Skip to main content

October 7, 2026

Configure Network Settings for Amazon WorkSpaces Core

For Horizon Cloud, your deployment requires subnet support in the Amazon WorkSpaces Core region, which requires the existence of a Virtual Private Cloud (VPC) in that region.

Create a VPC in an Amazon WorkSpaces Core region with applicable address space for the required subnets and NAT IPs.

Note: Horizon Cloud supports two deployment types for the Horizon Edge on Amazon WorkSpaces Core - Single Virtual Machine and Elastic Kubernetes Service. In addition to the three networking subnets described in the following section, the EKS deployment type requires an additional management subnet, as described in the subsequent section.

Creating Management, Tentant, and DMZ Subnets

Create three non-overlapping subnet address ranges in classless inter-domain routing (CIDR) format in the VPC. The following subnet requirements are minimum. For larger environments, larger subnets might be necessary.

  1. Create the Management subnet - /26 minimum

    If deploying an Edge Gateway and using a NAT Gateway as the outbound connectivity type, configure a NAT Gateway. Also, ensure that the Management subnet does not conflict with the following IP ranges:

    • 169.254.0.0/16
    • 172.30.0.0/16
    • 172.31.0.0/16
    • 192.0.2.0/24
  2. Create two Desktop (tenant) subnets in two different availability zones.

    For the primary desktop (tenant) subnet, create /27 minimum subnets, but size appropriately based on the number of desktops and RDS servers. You can add more subnets as required.

    Note: If you are using an internal load balancer, ensure that all VM subnets for your desktop VMs fall in the IP ranges described in RFC1918.

  3. Create the DMZ subnet.

    Create /27 minimum subnets for the cluster of Unified Access Gateway.

    Note: Deploying a Unified Access Gateway requires three subnets. Each Unified Access Gateway VM has three NICs, one from each subnet. The external load balancer backend pool is attached to the DMZ subnet NICs. The internal load balancer backend pool is attached to the desktop subnet NICs. Verify that there are no network security groups (NSGs) or firewall rules blocking ingress to the DMZ network from the internet. The only NSGs that Omnissa deploys are ones attached to the NICs (not subnet) and by default allow ingress. Any firewall or NSG rules blocking incoming traffic from the internet to the DMZ NICs will cause issues when attempting to connect to the Unified Access Gateways through the external load balancer.

Configuring Networking for Amazon Elastic Kubernetes Service (EKS) for the Edge Deployment Type

To support Elastic Kubernetes Service (EKS) as your Horizon Edge Gateway deployment type, you must add additional permissions and trust relationship to the admin role as described in Create IAM Policy and Roles.

You must also add an additional Management subnet.

For deploying the EKS control plane and managed node deployment, AWS needs 2 management subnets in different availability zones to ensure high availability. For related information, see VPC requirements and considerations in Amazon EKS product documentation.

  • For the VPC setting, click DNS settings and enable the Enable DNS resolution and Enable DNS hostnames check boxes.

  • For the NAT gateway setting, associate your new Management subnet.

  • In the DHCP option on VPC, add the following details, which are required for communication between nodes and the control plane:

    • domain-name: ec2.internal
    • domain-name-servers: AmazonProvidedDNS, ,

To ensure that the DNS resolution for the AD domain goes to AD DNS server, perform the following steps:

  • Ensure VPCs are connected through VPC Peering or Transit Gateway and that the Edge VPC can reach the AD DNS server.

  • Open the AWS Management Console, go to the Route 53 console, and in the navigation pane select Resolver and then choose Outbound endpoints.

  • Create an outbound endpoint using the following settings:

    • VPC: Select the Edge VPC.

    • Subnet: Choose one or more subnets in different availability zones.

    • Security group: Allow inbound port 53 (UDP and TCP).

    • Name: For example ad-outbound-endpoint.

    • Target IP(s): IP address of the AD DNS server.

    • In the Route 53 console, select Resolver > Rules and create a rule using the following settings:

      • Rule name: For example, forward-ad-domain.

      • Domain name: Your AD domain, for example ad.example.com.

      • Rule type: Forward.

      • Outbound endpoint: Select the endpoint that you just created.

      • Target IP(s): IP of the AD DNS server.

    • Associate the rule with the Edge VPC.

No changes are needed to the DHCP option sets or EC2 instance settings. DNS queries, for ad.example.com will be forwarded to the AD DNS server. All other DNS queries will continue to use AmazonProvidedDNS (169.254.169.253).

Along with the above networking requirement, AWS needs a CIDR block range to deploy control plane services that meet the following requirements:

  • Within one of the following private IP address blocks: 10.0.0.0/8, 172.16.0.0/12, or 192.168.0.0/16.

  • The CIDR must not overlap with the selected VPC CIDR.

  • The CIDR value should be between /24 and /12.eg: 10.160.0.0/16 (For related information, see KubernetesNetworkConfigRequest in Amaozn EKS product documentation.

  • The SKU used by nodes in cluster Edge deployments should be m5.large - 2 vCPUs and 8 GiB. Note that Omnissa automatically selects this SKU during Edge deployment. Your system should have quota for this SKU available to support deployment success.

Specifying Agent Pairing and AWS IP Ranges for Amazon Workspaces Core in Settings

In Horizon Cloud, every VM connects securely to the Horizon Control Plane so that an agent running on a VM can send data in a more secure way. This process is referred to as agent pairing. For Amazon Workspaces Core, you can optionally specify an allowed NAT Gateway IP address range to use for this agent pairing by using a General Settings UI sequence. The IP range that you specify is used to validate and allow an external address to be used to connect one way traffic for internal VIP networks.

You can specify multiple NAT Gateway IP address ranges. Use of this setting is optional and allows for added security.

If you specify at least one NAT Gateway IP address range here, validation is performed and access is subsequently denied if a request is made that does not originate from within that IP range. If you do not supply a network range here, access is allowed from any of your NAT Gateway IP addresses.

Note: If you do not use AWS for your deployments, you can safely ignore the AWS IP Ranges section under General Settings in the Horizon Universal Console.

  1. From the Horizon Universal Console, click Settings and then click Manage on the General Settings tile.

  2. Click Add in the Add a Network Range section and enter an allowed NAT Gateway IP address range.

  3. You can also click Add in the AWS IP Ranges section to specify CIDR, single IP, and and IP ranges.

Was this page helpful?

Provide feedback for this topic

Was this topic helpful?

Please do not include any personal or confidential information.

Generating link…