This page is a reference for all of the possible ports and protocols used for communication for a typical Horizon Edge with Horizon Connection Server. Use this table to ensure your network configuration and firewalls will allow the communication traffic that is required for a successful deployment and for day-to-day operations.
Deployment Specifics
The specific ports and protocols required for your particular deployment will in part depend on which features you select to use for your Horizon Edge deployments. If you do not plan to use Splunk Enterprise for monitoring, you can ignore the ports associated with Splunk Enterprise.
Important: In addition to the ports and protocols described here, a Horizon Edge deployment and the corresponding day-to-day operations have specific DNS requirements. For details, see Make Appropriate Destination URLs Reachable to Deploy a Horizon Edge Gateway in a Horizon 8 Environment.
Ports and Protocols Required by Horizon Edge
When you activate Horizon Infrastructure Monitoring, Horizon Edge is deployed and configured in the associated subscription.
The following table lists the ports and protocols that are needed during the activation process which deploys the appliance and configures the manager VMs so the appliance can collect the monitoring data it is designed to collect from those components. This table also lists the ports and protocols that are needed during steady-state operations of collecting the data the appliance is designed to collect.
Horizon Edge Outbound
| Source | Target | Ports | Protocols | Purpose |
|---|---|---|---|---|
| Horizon Edge | Unified Access Gateway VMs | 9443 | HTTPS | This port is used when monitoring is enabled for the Unified Access Gateways from the Horizon Control Plane. |
| Horizon Edge | Horizon Connection Server | 443 | HTTPS | License configuration |
| Horizon Edge | Splunk Enterprise | 8000 and 8088 | HTTP HTTPS | Monitoring data collection |
| Horizon Edge | DNS server | 53 and 853 | TCP UDP | DNS services |
| Horizon Edge | *.blob.core.windows.net | 443 | TCP | Used for programmatic access to the Azure Blob Storage to replicate images across Horizon 8 Edges. Note that any proxy access restrictions for this endpoint must be relaxed to allow for image replication. |
| Horizon Edge | horizonedgeprod.azurecr.io | 443 | TCP | Used for authentication while downloading Docker images to create the required Horizon Edge modules, which are useful for monitoring, SSO, UAG updates, and such. |
| Horizon Edge | *.azure-devices.net | 443 | TCP | Appliance used to communicate with the cloud control plane, download configurations for the appliance's module, and update the appliance's module's runtime status. Current concrete endpoints are: North America:
|
| Horizon Edge | *.data.workspaceone.com | 443 | TCP | To send events or metrics to Workspace ONE Intelligence for monitoring data.
See Workspace ONE Intelligence product documentation.
Concrete endpoints are as follows:
|
| Horizon Edge | NTP Server | 123 | UDP | NTP services |
| Horizon Edge | Horizon Connection Server | 4002 | TCP | Horizon Edge to Horizon Connection Server over Java Messaging Service (JMS). |
| Horizon Edge | softwareupdate.omnissa.com | 443 | TCP | Used to access the CDN to download the required horizon agent installer for image management operations. |
| Horizon Edge | cloud-sg-us-hdc-mqtt.horizon.omnissa.com | 443 | TCP | Used by Horizon 8 Edge components to communicate bidirectionally with Horizon Cloud for image management operations and license consumption tracking. Also required for Universal Broker. |
| Horizon Edge | cloud-sg-eu-hdc-mqtt.horizon.omnissa.com | 443 | TCP | Used by Horizon 8 Edge components to communicate bidirectionally with Horizon Cloud for image management operations and license consumption tracking. Also required for Universal Broker. |
| Horizon Edge | cloud-sg-jp-hdc-mqtt.horizon.omnissa.com | 443 | TCP | Used by Horizon 8 Edge components to communicate bidirectionally with Horizon Cloud for image management operations and license consumption tracking. Also required for Universal Broker. |
Horizon Edge Inbound
| Source | Target | Ports | Protocols | Purpose |
|---|---|---|---|---|
| Horizon Agent | Horizon Edge | 32198 | TCP UDP | Horizon Agent running on a VM can forward diagnostic logs to the Omnissa-managed Azure Blob Storage through the Horizon Edge Gateway. |
| Horizon Agent | Horizon Edge | 31883 | TCP UDP | Horizon agent running on VM to MQTT running on Edge. |
VDI Ports and Protocols Requirements
The following table provides the ports and protocols that are required for the desktop (VDI or tenant) subnets configured in your environment.
VDI Ports and Protocols Requirements
| Source | Target | Port | Protocol | Purpose |
|---|---|---|---|---|
| Desktop (tenant) Subnet |
| 443 | TCP | Used by Digital Employee Experience (DEX) telemetry agent to send data to Omnissa Intelligence. This is required only for DEX-enabled desktops. |
| Desktop (tenant) Subnet |
| 443 | TCP | Used by Digital Employee Experience (DEX) telemetry agent to authenticate with Omnissa Intelligence. This is required only for DEX-enabled desktops. |
Was this page helpful?