DMZ-based Unified Access Gateway appliances require certain firewall rules on the front-end and back-end firewalls. During installation, Unified Access Gateway services are set up to listen on certain network ports by default.
A DMZ-based Unified Access Gateway appliance deployment usually includes two firewalls:
- An external network-facing, front-end firewall is required to protect both the DMZ and the internal network. You configure this firewall to allow external network traffic to reach the DMZ.
- A back-end firewall between the DMZ and the internal network is required to provide a second tier of security. You configure this firewall to accept only traffic that originates from services within the DMZ.
Firewall policy strictly controls inbound communications from DMZ services, which greatly reduces the risk of compromising your internal network.
The following tables list the port requirements for the different services within Unified Access Gateway.
Port Requirements for the Secure Email Gateway
| Port | Protocol | Source | Target/Destination | Description |
|---|---|---|---|---|
| 443 or any configured SEG server listener port* | HTTPS | Devices (from Internet and Wi-Fi) | Unified Access Gateway Secure Email Gateway endpoint | Secure Email Gateway listens on port 11443. When 443 or any other listener port is configured, Unified Access Gateway will internally route the SEG traffic to 11443. |
| 443 or any configured SEG server listener port* | HTTPS | Workspace ONE UEM Console | Unified Access Gateway Secure Email Gateway endpoint | |
| 443 or any configured SEG server listener port* | HTTPS | Email Notification Service (when enabled) | Unified Access Gateway Secure Email Gateway endpoint | |
| 5701 | TCP | Secure Email Gateway | Secure Email Gateway | Used for Hazelcast distributed cache. |
| 41232 | TLS/TCP | Secure Email Gateway | Secure Email Gateway | Used for Vertx cluster management. |
| 44444 | HTTPS | Secure Email Gateway | Secure Email Gateway | Used for Diagnostic and Administrative functionalities. |
| Any | HTTPS | Secure Email Gateway | Email Server | SEG connects to Email server's listener port, usually 443, to serve email traffic |
| Any | HTTPS | Secure Email Gateway | Workspace ONE UEM API server | SEG fetches the configuration and policy data from Workspace ONE. Port is usually 443. |
| 88 | TCP | Secure Email Gateway | KDC Server/AD Server | Used for fetching Kerberos authentication tokens when KCD authentication is enabled. |
Port Requirements for Horizon
| Port | Protocol | Source | Target | Description |
|---|---|---|---|---|
| 443 | TCP | Internet | Unified Access Gateway | For web traffic, Horizon Client XML - API, Horizon Tunnel, and Blast Extreme |
| 443 | UDP | Internet | Unified Access Gateway | UDP 443 is internally forwarded to UDP 9443 on UDP Tunnel Server service on Unified Access Gateway. |
| 8443 | UDP | Internet | Unified Access Gateway | Blast Extreme (optional) |
| 8443 | TCP | Internet | Unified Access Gateway | Blast Extreme (optional) |
| 4172 | TCP and UDP | Internet | Unified Access Gateway | PCoIP (optional) |
| 443 | TCP | Unified Access Gateway | Horizon Connection Server | Horizon Client XML-API, Blast extreme Horizon Web Client |
| 22443 | TCP and UDP | Unified Access Gateway | Desktops and RDS Hosts | Blast Extreme |
| 4172 | TCP and UDP | Unified Access Gateway | Desktops and RDS Hosts | PCoIP (optional) |
| 32111 | TCP | Unified Access Gateway | Desktops and RDS Hosts | Framework channel for USB Redirection |
| 3389 | TCP | Unified Access Gateway | Desktops and RDS Hosts | Only required if the Horizon Clients use the RDP protocol. |
| 9427 | TCP | Unified Access Gateway | Desktops and RDS Hosts | MMR, CDR, and HTML5 features For example, Microsoft Teams Optimization, Browser Redirection, and others. |
Port Requirements for Workspace ONE Intelligence Configuration
| Port | Protocol | Source | Target | Description |
|---|---|---|---|---|
| Any | HTTPS | Unified Access Gateway | Workspace ONE Intelligence Server | curl -ILvv https://<api_server_hostname>/v1/device/risk_score
curl -ILvv https://<event_server_hostname>/api/v2/protocol/event/a/uag
curl -ILvv https://<auth_server_hostname>/oauth/token?grant_type=client_credentials
The expected response is HTTP 401 unauthorized. |
Port Requirements for OPSWAT Integration
| Port | Protocol | Source | Target | Description |
|---|---|---|---|---|
| Any | HTTPS | Unified Access Gateway | OPSWAT Server | curl -v https://gears.opswat.com/o/oauth/token
curl -v https://gears.opswat.com//o/api/v3.3/devices/detail
curl -v https://gears.opswat.com//o/api/v3.1/account
The expected response is HTTP 401 unauthorized or HTTP 302 redirect. |
Port Requirements for Web Reverse Proxy
| Port | Protocol | Source | Target | Description |
|---|---|---|---|---|
| 443 | TCP | Internet | Unified Access Gateway | For web traffic |
| Any | TCP | Unified Access Gateway | Intranet Site | Any configured custom port on which the Intranet is listening. For example, 80, 443, 8080 and so on. |
| 88 | TCP | Unified Access Gateway | KDC Server/AD Server | Required for Identity Bridging to access AD if SAML to Kerberos/Certificate to Kerberos is configured. |
| 88 | UDP | Unified Access Gateway | KDC Server/AD Server | Required for Identity Bridging to access AD if SAML to Kerberos/Certificate to Kerberos is configured. |
Port Requirements for Admin UI
| Port | Protocol | Source | Target | Description |
|---|---|---|---|---|
| 9443 | TCP | Admin UI | Unified Access Gateway | Management interface |
Port Requirements for SSH
| Port | Protocol | Source | Target | Description |
|---|---|---|---|---|
| 22 or any other as configured during deployment | SSH | SSH Client | Unified Access Gateway | When SSH is enabled on Unified Access Gateway, port 22 is used by default. The administrator can change the value to any other preferred port at the time of deployment. For more information, see PowerShell deployment parameters and Deploying to vSphere using the OVF Template Wizard. |
Port Requirements for Content Gateway Basic Endpoint Configuration
| Port | Protocol | Source | Target | Description |
|---|---|---|---|---|
| 443 or any configured CG endpoint port* | HTTPS | Devices (from Internet and Wi-Fi) | Unified Access Gateway Content Gateway Endpoint | This is the port on which Content Gateway server is listening to the traffic. This refers to Content Gateway Endpoint Port under Content Gateway Configuration in the WorkspaceONE UEM console when the configuration type is set to BASIC.
If 443 is used, Content Gateway server will listen on port 10443. Unified Access Gateway will internally redirect traffic from 443 to 10443. |
| 443 or any configured CG endpoint port* | HTTPS | Workspace ONE UEM Device Services | Unified Access Gateway Content Gateway Endpoint | |
| 443 or any configured CG endpoint port* | HTTPS | Workspace ONE UEM Console | Unified Access Gateway Content Gateway Endpoint | |
| Any | HTTPS | Unified Access Gateway Content Gateway Endpoint | Workspace ONE UEM API Server | |
| Any port where the repository is listening to. | HTTP or HTTPS | Unified Access Gateway Content Gateway Endpoint | Web-based content repositories such as (SharePoint/WebDAV/CMIS, and so on | Any configured custom port on which the Intranet site is listening to. |
| 137–139 and 445 | CIFS or SMB | Unified Access Gateway Content Gateway Endpoint | Network Share-based repositories (Windows file shares) | SMB based repositories (Distributed file systems, NFS, NetApp OnTap, Nutanix Shares, IBM Share Drives) |
Port Requirements for Content Gateway Relay Endpoint Configuration
| Port | Protocol | Source | Target/Destination | Description |
|---|---|---|---|---|
| 443 or any configured CG Endpoint port* | HTTP/HTTPS | Unified Access Gateway Relay Server(Content Gateway Relay) | Unified Access Gateway Content Gateway Endpoint | This is the port on which Content Gateway Endpoint server is listening to the traffic. This refers to Content Gateway Endpoint Port under Content Gateway Configuration at WorkspaceONE UEM console when configuration type is set to RELAY.
If 443 is used, Content Gateway Endpoint server will listen on port 10443. Unified Access Gateway will internally redirect the traffic from 443 to 10443. |
| 443 or any configured CG Relay port* | HTTPS | Devices (from Internet and Wi-Fi) | Unified Access Gateway Relay Server(Content Gateway Relay) | This is the port on which Content Gateway Relay server is listening to the traffic. This refers to Content Gateway Relay Port under Content Gateway Configuration at WorkspaceONE UEM console when configuration type is set to RELAY. Default value is 443.
If 443 is used, Content Gateway Relay server will listen on port 10443. Unified Access Gateway will internally redirect the traffic from 443 to 10443. |
| 443 or any configured CG Relay port* | TCP | Workspace ONE UEM Device Services | Unified Access Gateway Relay Server(Content Gateway Relay) | |
| 443 or any configured CG Relay port* | HTTPS | Workspace ONE UEM Console | Unified Access Gateway Relay Server(Content Gateway Relay) | |
| Any | HTTPS | Unified Access Gateway Content Gateway Relay | Workspace ONE UEM API Server | |
| Any | HTTPS | Unified Access Gateway Content Gateway Endpoint | Workspace ONE UEM API Server | |
| HTTP or HTTPS | Unified Access Gateway Content Gateway Endpoint | Web-based content repositories such as (SharePoint/WebDAV/CMIS, and so on | Any configured custom port on which the Intranet site is listening to. | |
| 137–139 and 445 | CIFS or SMB | Unified Access Gateway Content Gateway Endpoint | Network Share-based repositories (Windows file shares) | SMB based repositories (Distributed file systems, NFS, NetApp OnTap, Nutanix Shares, IBM Share Drives) |
Port Requirements for Tunnel
| Port | Protocol | Source | Target/Destination | Verification | Note (See the Note section at the bottom of the page) |
|---|---|---|---|---|---|
| 8443 * | TCP, UDP | Devices | Tunnel Per-App tunnel | Run the following command after installation: netstat -tlpn | grep [Port] | 1 |
Tunnel Basic Endpoint Configuration
| Port | Protocol | Source | Target/Destination | Verification | Note (See the Note section at the bottom of the page) |
|---|---|---|---|---|---|
| SaaS: 443 : 2001 * | HTTPS | Tunnel | AirWatch Cloud Messaging Server | curl -Ivv https://<AWCM URL>:<port>/awcm/status/ping
The expected response is
. | 2 |
| SaaS: 443 On-Prem: 80 or 443 | HTTP or HTTPS | Tunnel | Workspace ONE UEM REST API Endpoint
| curl -Ivv https://<API URL>/api/mdm/ping
The expected response is HTTP 401 unauthorized. | 5 |
| 80,443, any TCP | HTTP, HTTPS, or TCP | Tunnel | Internal Resources | Confirm that the Tunnel can access internal resources over the required port. | 4 |
| 514 * | UDP | Tunnel | Syslog Server |
Tunnel Cascade Configuration
| Port | Protocol | Source | Target/Destination | Verification | Note (See the Note section at the bottom of the page) |
|---|---|---|---|---|---|
| SaaS: 443 On-Prem: 2001 * | TLS v1.2 | Tunnel Front-End | AirWatch Cloud Messaging Server | Verify by using wget to https://<AWCM URL>:<port>/awcm/status and ensuring you receive an HTTP 200 response. | 2 |
| 8443 | TLS v1.2 | Tunnel Front-End | Tunnel Back-End | Telnet from Tunnel Front-End to the Tunnel Back-End server on port | 3 |
| SaaS: 443 On-Prem: 2001 | TLS v1.2 | Tunnel Back-End | Workspace ONE UEM Cloud Messaging Server | Verify by using wget to https://<AWCM URL>:<port>/awcm/status and ensuring you receive an HTTP 200 response. | 2 |
| 80 or 443 | TCP | Tunnel Back-End | Internal websites/web apps | 4 | |
| 80, 443, any TCP | TCP | Tunnel Back-End | Internal resources | 4 | |
| 80 or 443 | HTTPS | Tunnel Front-End and Back-End | Workspace ONE UEM REST API Endpoint
| curl -Ivv https://<API URL>/api/mdm/ping
The expected response is HTTP 401 unauthorized. | 5 |
Tunnel Front-end and Back-end Configuration
| Port | Protocol | Source | Target/Destination | Verification | Note (See the Note section at the bottom of the page) |
|---|---|---|---|---|---|
| SaaS: 443 On-Prem: 2001 | HTTP or HTTPS | Tunnel Front-End | AirWatch Cloud Messaging Server | curl -Ivv https://<AWCM URL>:<port>/awcm/status/ping
The expected response is HTTP 200 OK. | 2 |
| 80 or 443 | HTTPS or HTTPS | Tunnel Back-End and Front-End | Workspace ONE UEM REST API Endpoint
| curl -Ivv https://<API URL>/api/mdm/ping
The expected response is HTTP 401 unauthorized.
The Tunnel Endpoint requires access to the REST API Endpoint only during initial deployment. | 5 |
| 2010 * | HTTPS | Tunnel Front-end | Tunnel Back-end | Telnet from Tunnel Front-end to the Tunnel Back-end server on port | 3 |
| 80, 443, any TCP | HTTP, HTTPS, or TCP | Tunnel Back-end | Internal resources | Confirm that the Tunnel can access internal resources over the required port. | 4 |
| 514 * | UDP | Tunnel | Syslog Server |
The following points are valid for the Tunnel requirements.
- If port 443 is used, Per-App Tunnel will listen on port 8443.
2. For the Tunnel to query the Workspace ONE UEM console for compliance and tracking purposes. 3. For Tunnel Front-end topologies to forward device requests to the internal Tunnel Back-end only. 4. For applications using Tunnel to access internal resources. 5. The Tunnel must communicate with the API for initialization. Ensure that there is connectivity between the REST API and the Tunnel server. Navigate to Groups & Settings > All Settings > System > Advanced > Site URLs to set the REST API server URL. This page is not available to SaaS customers. The REST API URL for SaaS customers is most commonly your Console or Devices Services server URL.
Was this page helpful?