This page is a reference for all of the possible ports and protocols used for communication within a typical Horizon Cloud on Amazon WorkSpaces Core deployment in Horizon Cloud. Use these tables to ensure your network configuration and firewalls will allow the communication traffic that is required for a successful deployment and for day-to-day operations.
Deployment Specifics
The specific ports and protocols required for your particular deployment will in part depend on which features you select to use for your Horizon Cloud on Amazon Workspaces Core deployment. If you do not plan to use a specific component or protocol, then its required communication traffic is not necessary for your purposes, and you can ignore the ports associated with that component.
Important: In addition to the ports and protocols described here, a Horizon Edge deployment and the corresponding day-to-day operations have specific DNS requirements. For details, see Make Appropriate Destination URLs Reachable to Deploy a Horizon Edge Gateway in an Amazon Workspaces Core Environment.
Ports and Protocols Required by Horizon Edge
When you activate Horizon Infrastructure Monitoring, Horizon Edge is deployed and configured in the associated subscription. The following table lists the ports and protocols that are needed during the activation process which deploys the appliance and configures the manager VMs so the appliance can collect the monitoring data it is designed to collect from those components. This table also lists the ports and protocols that are needed during steady-state operations of collecting the data the appliance is designed to collect.
| Source | Target | Ports | Protocols | Purpose |
|---|---|---|---|---|
| Horizon Edge | Unified Access Gateway VMs | 9443 | HTTPS | This port is used by the Edge VM over the Management subnet to configure settings in the Edge's Unified Access Gateway configuration. This port requirement applies when initially deploying a Unified Access Gateway configuration and when editing an Edge to add a Unified Access Gateway configuration or update settings for that Unified Access Gateway configuration also monitor the session statistics from the Unified Access Gateway. |
| Horizon Edge | Domain controller | Kerberos: 88 LDAP: 389, 3268 LDAPS: 636, 3269 | TCP UDP | Registering your Horizon Cloud with Domain and for SSO login and periodic discovery of domain controllers. These ports are required for LDAP or LDAPS services when LDAP/LDAPS will be specified in that workflow. LDAP is the default for most tenants. Target is the server that contains a domain controller role in the Active Directory configuration. |
| Horizon Edge | AD Certificate Services | 135 and a port within the range of 49152 to 65535 | TCP (RPC) | Connecting to the Microsoft Enterprise Certificate Authority (AD CS) to obtain short-lived certificates for True SSO. The Horizon Edge uses TCP port 135 for the initial RPC communication, then a port within the range 49152 - 65535 to communicate with AD CS (Azure Directory Certificate Services). |
| Horizon Edge | DNS server | 53 and 853 | TCP UDP | DNS services. |
| Horizon Edge |
| 443 | TCP | Used for programmatic access to the Azure Blob Storage and to upload the Horizon Edge logs as and when required. Used for downloading Docker images to create the required Horizon Edge modules, which are useful for monitoring, SSO, UAG updates, and such. |
| Horizon Edge | horizonedgeprod.azurecr.io | 443 | TCP | Used for authentication while downloading Docker images to create the required Horizon Edge modules, which are useful for monitoring, SSO, UAG updates, and such. |
| Horizon Edge | *.azure-devices.net | 443 | TCP | Appliance used to communicate with the cloud control plane, download configurations for the appliance's module, and update the appliance's module's runtime status. Current concrete endpoints are: North America:
|
| Horizon Edge | *.data.workspaceone.com | 443 | TCP | To send events or metrics to Workspace ONE Intelligence for monitoring data.
See Workspace ONE Intelligence product documentation.
Concrete endpoints are as follows:
|
| Horizon Edge | login.microsoftonline.com | 443 | TCP | Generally used by applications to authenticate against Microsoft Azure service. |
| Horizon Edge |
Region Specific: *.horizon.omnissa.com US
| 443 | TCP | Appliance used to communicate with the cloud control plane and for Day2 operations. |
| Horizon Edge Gateway (single VM type) | NTP server | 123 | UDP | NTP services |
Unified Access Gateway VM Ports and Protocols Requirements
In addition to the primary ports and protocols requirements listed in the table above, the ports and protocols in the following tables are related to the gateways that you have configured to operate for ongoing operations after deployment.
For connections configured with Unified Access Gateway instances, traffic must be allowed to and from the Unified Access Gateway instances to targets listed in the table below.
Notes:
- This guidance comes from the Unified Access Gateway documentation: for these service-deployed Unified Access Gateway instances, the UDP ports require both forward and reply UDP datagrams to be allowed. For example, Unified Access Gateway services use DNS to resolve hostnames. DNS requests to the instances are made on UDP port 53 and so it is important that an external firewall does not block these requests or replies.
- The Unified Access Gateway is deployed on a multi-NIC configuration. The Source Network column in the table that follows details which network the traffic comes from.
Port Requirements for Traffic from Unified Access Gateway Instances
| Source | Target | Port | Source Network | Protocol | Purpose |
|---|---|---|---|---|---|
| Unified Access Gateway | *.horizon.omnissa.com | 443 | DMZ network | TCP UDP | Unified Access Gateway needs to be able to resolve these addresses at any time or the user will not be able to launch the session, because the Unified Access Gateway fetches the JWK set from:cloud-sg-<region>-r-<DC>.horizon.omnissa.com. The endpoints are as follows:
|
| Unified Access Gateway | DNS server | 53 and 853 | Any | TCP UDP | DNS services. |
| Unified Access Gateway | Horizon agent in the desktop or farm RDSH VMs | 22443 | Tenant Network | TCP UDP | Blast Extreme By default, when using Blast Extreme, client-drive redirection (CDR) traffic and USB traffic are side-channeled in this port. If preferred, the CDR traffic can be separated onto the TCP 9427 port and the USB redirection traffic can be separated onto the TCP 32111 port. |
| Unified Access Gateway | Horizon agent in the desktop or farm RDSH VMs | 9427 | Tenant Network | TCP | Optional for CDR and multimedia redirection (MMR) traffic. |
| Unified Access Gateway | Horizon agent in the desktop or farm RDSH VMs | 32111 | Tenant Network | TCP | Optional for USB redirection traffic. |
| Unified Access Gateway | NTP server The default value is time.google.com. However, you can freely change this value. | 123 | DMZ Network | UDP | NTP services |
| Unified Access Gateway | *.blob.core.windows.net *.blob.storage.azure.net | 443 | DMZ Network | TCP | Used for programmatic access to the Azure Blob Storage to upload the Unified Access Gateway logs as and when required. |
App Volumes Ports and Protocols
To support App Volumes features for use with Horizon Cloud on Amazon WorkSpaces Core, you must configure port 445 for TCP protocol traffic to the tenant (desktops) subnet. Port 445 is the standard SMB port for accessing an SMB file share on Microsoft Windows. The AppStacks are stored in an SMB file share located in the same resource group as the pod manager VMs.
Note: If you use a self-managed Active Directory, on-premises or in the cloud, to manage identities and devices, you can add an FSx for Windows File Server file system to the Active Directory domain. See AWS documentation about using a self-managed Microsoft Active Directory.
Port Requirements for App Volumes
| Source | Target | Port | Protocol | Purpose |
|---|---|---|---|---|
| App Volumes agent in the base imported VM, the golden images, desktop VMs, farm RDSH VMs | The IP address of the Amazon FSx for Windows File Server | 445 | TCP | App Volumes application virtualization on the VDI machines and application package capture on the VDI machines depend on access to the fileshares. |
VDI Ports and Protocols Requirements
The following table provides the ports and protocols that are required for the desktop (VDI or tenant) subnets configured in your environment.
VDI Ports and Protocols Requirements
| Source | Target | Port | Protocol | Purpose |
|---|---|---|---|---|
| Desktop (tenant) Subnet | *.horizon.omnissa.com | 443 | TCP MQTT | For agent-related operations, such as certificate signing using VM Hub and renewal. Current concrete endpoints are: US:
|
| Desktop (tenant) Subnet | Domain controller | 88 | TCP UDP | Kerberos services. The target is the server that contains a domain controller role in an Active Directory configuration. Registering the Edge an Active Directory is a requirement. |
| Desktop (tenant) Subnet | Domain controller | Kerberos: 88 LDAP: 389, 3268 LDAPS: 636, 3269 | TCP UDP | These ports are required for LDAP or LDAPS services for VM to domain controller connectivity, in case the VDI is unable to reach any domain controller, then session launch is not possible. |
| Desktop (tenant) Subnet | DNS Server | 53 and 853 | TCP UDP | DNS Services |
| Desktop (tenant) Subnet | NTP server | 123 | UDP | NTP services |
| Desktop (tenant) Subnet | *.blob.core.windows.net | 443 | TCP | DCT log bundle upload. When a customer admin clicks on the DCT log collection for any VM after request processing, the bundle will be uploaded from VDI to blob to make that bundle available to download from the Horizon Universal Console. |
| Desktop (tenant) Subnet | Horizon Edge | 31883 | TCP MQTT UDP | Horizon agent running on VM to MQTT running on Edge. |
| Desktop (tenant) Subnet | Horizon Edge | 32443 | TCP | Single Sign-On for your Amazon WorkSpaces Core Edge. |
| Desktop (tenant) Subnet and Management Subnet | softwareupdate.omnissa.com | 443 | TCP | Software package server. Used for downloading updates of the agent-related software used in the system's image-related operations and automated agent update process. Note The management subnet is required for the softwareupdate target only if you plan to use the management subnet for importing and publishing images. |
| Desktop (tenant) Subnet | Private Link Endpoint | 443 | TCP | Desktop connectivity to the connection service in the cloud control plane. |
| Desktop (tenant) Subnet and Management Subnet | AD Certificate Services | 135 and 445 and a port within the range of 49152 to 65535 | TCP (RPC) | To add desktops to domain. |
| Desktop (tenant) Subnet | CRL distribution point (CDP) Examples: Or
| 80 | TCP | The bootstrapping process for the VM involves sending an HTTP POST request to the Horizon Cloud endpoint. To establish a secure connection, a Certificate Revocation List (CRL) check is performed. If this check is not permitted through the internet, VM customization fails. |
| Desktop (tenant) Subnet |
| 443 | TCP | Used by Digital Employee Experience (DEX) telemetry agent to send data to Omnissa Intelligence. This is required only for DEX-enabled desktops. |
| Desktop (tenant) Subnet |
| 443 | TCP | Used by Digital Employee Experience (DEX) telemetry agent to authenticate with Omnissa Intelligence. This is required only for DEX-enabled desktops. |
| Desktop (tenant) Subnet | *.horizon.omnissa.com | 443 | TCP UDP | Successfully registers WorkSpaces Core desktops to Horizon Cloud. |
End-User Connection Traffic Ports and Protocols Requirements
For detailed information about the various Horizon Clients that your end users might use with your Horizon Edge Virtual Appliance, see the Horizon Client product documentation. Which ports must be opened for traffic from the end users' connections to reach their virtual desktops and remote applications depends on the choice you make for how your end users will connect.
End User Connection Traffic Ports and Protocols
| Source | Target | Port | Protocol | Purpose |
|---|---|---|---|---|
| Horizon Client | AWS load balancer for these Unified Access Gateway instances | 443 | TCP | To carry CDR, MMR, USB redirection, and tunneled RDP traffic. SSL (HTTPS access) is enabled by default for client connections. Port 80 (HTTP access) can be used in some cases. |
| Horizon Client | AWS load balancer for these Unified Access Gateway instances | 8443 or 443 | TCP | Blast Extreme via Blast Secure Gateway on Unified Access Gateway for data traffic from Horizon Client. The port used, 8443 or 443, is defined when the Horizon Edge Gateway is deployed. |
| Horizon Client | AWS load balancer for these Unified Access Gateway instances | 443 | UDP | Blast Extreme via the Unified Access Gateway for data traffic. |
| Horizon Client | AWS load balancer for these Unified Access Gateway instances | 8443 | UDP | Blast Extreme via Blast Secure Gateway on Unified Access Gateway for data traffic (adaptive transport). |
| Browser | AWS load balancer for these Unified Access Gateway instances | 443 | TCP | To carry CDR, MMR, USB redirection, and tunneled RDP traffic. SSL (HTTPS access) is enabled by default for client connections. Port 80 (HTTP access) can be used in some cases. |
| Browser | AWS load balancer for these Unified Access Gateway instances | 8443 or 443 | TCP | Blast Extreme via Blast Secure Gateway on Unified Access Gateway for data traffic from the Horizon Web Client. |
| Horizon Client/Browser | *.horizon.omnissa.com | 443 | TCP | See the table for allowing URLs for the tenant subnet – regional VM hub DNS hostnames in Make Appropriate Destination URLs Reachable to Deploy a Horizon Edge Gateway in an Amazon WorkSpaces Core Environment. Regarding the URLs listed in that table, after logging in and listing the launch items, when an end user clicks to launch a desktop, the redirection of the protocol traffic to Unified Access Gateway occurs from one of those URLs based on the region in which the specified VM is located. You must allowlist URLs listed in that table based on the global regions from which you deliver desktops and applications. In the table, the client needs access to the Service Gateway URL for each relevant region, such as the following: |
| Horizon Client/Browser | cloud.omnissahorizon.com | 443 | TCP | If you have a restricted network, you must allowlist the appropriate URLs to enable end users to access their applications and desktops. See Launch a Desktop with Horizon Client. If you have customized the Client Access URL as described in Configure Client Settings, ensure that your custom URL is also added to your allowlist. |
Was this page helpful?