu-r-uksouth.horizon.omnissa.com
  • MQTT: cloud-sg-eu-r-uksouth-mqtt.horizon.omnissa.com
  • germanywestcentral
  • germanynorth
  • swedencentral
  • swedensouth
  • francecentral
  • francesouth
  • switzerlandnorth
  • switzerlandwest
  • italynorth
  • israelcentral
  • polandcentral
  • spaincentral
  • qatarcentral
  • Service Gateway: cloud-sg-eu-r-germanywestcentral.horizon.omnissa.com
  • MQTT: cloud-sg-eu-r-germanywestcentral-mqtt.horizon.omnissa.com
  • japanwest
  • japaneast
  • koreacentral
  • Service Gateway: cloud-sg-jp-r-japaneast.horizon.omnissa.com
  • MQTT: cloud-sg-jp-r-japaneast-mqtt.horizon.omnissa.com
  • australiaeast
  • australiacentral
  • australiacentral2
  • australiasoutheast
  • newzealandnorth
  • southafricanorth
  • Service Gateway: cloud-sg-jp-r-australiaeast.horizon.omnissa.com
  • MQTT: cloud-sg-jp-r-australiaeast-mqtt.horizon.omnissa.com
  • centralindia
  • jioindiawest
  • jioindiacentral
  • southindia
  • westindia
  • indonesiacentral
  • Service Gateway: cloud-sg-jp-r-centralindia.horizon.omnissa.com
  • MQTT: cloud-sg-jp-r-centralindia-mqtt.horizon.omnissa.com

Allow URLs for Proxy Enablement

If you plan to use a proxy server to control the traffic flow from your environment, open the required ports to allow the Horizon Edge Gateway to reach the proxy server. When the format of your Microsoft Azure Edge is Edge Gateway (AKS), see Outbound network and FQDN rules for Azure Kubernetes Service (AKS) clusters.

Using IP Addresses Instead of URLs

For situations where using URLs is not possible, see KB 6000374 - IP Addresses for Service Components.

Was this page helpful?

Provide feedback for this topic

Was this topic helpful?

Please do not include any personal or confidential information.

Generating link…