Skip to main content

March 14, 2026

Firewall rules for DMZ-based Unified Access Gateway appliances

DMZ-based Unified Access Gateway appliances require certain firewall rules on the front-end and back-end firewalls. During installation, Unified Access Gateway services are set up to listen on certain network ports by default.

A DMZ-based Unified Access Gateway appliance deployment usually includes two firewalls:

  • An external network-facing, front-end firewall is required to protect both the DMZ and the internal network. You configure this firewall to allow external network traffic to reach the DMZ.
  • A back-end firewall between the DMZ and the internal network is required to provide a second tier of security. You configure this firewall to accept only traffic that originates from the services within the DMZ.

Firewall policy strictly controls inbound communications from DMZ service, which greatly reduces the risk of compromising your internal network.

The following tables list the port requirements for the different services within Unified Access Gateway.

Note: All UDP ports require forward datagrams and reply datagrams to be allowed. Unified Access Gateway services use DNS to resolve hostnames. The DNS server IP addresses are configurable. DNS requests are made on UDP port 53 and so it is important that an external firewall does not block these requests or replies.

Port Requirements for the Secure Email Gateway

PortProtocolSourceTarget/DestinationDescription
443* or any port greater than 1024HTTPSDevices (from Internet and Wi-Fi) Unified Access Gateway Secure Email Gateway endpointSecure Email Gateway listens on port 11443. When 443 or any other port is configured, Unified Access Gateway will internally route the SEG traffic to 11443.
443* or any port greater than 1024HTTPSWorkspace ONE UEM Console Unified Access Gateway Secure Email Gateway endpointSecure Email Gateway listens on port 11443. When 443 or any other port is configured, Unified Access Gateway will internally route the SEG traffic to 11443.
443* or any port greater than 1024HTTPSEmail Notification Service (when enabled) Unified Access Gateway Secure Email Gateway endpointSecure Email Gateway listens on port 11443. When 443 or any other port is configured, Unified Access Gateway will internally route the SEG traffic to 11443.
5701TCPSecure Email GatewaySecure Email GatewayUsed for Hazelcast distributed cache.
41232TLS/TCPSecure Email GatewaySecure Email GatewayUsed for Vertx cluster management.
44444HTTPSSecure Email GatewaySecure Email GatewayUsed for Diagnostic and Administrative functionalities.
AnyHTTPSSecure Email GatewayEmail ServerSEG connects to Email server's listener port, usually 443, to serve email traffic
AnyHTTPSSecure Email GatewayWorkspace ONE UEM API serverSEG fetches the configuration and policy data from Workspace ONE. Port is usually 443.
88TCPSecure Email GatewayKDC Server/AD ServerUsed for fetching Kerberos authentication tokens when KCD authentication is enabled.

Note: As the Secure Email Gateway (SEG) service runs as a non-root user in the Unified Access Gateway, the SEG cannot run on the system ports. Therefore, the custom ports must be greater than port 1024.

Port Requirements for Horizon

PortProtocolSourceTargetDescription
443TCPInternetUnified Access GatewayFor web traffic, Horizon Client XML - API, Horizon Tunnel, and Blast Extreme
443UDPInternetUnified Access GatewayUDP 443 is internally forwarded to UDP 9443 on UDP Tunnel Server service on Unified Access Gateway.
8443UDPInternetUnified Access GatewayBlast Extreme (optional)
8443TCPInternetUnified Access GatewayBlast Extreme (optional)
4172TCP and UDPInternetUnified Access GatewayPCoIP (optional)
443TCPUnified Access GatewayHorizon Connection ServerHorizon Client XML-API, Blast extreme HTML access
22443TCP and UDPUnified Access GatewayDesktops and RDS HostsBlast Extreme
4172TCP and UDPUnified Access GatewayDesktops and RDS HostsPCoIP (optional)
32111TCPUnified Access GatewayDesktops and RDS HostsFramework channel for USB Redirection
3389TCPUnified Access GatewayDesktops and RDS HostsOnly required if the Horizon Clients use the RDP protocol.
9427TCPUnified Access GatewayDesktops and RDS HostsMMR, CDR, and HTML5 features For example, Microsoft Teams Optimization, Browser Redirection, and others.

Note: To allow external client devices to connect to a Unified Access Gateway appliance within the DMZ, the front-end firewall must allow traffic on certain ports. By default, the external client devices and external web clients (HTML Access) connect to a Unified Access Gateway appliance within the DMZ on TCP port 443. If you use the Blast protocol, port 8443 must be open on the firewall. If you use Blast through TCP port 443, there is no need to open TCP 8443 on the firewall.

Port Requirements for Workspace ONE Intelligence Configuration

PortProtocolSourceTargetDescription
443HTTPSUnified Access GatewayWorkspace ONE Intelligence Servercurl -ILvv https://<api_server_hostname>/v1/device/risk_score

curl -ILvv https://<event_server_hostname>/api/v2/protocol/event/a/uag

curl -ILvv https://<auth_server_hostname>/oauth/token?grant_type=client_credentials

The expected response is HTTP 401 unauthorized.

Port Requirements for Web Reverse Proxy

PortProtocolSourceTargetDescription
443TCPInternetUnified Access GatewayFor web traffic
AnyTCPUnified Access GatewayIntranet SiteAny configured custom port on which the Intranet is listening. For example, 80, 443, 8080 and so on.
88TCPUnified Access GatewayKDC Server/AD ServerRequired for Identity Bridging to access AD if SAML to Kerberos/Certificate to Kerberos is configured.
88UDPUnified Access GatewayKDC Server/AD ServerRequired for Identity Bridging to access AD if SAML to Kerberos/Certificate to Kerberos is configured.

Port Requirements for Admin UI

PortProtocolSourceTargetDescription
9443TCPAdmin UIUnified Access GatewayManagement interface

Port Requirements for Content Gateway Basic Endpoint Configuration

PortProtocolSourceTargetDescription
Any port > 1024 or 443*HTTPSDevices (from Internet and Wi-Fi)Unified Access Gateway Content Gateway EndpointIf 443 is used, Content Gateway will listen on port 10443.
Any port > 1024 or 443*HTTPSWorkspace ONE UEM Device ServicesUnified Access Gateway Content Gateway Endpoint
Any port > 1024 or 443*HTTPSWorkspace ONE UEM ConsoleUnified Access Gateway Content Gateway EndpointIf 443 is used, Content Gateway will listen on port 10443.
Any port > 1024 or 443*HTTPSUnified Access Gateway Content Gateway EndpointWorkspace ONE UEM API Server 
Any port where the repository is listening to.HTTP or HTTPSUnified Access Gateway Content Gateway EndpointWeb-based content repositories such as (SharePoint/WebDAV/CMIS, and so onAny configured custom port on which the Intranet site is listening to.
137–139 and 445CIFS or SMBUnified Access Gateway Content Gateway EndpointNetwork Share-based repositories (Windows file shares)SMB based repositories (Distributed file systems, NFS, NetApp OnTap, Nutanix Shares, IBM Share Drives)

Port Requirements for Content Gateway Relay Endpoint Configuration

PortProtocolSourceTarget/DestinationDescription
Any port > 1024 or 443*HTTP/HTTPSUnified Access Gateway Relay Server(Content Gateway Relay)Unified Access Gateway Content Gateway Endpoint*If 443 is used, Content Gateway will listen on port 10443.
Any port > 1024 or 443*HTTPSDevices (from Internet and Wi-Fi)Unified Access Gateway Relay Server(Content Gateway Relay)*If 443 is used, Content Gateway will listen on port 10443.
Any port > 1024 or 443*TCPWorkspace ONE UEM Device ServicesUnified Access Gateway Relay Server(Content Gateway Relay)*If 443 is used, Content Gateway will listen on port 10443.
Any port > 1024 or 443*HTTPSWorkspace ONE UEM ConsoleUnified Access Gateway Relay Server(Content Gateway Relay)*If 443 is used, Content Gateway will listen on port 10443.
Any port > 1024 or 443*HTTPSUnified Access Gateway Content Gateway RelayWorkspace ONE UEM API Server*If 443 is used, Content Gateway will listen on port 10443.
Any port > 1024 or 443*HTTPSUnified Access Gateway Content Gateway EndpointWorkspace ONE UEM API Server*If 443 is used, Content Gateway will listen on port 10443.
Any port where the repository is listening to.HTTP or HTTPSUnified Access Gateway Content Gateway EndpointWeb-based content repositories such as (SharePoint/WebDAV/CMIS, and so onAny configured custom port on which the Intranet site is listening to.
Any port > 1024 or 443*HTTPSUnified Access Gateway (Content Gateway Relay)Unified Access Gateway Content Gateway Endpoint*If 443 is used, Content Gateway will listen on port 10443.
137–139 and 445CIFS or SMBUnified Access Gateway Content Gateway EndpointNetwork Share-based repositories (Windows file shares)SMB based repositories (Distributed file systems, NFS, NetApp OnTap, Nutanix Shares, IBM Share Drives)

Note: Since Content Gateway service runs as a non-root user in Unified Access Gateway, Content Gateway cannot run on system ports and therefore, custom ports should be > 1024.

Port Requirements for Omnissa Workspace ONE Tunnel

PortProtocolSourceTarget/DestinationVerificationNote (See the Note section at the bottom of the page)
8443 *TCP, UDPDevices (from Internet and Wi-Fi) Tunnel Per-App tunnelRun the following command after installation: netstat -tlpn | grep [Port]1

Omnissa Workspace ONE Tunnel Basic Endpoint Configuration

PortProtocolSourceTarget/DestinationVerificationNote (See the Note section at the bottom of the page)
SaaS: 443 : 2001 *HTTPSTunnelAirWatch Cloud Messaging Servercurl -Ivv https://<AWCM URL>:<port>/awcm/status/ping The expected response is
HTTP 200 OK
.
2
SaaS: 443 On-Prem: 80 or 443HTTP or HTTPSTunnelWorkspace ONE UEM REST API Endpoint
  • SaaS:https://asXXX.awmdm. com or https://asXXX. airwatchportals.com
  • On-Prem: Most commonly your DS or Console server
curl -Ivv https://<API URL>/api/mdm/ping The expected response is HTTP 401 unauthorized.5
80,443, any TCPHTTP, HTTPS, or TCPTunnelInternal ResourcesConfirm that the Tunnel can access internal resources over the required port.4
514 *UDP TunnelSyslog Server

Omnissa Workspace ONE Tunnel Cascade Configuration

PortProtocolSourceTarget/DestinationVerificationNote (See the Note section at the bottom of the page)
SaaS: 443 On-Prem: 2001 *TLS v1.2Tunnel Front-EndAirWatch Cloud Messaging ServerVerify by using wget to https://<AWCM URL>:<port>/awcm/status and ensuring you receive an HTTP 200 response.2
8443TLS v1.2Tunnel Front-EndTunnel Back-EndTelnet from Tunnel Front-End to the Tunnel Back-End server on port3
SaaS: 443 On-Prem: 2001TLS v1.2Tunnel Back-EndWorkspace ONE UEM Cloud Messaging ServerVerify by using wget to https://<AWCM URL>:<port>/awcm/status and ensuring you receive an HTTP 200 response.2
80 or 443TCPTunnel Back-EndInternal websites/web apps4
80, 443, any TCPTCPTunnel Back-EndInternal resources4
80 or 443HTTPS Tunnel Front-End and Back-EndWorkspace ONE UEM REST API Endpoint
  • SaaS:https://asXXX.awmdm. com or https://asXXX. airwatchportals.com
  • On-Prem: Most commonly your DS or Console server
curl -Ivv https://<API URL>/api/mdm/ping The expected response is HTTP 401 unauthorized.5

Omnissa Workspace ONE Tunnel Front-end and Back-end Configuration

PortProtocolSourceTarget/DestinationVerificationNote (See the Note section at the bottom of the page)
SaaS: 443 On-Prem: 2001HTTP or HTTPSTunnel Front-EndAirWatch Cloud Messaging Servercurl -Ivv https://<AWCM URL>:<port>/awcm/status/ping The expected response is HTTP 200 OK.2
80 or 443HTTPS or HTTPS Tunnel Back-End and Front-EndWorkspace ONE UEM REST API Endpoint
  • SaaS:https://asXXX.awmdm. com or https://asXXX. airwatchportals.com
  • On-Prem: Most commonly your DS or Console server
curl -Ivv https://<API URL>/api/mdm/ping The expected response is HTTP 401 unauthorized. The Tunnel Endpoint requires access to the REST API Endpoint only during initial deployment.5
2010 *HTTPS Tunnel Front-end Tunnel Back-endTelnet from Tunnel Front-end to the Tunnel Back-end server on port3
80, 443, any TCPHTTP, HTTPS, or TCPTunnel Back-endInternal resourcesConfirm that the Tunnel can access internal resources over the required port.4
514 *UDP TunnelSyslog Server

The following points are valid for the Tunnel requirements.

Note: * - This port can be changed if needed based on your environment's restrictions

  1. If port 443 is used, Per-App Tunnel will listen on port 8443.

    Note: When Tunnel and Content Gateway services are enabled on the same appliance, and TLS Port Sharing is enabled, the DNS names must be unique for each service. When TLS is not enabled only one DNS name can be used for both services as the port will differentiate the incoming traffic. (For Content Gateway, if port 443 is used, Content Gateway will listen on port 10443.)

  2. For the Tunnel to query the Workspace ONE UEM console for compliance and tracking purposes.

  3. For Tunnel Front-end topologies to forward device requests to the internal Tunnel Back-end only.

  4. For applications using Tunnel to access internal resources.

  5. The Tunnel must communicate with the API for initialization. Ensure that there is connectivity between the REST API and the Tunnel server. Navigate to Groups & Settings > All Settings > System > Advanced > Site URLs to set the REST API server URL. This page is not available to SaaS customers. The REST API URL for SaaS customers is most commonly your Console or Devices Services server URL.

Was this page helpful?

Provide feedback for this topic

Was this topic helpful?

Please do not include any personal or confidential information.

Generating link…