Skip to main content

March 14, 2026

Firewall Rules for DMZ-Based Unified Access Gateway Appliances

DMZ-based Unified Access Gateway appliances require certain firewall rules on the front-end and back-end firewalls. During installation, Unified Access Gateway services are set up to listen on certain network ports by default.

A DMZ-based Unified Access Gateway appliance deployment usually includes two firewalls:

  • An external network-facing, front-end firewall is required to protect both the DMZ and the internal network. You configure this firewall to allow external network traffic to reach the DMZ.
  • A back-end firewall between the DMZ and the internal network is required to provide a second tier of security. You configure this firewall to accept only traffic that originates from the services within the DMZ.

Firewall policy strictly controls inbound communications from DMZ service, which greatly reduces the risk of compromising your internal network.

The following tables list the port requirements for the different services within Unified Access Gateway.

Note: All UDP ports require forward datagrams and reply datagrams to be allowed.

Port Requirements for the Secure Email Gateway

PortProtocolSourceTarget/DestinationDescription
443* or any port greater than 1024HTTPSDevices (from Internet and Wi-Fi) Unified Access Gateway Secure Email Gateway endpointSecure Email Gateway listens on port 11443
443* or any port greater than 1024HTTPSWorkspace ONE UEM Console Unified Access Gateway Secure Email Gateway endpointSecure Email Gateway listens on port 11443
443* or any port greater than 1024HTTPSEmail Notification Service (when enabled) Unified Access Gateway Secure Email Gateway endpointSecure Email Gateway listens on port 11443
5701HTTPSecure Email GatewaySecure Email GatewayUsed for Hazelcast distributed cache
41232HTTPSSecure Email GatewaySecure Email GatewayUsed for Vertx cluster management
44444HTTPSSecure Email GatewaySecure Email GatewayUsed for Diagnostic and Administrative functionalities

Note: As the Secure Email Gateway (SEG) service runs as a non-root user in the Unified Access Gateway, the SEG cannot run on the system ports. Therefore, the custom ports must be greater than port 1024.

Port Requirements for Horizon

PortProtocolSourceTargetDescription
443TCPInternetUnified Access GatewayFor web traffic, Horizon Client XML - API, Horizon Tunnel, and Blast Extreme
443UDPInternetUnified Access GatewayUDP 443 is internally forwarded to UDP 9443 on UDP Tunnel Server service on Unified Access Gateway.
8443UDPInternetUnified Access GatewayBlast Extreme (optional)
8443TCPInternetUnified Access GatewayBlast Extreme (optional)
4172TCP and UDPInternetUnified Access GatewayPCoIP (optional)
443TCPUnified Access GatewayHorizon Connection ServerHorizon Client XML-API, Blast extreme HTML access, Horizon Air Console Access (HACA)
22443TCP and UDPUnified Access GatewayDesktops and RDS HostsBlast Extreme
4172TCP and UDPUnified Access GatewayDesktops and RDS HostsPCoIP (optional)
32111TCPUnified Access GatewayDesktops and RDS HostsFramework channel for USB Redirection
3389TCPUnified Access GatewayDesktops and RDS HostsOnly required if the Horizon Clients use the RDP protocol.
9427TCPUnified Access GatewayDesktops and RDS HostsMMR, CDR, and HTML5 features For example, Microsoft Teams Optimization, Browser Redirection, and others.

Note: To allow external client devices to connect to a Unified Access Gateway appliance within the DMZ, the front-end firewall must allow traffic on certain ports. By default the external client devices and external web clients (HTML Access) connect to a Unified Access Gateway appliance within the DMZ on TCP port 443. If you use the Blast protocol, port 8443 must be open on the firewall, but you can configure Blast for port 443 as well.

Port Requirements for Web Reverse Proxy

PortProtocolSourceTargetDescription
443TCPInternetUnified Access GatewayFor web traffic
AnyTCPUnified Access GatewayIntranet SiteAny configured custom port on which the Intranet is listening. For example, 80, 443, 8080 and so on.
88TCPUnified Access GatewayKDC Server/AD ServerRequired for Identity Bridging to access AD if SAML to Kerberos/Certificate to Kerberos is configured.
88UDPUnified Access GatewayKDC Server/AD ServerRequired for Identity Bridging to access AD if SAML to Kerberos/Certificate to Kerberos is configured.

Port Requirements for Admin UI

PortProtocolSourceTargetDescription
9443TCPAdmin UIUnified Access GatewayManagement interface

Port Requirements for Content Gateway Basic Endpoint Configuration

PortProtocolSourceTargetDescription
443* or any port > 1024HTTPSDevices (from Internet and Wi-Fi)Unified Access Gateway Content Gateway EndpointIf 443 is used, Content Gateway will listen on port 10443.
443* or any port > 1024HTTPSWorkspace ONE UEM Device ServicesUnified Access Gateway Content Gateway Endpoint
443* or any port > 1024HTTPSWorkspace ONE UEM ConsoleUnified Access Gateway Content Gateway EndpointIf 443 is used, Content Gateway will listen on port 10443.
443* or any port > 1024HTTPSUnified Access Gateway Content Gateway EndpointWorkspace ONE UEM API Server 
Any port where the repository is listening to.HTTP or HTTPSUnified Access Gateway Content Gateway EndpointWeb-based content repositories such as (SharePoint/WebDAV/CMIS, and so onAny configured custom port on which the Intranet site is listening to.
137–139 and 445CIFS or SMBUnified Access Gateway Content Gateway EndpointNetwork Share-based repositories (Windows file shares)Intranet Shares

Port Requirements for Content Gateway Relay Endpoint Configuration

PortProtocolSourceTarget/DestinationDescription
443* or any port > 1024HTTP/HTTPSUnified Access Gateway Relay Server(Content Gateway Relay)Unified Access Gateway Content Gateway EndpointIf 443 is used, Content Gateway will listen on port 10443.
443* or any port > 1024HTTPSDevices (from Internet and Wi-Fi)Unified Access Gateway Relay Server(Content Gateway Relay)If 443 is used, Content Gateway will listen on port 10443.
443* or any port > 1024TCPWorkspace ONE UEM Device ServicesUnified Access Gateway Relay Server(Content Gateway Relay)If 443 is used, Content Gateway will listen on port 10443.
443* or any port > 1024HTTPSWorkspace ONE UEMConsole
443* or any port > 1024HTTPSUnified Access Gateway Content Gateway RelayWorkspace ONE UEM API Server 
443* or any port > 1024HTTPSUnified Access Gateway Content Gateway EndpointWorkspace ONE UEM API Server 
Any port where the repository is listening to.HTTP or HTTPSUnified Access Gateway Content Gateway EndpointWeb-based content repositories such as (SharePoint/WebDAV/CMIS, and so onAny configured custom port on which the Intranet site is listening to.
443* or any port > 1024HTTPSUnified Access Gateway (Content Gateway Relay)Unified Access Gateway Content Gateway EndpointIf 443 is used, Content Gateway will listen on port 10443.
137–139 and 445CIFS or SMBUnified Access Gateway Content Gateway EndpointNetwork Share-based repositories (Windows file shares)Intranet Shares

Note: Since Content Gateway service runs as a non-root user in Unified Access Gateway, Content Gateway cannot run on system ports and therefore, custom ports should be > 1024.

Port Requirements for Tunnel

PortProtocolSourceTarget/DestinationVerificationNote (See the Note section at the bottom of the page)
2020 *HTTPSDevices (from Internet and Wi-Fi)Tunnel ProxyRun the following command after installation: netstat -tlpn | grep [Port]
8443 *TCP, UDPDevices (from Internet and Wi-Fi)Tunnel Per-App tunnelRun the following command after installation: netstat -tlpn | grep [Port]1

Tunnel Basic Endpoint Configuration

PortProtocolSourceTarget/DestinationVerificationNote (See the Note section at the bottom of the page)
SaaS: 443 : 2001 *HTTPSTunnelWorkspace ONE UEMCloud Messaging Servercurl -Ivv https://<AWCM URL>:<port>/awcm/status/ping The expected response is HTTP 200 OK.2
SaaS: 443 On-Prem: 80 or 443HTTP or HTTPSTunnelWorkspace ONE UEM REST API Endpoint
  • SaaS:https://asXXX.awmdm. com or https://asXXX. airwatchportals.com
  • On-Prem: Most commonly your DS or Console server
curl -Ivv https://<API URL>/api/mdm/ping The expected response is HTTP 401 unauthorized.5
80,443, any TCPHTTP, HTTPS, or TCPTunnelInternal ResourcesConfirm that the Tunnel can access internal resources over the required port.4
514 *UDPTunnelSyslog Server
On-prem: 2020HTTPSWorkspace ONE UEM ConsoleTunnel ProxyOn-Premises users can test the connection using the telnet command :telnet <Tunnel Proxy URL> <port>6

Tunnel Cascade Configuration

PortProtocolSourceTarget/DestinationVerificationNote (See the Note section at the bottom of the page)
SaaS: 443 On-Prem: 2001 *TLS v1.2Tunnel Front-EndWorkspace ONE UEM Cloud Messaging ServerVerify by using wget to https://<AWCM URL>:<port>/awcm/status and ensuring you receive an HTTP 200 response.2
8443TLS v1.2Tunnel Front-EndTunnel Back-EndTelnet from Tunnel Front-End to the Tunnel Back-End server on port3
SaaS: 443 On-Prem: 2001TLS v1.2Tunnel Back-EndWorkspace ONE UEM Cloud Messaging ServerVerify by using wget to https://<AWCM URL>:<port>/awcm/status and ensuring you receive an HTTP 200 response.2
80 or 443TCPTunnel Back-EndInternal websites/web apps4
80, 443, any TCPTCPTunnel Back-EndInternal resources4
80 or 443HTTPSTunnel Front-End and Back-EndWorkspace ONE UEM REST API Endpoint
  • SaaS:https://asXXX.awmdm. com or https://asXXX. airwatchportals.com
  • On-Prem: Most commonly your DS or Console server
curl -Ivv https://<API URL>/api/mdm/ping The expected response is HTTP 401 unauthorized.5

Tunnel Front-end and Back-end Configuration

PortProtocolSourceTarget/DestinationVerificationNote (See the Note section at the bottom of the page)
SaaS: 443 On-Prem: 2001HTTP or HTTPSTunnel Front-EndWorkspace ONE UEM Cloud Messaging Servercurl -Ivv https://<AWCM URL>:<port>/awcm/status/ping The expected response is HTTP 200 OK.2
80 or 443HTTPS or HTTPSTunnel Back-End and Front-EndWorkspace ONE UEM REST API Endpoint
  • SaaS:https://asXXX.awmdm. com or https://asXXX. airwatchportals.com
  • On-Prem: Most commonly your DS or Console server
curl -Ivv https://<API URL>/api/mdm/ping The expected response is HTTP 401 unauthorized. The Tunnel Endpoint requires access to the REST API Endpoint only during initial deployment.5
2010 *HTTPSTunnel Front-endTunnel Back-endTelnet from Tunnel Front-end to the Tunnel Back-end server on port3
80, 443, any TCPHTTP, HTTPS, or TCPTunnel Back-endInternal resourcesConfirm that the Tunnel can access internal resources over the required port.4
514 *UDPTunnelSyslog Server
On-Prem: 2020HTTPSWorkspace ONE UEMTunnel ProxyOn-Premises users can test the connection using the telnet command :telnet <Tunnel Proxy URL> <port>6

The following points are valid for the Tunnel requirements.

Note: * - This port can be changed if needed based on your environment's restrictions

  1. If port 443 is used, Per-App Tunnel will listen on port 8443.

    Note: When Tunnel and Content Gateway services are enabled on the same appliance, and TLS Port Sharing is enabled, the DNS names must be unique for each service. When TLS is not enabled only one DNS name can be used for both services as the port will differentiate the incoming traffic. (For Content Gateway, if port 443 is used, Content Gateway will listen on port 10443.)

  2. For the Tunnel to query the Workspace ONE UEM console for compliance and tracking purposes.

  3. For Tunnel Front-end topologies to forward device requests to the internal Tunnel Back-end only.

  4. For applications using Tunnel to access internal resources.

  5. The Tunnel must communicate with the API for initialization. Ensure that there is connectivity between the REST API and the Tunnel server. Navigate to Groups & Settings > All Settings > System > Advanced > Site URLs to set the REST API server URL. This page is not available to SaaS customers. The REST API URL for SaaS customers is most commonly your Console or Devices Services server URL.

  6. This is required for a successful "Test Connection" to the Tunnel Proxy from the Workspace ONE UEM console. The requirement is optional and can be omitted without loss of functionality to devices. For SaaS customers, the Workspace ONE UEM console might already have inbound connectivity to the Tunnel Proxy on port 2020 due to the inbound Internet requirement on port 2020.

Was this page helpful?

Provide feedback for this topic

Was this topic helpful?

Please do not include any personal or confidential information.

Generating link…