Ensure that the required ports and protocols for your Horizon Cloud on Nutanix deployment allow communication as necessary. Use the following table to ensure your network configuration and firewalls will allow the communication traffic that is required for a successful deployment and for daily operations.
Note: Horizon Cloud on Nutanix is currently available in Limited Availability (LA) mode only.
For the Horizon Cloud on Nutanix provider type, the following table lists the required ports and protocols, along with the destination for the network traffic from the Horizon Edge.
| Source | Target | Ports | Protocol | Purpose |
|---|---|---|---|---|
| Horizon Edge | Nutanix Prism Central | 443 | HTTPS | This port is used by the edge to communicate with Nutanix Prism Central for UAG/desktop lifecycle management and inventory discovery. |
| Horizon Edge | Unified Access Gateway VMs | 9443 | HTTPS | This port is used by the Edge VM over the Management subnet to configure settings in the Edge's Unified Access Gateway (UAG) configuration. This port requirement applies when initially deploying a Unified Access Gateway configuration and when editing an Edge to add a Unified Access Gateway configuration or update settings for that Unified Access Gateway configuration. It is also used to monitor session statistics from the Unified Access Gateway. |
| Horizon Edge | Domain controller | Kerberos: 88 (TCP, UDP); LDAP: 389, 3268 (TCP); LDAPS: 636, 3269 (TCP) | TCP / UDP | Registering your Horizon Cloud with Domain and for SSO login and periodic discovery of domain controllers. These ports are required for LDAP or LDAPS services when LDAP/LDAPS will be specified in that workflow. LDAP is the default for most tenants. Target is the server that contains a domain controller role in the Active Directory configuration. |
| Horizon Edge | AD Certificate Services | 135 and a port within the range 49152–65535 | TCP (RPC) | Connecting to the Microsoft Enterprise Certificate Authority (AD CS) to obtain short-lived certificates for True SSO. The Horizon Edge uses TCP port 135 for the initial RPC communication, then a port within the range 49152–65535 to communicate with Azure Directory Certificate Services. |
| Horizon Edge | DNS server | 53 and 853 | TCP / UDP | DNS services. |
| Horizon Edge | *.blob.core.windows.net / *.blob.storage.azure.net | 443 | TCP | Used for programmatic access to the Azure Blob Storage and to upload the Horizon Edge logs as and when required. Also used for downloading Docker images to create the required Horizon Edge modules, which are useful for monitoring, SSO, UAG updates, and so on. |
| Horizon Edge | Azure Container Registry / Microsoft Azure | 443 | TCP | Used for authentication while downloading Docker images to create the required Horizon Edge modules, which are useful for monitoring, SSO, UAG updates, and so on. |
| Horizon Edge | *.azure-devices.net | 443 | TCP | Appliance used to communicate with the cloud control plane, download configurations for the appliance's module, and update the appliance's module's runtime status. Current concrete endpoints are: North America: edgehubprodna.azure-devices.net Europe: edgehubprodeu.azure-devices.net Japan: edgehubprodjp.azure-devices.net |
| Horizon Edge | *.data.workspaceone.com (Omnissa) | 443 | TCP | To send events or metrics to Workspace ONE Intelligence for monitoring data. Endpoints are: eventproxy.na1.data.workspaceone.com, eventproxy.eu1.data.workspaceone.com, eventproxy.eu2.data.workspaceone.com, eventproxy.uk1.data.workspaceone.com, eventproxy.ca1.data.workspaceone.com, eventproxy.ap1.data.workspaceone.com, eventproxy.ap2.data.workspaceone.com, eventproxy.au1.data.workspaceone.com, eventproxy.in1.data.workspaceone.com |
| Horizon Edge | *.horizon.omnissa.com — Region-specific MQTT endpoints are: US: cloud-sg-us-hdc-mqtt.horizon.omnissa.com EU: cloud-sg-eu-hdc-mqtt.horizon.omnissa.com APAC: cloud-sg-jp-hdc-mqtt.horizon.omnissa.com | 443 | TCP / MQTT | This port is required for Horizon Edge communication with the control plane for desktop lifecycle management and inventory discovery. |
| Horizon Edge | *.horizon.omnissa.com Region-specific endpoints are: US: cloud-sg-us-r-westus2.horizon.omnissa.com, cloud-sg-us-r-eastus2.horizon.omnissa.com, cloud-sg-us.horizon.omnissa.com EU: cloud-sg-eu-r-northeurope.horizon.omnissa.com, cloud-sg-eu-r-germanywestcentral.horizon.omnissa.com, cloud-sg-eu.horizon.omnissa.com, cloud-sg-eu-r-uksouth.horizon.omnissa.com APAC: cloud-sg-jp-r-japaneast.horizon.omnissa.com, cloud-sg-jp.horizon.omnissa.com, cloud-sg-jp-r-australiaeast.horizon.omnissa.com, cloud-sg-jp-r-centralindia.horizon.omnissa.com | 443 | TCP | Appliance used to communicate with the cloud control plane and for Day 2 operations. |
| Horizon Edge Gateway (single VM type) | NTP server | 123 | UDP | NTP services. |
| Horizon Edge | Unified Access Gateway load balancer IP addresses (front end) | 443 | HTTPS | Horizon Edge periodically checks that public and private load balancer IP addresses or URLs are reachable by querying the following URL: https://{LB_IP}/favicon.ico |
| Horizon Edge | repo.omnissa.com | 443 | HTTPS | Omnissa UAG image repository. |
Was this page helpful?