Skip to main content

Port and Protocol Requirements for Deploying Horizon 8 Edge

This page is a reference for all of the possible ports and protocols used for communication for a typical Horizon Edge with Horizon Connection Server. Use this table to ensure your network configuration and firewalls will allow the communication traffic that is required for a successful deployment and for day-to-day operations.

Deployment Specifics

The specific ports and protocols required for your particular deployment will in part depend on which features you select to use for your Horizon Edge deployments. If you do not plan to use Splunk Enterprise for monitoring, you can ignore the ports associated with Splunk Enterprise.

Important: In addition to the ports and protocols described here, a Horizon Edge deployment and the corresponding day-to-day operations have specific DNS requirements. For details, see Make Appropriate Destination URLs Reachable to Deploy a Horizon Edge Gateway in a Horizon 8 Environment.

Ports and Protocols Required by Horizon Edge

When you activate Horizon Infrastructure Monitoring, Horizon Edge is deployed and configured in the associated subscription.

The following table lists the ports and protocols that are needed during the activation process which deploys the appliance and configures the manager VMs so the appliance can collect the monitoring data it is designed to collect from those components. This table also lists the ports and protocols that are needed during steady-state operations of collecting the data the appliance is designed to collect.

Horizon Edge Outbound

SourceTargetPortsProtocolsPurpose
Horizon EdgeUnified Access Gateway VMs9443HTTPSThis port is used when monitoring is enabled for the Unified Access Gateways from the Horizon Control Plane.
Horizon EdgeHorizon Connection Server443HTTPSLicense configuration
Horizon EdgeSplunk Enterprise8000 and 8088HTTP
HTTPS
Monitoring data collection
Horizon EdgeDNS server53 and 853TCP
UDP
DNS services
Horizon Edge*.blob.core.windows.net443TCPUsed for programmatic access to the Azure Blob Storage to replicate images across Horizon 8 Edges. Note that any proxy access restrictions for this endpoint must be relaxed to allow for image replication.
Horizon Edgehorizonedgeprod.azurecr.io443TCPUsed for authentication while downloading Docker images to create the required Horizon Edge modules, which are useful for monitoring, SSO, UAG updates, and such.
Horizon Edge*.azure-devices.net443TCPAppliance used to communicate with the cloud control plane, download configurations for the appliance's module, and update the appliance's module's runtime status. Current concrete endpoints are:

North America:
  • edgehubprodna.azure-devices.net
Europe:
  • edgehubprodeu.azure-devices.net
Japan:
  • edgehubprodjp.azure-devices.net
Horizon Edge*.data.workspaceone.com 443TCPTo send events or metrics to Workspace ONE Intelligence for monitoring data. See Workspace ONE Intelligence product documentation. Concrete endpoints are as follows:
  • eventproxy.na1.data.workspaceone.com
  • eventproxy.eu1.data.workspaceone.com
  • eventproxy.eu2.data.workspaceone.com
  • eventproxy.uk1.data.workspaceone.com
  • eventproxy.ca1.data.workspaceone.com
  • eventproxy.ap1.data.workspaceone.com
  • eventproxy.ap2.data.workspaceone.com
  • eventproxy.au1.data.workspaceone.com
  • eventproxy.in1.data.workspaceone.com
Horizon EdgeNTP Server123UDPNTP services
Horizon EdgeHorizon Connection Server4002TCPHorizon Edge to Horizon Connection Server over Java Messaging Service (JMS).
Horizon Edge softwareupdate.omnissa.com 443TCPUsed to access the CDN to download the required horizon agent installer for image management operations.
Horizon Edgecloud-sg-us-hdc-mqtt.horizon.omnissa.com 443TCP Used by Horizon 8 Edge components to communicate bidirectionally with Horizon Cloud for image management operations and license consumption tracking. Also required for Universal Broker.
Horizon Edgecloud-sg-eu-hdc-mqtt.horizon.omnissa.com 443TCP Used by Horizon 8 Edge components to communicate bidirectionally with Horizon Cloud for image management operations and license consumption tracking. Also required for Universal Broker.
Horizon Edgecloud-sg-jp-hdc-mqtt.horizon.omnissa.com 443TCP Used by Horizon 8 Edge components to communicate bidirectionally with Horizon Cloud for image management operations and license consumption tracking. Also required for Universal Broker.

Horizon Edge Inbound

SourceTargetPortsProtocolsPurpose
Horizon AgentHorizon Edge32198TCP
UDP
Horizon Agent running on a VM can forward diagnostic logs to the Omnissa-managed Azure Blob Storage through the Horizon Edge Gateway.
Horizon AgentHorizon Edge31883TCP
UDP
Horizon agent running on VM to MQTT running on Edge.

VDI Ports and Protocols Requirements

The following table provides the ports and protocols that are required for the desktop (VDI or tenant) subnets configured in your environment.

VDI Ports and Protocols Requirements

SourceTargetPortProtocolPurpose
Desktop (tenant) Subnet
  • eventproxy.na1.data.workspaceone.com
  • eventproxy.eu1.data.workspaceone.com
  • eventproxy.eu2.data.workspaceone.com
  • eventproxy.uk1.data.workspaceone.com
  • eventproxy.ca1.data.workspaceone.com
  • eventproxy.ap1.data.workspaceone.com
  • eventproxy.ap2.data.workspaceone.com
  • eventproxy.au1.data.workspaceone.com
  • eventproxy.in1.data.workspaceone.com
443TCPUsed by Digital Employee Experience (DEX) telemetry agent to send data to Omnissa Intelligence. This is required only for DEX-enabled desktops.
Desktop (tenant) Subnet
  • auth.na1.data.workspaceone.com
  • auth.eu1.data.workspaceone.com
  • auth.eu2.data.workspaceone.com
  • auth.uk1.data.workspaceone.com
  • auth.ca1.data.workspaceone.com
  • auth.ap1.data.workspaceone.com
  • auth.ap2.data.workspaceone.com
  • auth.au1.data.workspaceone.com
  • auth.in1.data.workspaceone.com
443TCPUsed by Digital Employee Experience (DEX) telemetry agent to authenticate with Omnissa Intelligence. This is required only for DEX-enabled desktops.

Was this page helpful?

Provide feedback for this topic

Was this topic helpful?

Please do not include any personal or confidential information.

Generating link…