Ensure that the required ports, protocols, and destination URLs for your Horizon Cloud on Microsoft Azure deployment allow communication as necessary. Use the following tables to verify that your network configuration and firewalls will allow the communication traffic required for a successful deployment and for day-to-day operations.
The specific ports and protocols required for your deployment will in part depend on which features you select to use. If you do not plan to use a specific component or protocol, its required communication traffic is not necessary, and you can ignore the ports associated with that component. For example, if your end users will only use the Blast Extreme display protocol, then allowing the PCoIP ports is not a requirement.
Note: If your deployment uses a proxy server to control traffic flow, open the required ports to allow the Horizon Edge Gateway to reach the proxy server. When the format of your Microsoft Azure Edge is Edge Gateway (AKS), see Outbound network and FQDN rules for Azure Kubernetes Service (AKS) clusters. For situations where using URLs is not possible, see KB 6000374 — IP Addresses for Service Components.
Ports and Protocols Required by Horizon Edge
When you activate Horizon Infrastructure Monitoring, Horizon Edge is deployed and configured in the associated subscription. The following table lists the ports and protocols needed during the activation process — in which the appliance deploys and configures the manager VMs so the appliance can collect monitoring data — as well as the ports and protocols needed during steady-state operations.
To allow the URLs and wildcard sub-domains in the table below, add them to an allow list for your firewall and network security group, and bypass SSL deep packet inspection in both the firewall and, if applicable, the proxy server.
| Source | Target | Ports | Protocols | Proxy Traffic (if configured) | Purpose |
|---|---|---|---|---|---|
| Horizon Edge | *.azure-devices.netRegion-specific names: North America: - edgehubprodna.azure-devices.netEurope: - edgehubprodeu.azure-devices.netJapan: - edgehubprodjp.azure-devices.net | 443 | TCP | Yes | Used to connect the appliance to the Horizon Cloud control plane, to download configurations for the appliance's module, and to update the appliance's module's runtime status. |
| Horizon Edge | *.horizon.omnissa.comRegion-specific endpoints: US: - cloud-sg-us-r-westus2.horizon.omnissa.com- cloud-sg-us-r-eastus2.horizon.omnissa.com- cloud-sg-us.horizon.omnissa.comEU: - cloud-sg-eu-r-northeurope.horizon.omnissa.com- cloud-sg-eu-r-germanywestcentral.horizon.omnissa.com- cloud-sg-eu.horizon.omnissa.com- cloud-sg-eu-r-uksouth.horizon.omnissa.comJP: - cloud-sg-jp-r-japaneast.horizon.omnissa.com- cloud-sg-jp.horizon.omnissa.com- cloud-sg-jp-r-australiaeast.horizon.omnissa.com- cloud-sg-jp-r-centralindia.horizon.omnissa.com | 443 | TCP | Yes | Appliance used to communicate with the cloud control plane and for Day 2 operations. |
| Horizon Edge | *.data.workspaceone.comRegion-specific names: - eventproxy.na1.data.workspaceone.com- eventproxy.eu1.data.workspaceone.com- eventproxy.eu2.data.workspaceone.com- eventproxy.uk1.data.workspaceone.com- eventproxy.ca1.data.workspaceone.com- eventproxy.ap1.data.workspaceone.com- eventproxy.ap2.data.workspaceone.com- eventproxy.au1.data.workspaceone.com- eventproxy.in1.data.workspaceone.com | 443 | TCP | Yes | Used for sending events or metrics to Workspace ONE Intelligence for monitoring data. See Workspace ONE Intelligence. |
| Horizon Edge | - *.blob.core.windows.net- *.blob.storage.azure.net | 443 | TCP | Yes | Used for programmatic access to Azure Blob Storage and to upload Horizon Edge logs as required. Used for downloading Docker images to create the required Horizon Edge modules, which are useful for monitoring, SSO, UAG updates, and such. |
| Horizon Edge | horizonedgeprod.azurecr.io | 443 | TCP | Yes | Used for authentication while downloading Docker images to create the required Horizon Edge modules, which are useful for monitoring, SSO, UAG updates, and such. |
| Horizon Edge | registry.k8s.io | 443 | TCP | Yes | Used for programmatic access to allow images to download as required. Used for downloading Docker images to create the required Horizon Edge modules, which are useful for monitoring, SSO, UAG updates, and such. Note: Applies to Horizon Edge Gateway VM-based deployment 2412 only. |
| Horizon Edge | https://aka.ms/downloadazcopy-v10-linux | 443 | TCP | Yes | Used to upload deployment logs to Azure Blob Storage for troubleshooting purposes. |
| Horizon Edge | login.microsoftonline.com | 443 | TCP | Yes | Generally used by applications to authenticate against Microsoft Azure service. |
| Horizon Edge | management.azure.com | 443 | TCP | Yes | Used for Edge API requests to the Microsoft Azure Resource Manager endpoints for using Microsoft Azure Resource Manager services. |
| Horizon Edge | - mcr.microsoft.com- *.data.mcr.microsoft.com- packages.microsoft.com- packages.aks.azure.com | 443 | HTTPS | Yes | Used for patching Microsoft components of the Horizon Edge Gateway. |
| Horizon Edge | - security.ubuntu.com- azure.archive.ubuntu.com- changelogs.ubuntu.com- motd.ubuntu.com | 80 | HTTP | Yes | Used for patching Ubuntu components. |
| Horizon Edge | softwareupdate.omnissa.com | 443 | TCP | No | Software package server. Used for downloading updates of the agent-related software used in the system's image-related operations and automated agent update process. |
| Horizon Edge | *.file.core.windows.net | 445 | TCP | No | Access to fileshares provisioned for the App Volumes workflows of importing packages and replicating the packages across fileshares. |
| Horizon Edge | monitor.horizon.omnissa.comIf your firewall or NSG supports service tags, apply Azure service tag AzureCloud instead of this hostname. | 1514 and 1515 | TCP | No | Used for system monitoring. |
| Horizon Edge | download.falco.org | 443 | HTTPS | No | Used by the security monitoring tool Falco for checking and downloading the latest resources required for it to function properly. |
| Horizon Edge | *.cloudfront.net | 443 | HTTPS | No | Used by the security monitoring tool Falco for checking and downloading the latest resources required for it to function properly. |
| Horizon Edge | Unified Access Gateway VMs | 9443 | HTTPS | No | This port is used by the Edge VM over the Management subnet to configure settings in the Edge's Unified Access Gateway configuration. This applies when initially deploying a Unified Access Gateway configuration, when editing an Edge to add or update a Unified Access Gateway configuration, and also to monitor session statistics from the Unified Access Gateway. |
| Horizon Edge | Unified Access Gateway external and internal load balancer IP addresses - front end | 443 | HTTPS | No | Horizon Edge periodically checks that public and private load balancer IP addresses or URLs are reachable by querying: https://{LB_IP}/favicon.ico. |
| Horizon Edge | Domain controller | Kerberos: 88; LDAP: 389, 3268; LDAPS: 636, 3269 | TCP, UDP | No | Registering your Horizon Cloud with Domain and for SSO login and periodic discovery of domain controllers. These ports are required for LDAP or LDAPS services when LDAP/LDAPS will be specified in that workflow. LDAP is the default for most tenants. Target is the server that contains a domain controller role in the Active Directory configuration. |
| Horizon Edge | AD Certificate Services | 135 and a port within the range of 49152 to 65535 | TCP (RPC) | No | Connecting to the Microsoft Enterprise Certificate Authority (AD CS) to obtain short-lived certificates for True SSO. The Horizon Edge uses TCP port 135 for the initial RPC communication, then a port within the range 49152–65535 to communicate with AD CS. |
| Horizon Edge | DNS server | 53 and 853 | TCP, UDP | No | DNS services. |
| Horizon Edge Gateway (single VM type) | NTP server | 123 | UDP | No | NTP services. |
| Horizon Edge Gateway (AKS type) | ntp.ubuntu.comThe NTP setting is inherited from Microsoft Azure and cannot be changed within Horizon Cloud. | 123 | UDP | No | NTP services. |
| Horizon Edge | time.google.com | 123 | UDP | Yes | Used for time synchronization. |
| Horizon Edge Gateway (AKS type) | *.azmk8s.io | 443 | TCP | No | Required for communication between the AKS Node and the API server. |
Unified Access Gateway VM Ports and Protocols Requirements
In addition to the primary ports and protocols listed in the table above, the ports and protocols in the following table apply to the gateways configured for ongoing operations after deployment. For connections configured with Unified Access Gateway instances, traffic must be allowed to and from the Unified Access Gateway instances to the targets listed below.
Considerations
-
For these service-deployed Unified Access Gateway instances, the UDP ports require both forward and reply UDP datagrams to be allowed. For example, Unified Access Gateway services use DNS to resolve hostnames. DNS requests are made on UDP port 53, so it is important that an external firewall does not block these requests or replies.
-
The Unified Access Gateway is deployed on a multi-NIC configuration. The Source Network column details which network the traffic originates from.
-
Bypass SSL deep packet inspection in the DMZ subnet for all URLs and wildcard subdomains listed below — in the firewall for traffic from the Unified Access Gateway to
*.horizon.omnissa.comendpoints, and in any proxy server the Unified Access Gateway itself uses to reach cloud control plane endpoints.
| Source | Target | Port | Source Network | Protocols | Purpose |
|---|---|---|---|---|---|
| Unified Access Gateway | *.horizon.omnissa.com — Region-specific endpoints:US: - cloud-sg-us.horizon.omnissa.com- cloud-sg-us-r-westus2.horizon.omnissa.com- cloud-sg-us-r-eastus2.horizon.omnissa.comEU: - cloud-sg-eu.horizon.omnissa.com- cloud-sg-eu-r-northeurope.horizon.omnissa.com- cloud-sg-eu-r-germanywestcentral.horizon.omnissa.com- cloud-sg-eu-r-uksouth.horizon.omnissa.comJP: - cloud-sg-jp.horizon.omnissa.com- cloud-sg-jp-r-japaneast.horizon.omnissa.com- cloud-sg-jp-r-australiaeast.horizon.omnissa.com- cloud-sg-jp-r-centralindia.horizon.omnissa.com | 443 | DMZ network | TCP, UDP | Unified Access Gateway needs to be able to resolve these addresses at any time or the user will not be able to launch the session, because the Unified Access Gateway fetches the JWK set from cloud-sg-<region>-r-<DC>.horizon.omnissa.com. Note: Starting with UAG version 25.06, deployments using the 'Internal access over a corporate network' access type require outbound connectivity from the UAG management interface to the target endpoints. Ensure this is allowed on your network, as detailed in the Requirements checklist. |
| Unified Access Gateway | DNS server | 53 and 853 | Any | TCP, UDP | DNS services. |
| Unified Access Gateway | Horizon agent in the desktop or farm RDSH VMs | 22443 | Tenant Network | TCP, UDP | Blast Extreme display protocol. By default, client-drive redirection (CDR) traffic and USB traffic are side-channeled on this port. If preferred, CDR traffic can be separated onto TCP port 9427 and USB redirection traffic can be separated onto TCP port 32111. |
| Unified Access Gateway | Horizon agent in the desktop or farm RDSH VMs | 9427 | Tenant Network | TCP | Optional for CDR and multimedia redirection (MMR) traffic. |
| Unified Access Gateway | Horizon agent in the desktop or farm RDSH VMs | 32111 | Tenant Network | TCP | Optional for USB redirection traffic. |
| Unified Access Gateway | NTP server (default: time.google.com - you can change this value) | 123 | DMZ Network | UDP | NTP services. |
| Unified Access Gateway | - *.blob.core.windows.net- *.blob.storage.azure.net | 443 | DMZ Network | TCP | Used for programmatic access to Azure Blob Storage to upload Unified Access Gateway logs as required. |
| Unified Access Gateway | Edge Management Network | 31443 | UAG Management Network | TCP | Requirement for Availability Monitoring. |
App Volumes Ports and Protocols
To support App Volumes features for use with Horizon Cloud on Microsoft Azure, you must configure port 445 for TCP protocol traffic to the tenant (desktops) subnet. Port 445 is the standard SMB port for accessing an SMB file share on Microsoft Windows. The AppStacks are stored in an SMB file share located in the same resource group as the pod manager VMs.
| Source | Target | Port | Protocol | Purpose |
|---|---|---|---|---|
| App Volumes agent in the base imported VM, the golden images, desktop VMs, farm RDSH VMs | *.file.core.windows.net | 445 | TCP | App Volumes application virtualization on the VDI machines and application package capture on the VDI machines depend on access to the fileshares. |
VDI Ports and Protocols Requirements
The following table provides the ports and protocols required for the desktop (VDI or tenant) subnets configured in your environment.
Note: In addition to the ports listed below, ensure that the URLs and wildcard subdomains required for Horizon Edge are also reachable from your environment. For details, see Ports and Protocols Required by Horizon Edge above.
You can allow a URL for the tenant (desktop) subnet at the global VM Hub level or at the regional VM Hub level. If using regional VM Hub instances suits the needs of your site, use the two corresponding URLs: Service Gateway and MQTT, for the region in which your Horizon Edge Gateway is deployed. The regional endpoint mapping is shown below the table.
| Source | Target | Port | Protocol | Purpose |
|---|---|---|---|---|
| Desktop (tenant) Subnet | *.horizon.omnissa.com — Region-specific endpoints:US: - cloud-sg-us-r-westus2.horizon.omnissa.com- cloud-sg-us-r-westus2-mqtt.horizon.omnissa.com- cloud-sg-us-r-eastus2.horizon.omnissa.com- cloud-sg-us-r-eastus2-mqtt.horizon.omnissa.comEU: - cloud-sg-eu-r-northeurope.horizon.omnissa.com- cloud-sg-eu-r-northeurope-mqtt.horizon.omnissa.com- cloud-sg-eu-r-germanywestcentral.horizon.omnissa.com- cloud-sg-eu-r-germanywestcentral-mqtt.horizon.omnissa.com- cloud-sg-eu-r-uksouth.horizon.omnissa.com- cloud-sg-eu-r-uksouth-mqtt.horizon.omnissa.comJP: - cloud-sg-jp-r-japaneast.horizon.omnissa.com- cloud-sg-jp-r-japaneast-mqtt.horizon.omnissa.com- cloud-sg-jp-r-australiaeast.horizon.omnissa.com- cloud-sg-jp-r-australiaeast-mqtt.horizon.omnissa.com- cloud-sg-jp-r-centralindia.horizon.omnissa.com- cloud-sg-jp-r-centralindia-mqtt.horizon.omnissa.com | 443 | TCP, MQTT | For agent-related operations, such as certificate signing using VM Hub and renewal. |
| Desktop (tenant) Subnet | Domain controller | 88 | TCP, UDP | Kerberos services. The target is the server that contains a domain controller role in an Active Directory configuration. Registering the Edge with Active Directory is a requirement. |
| Desktop (tenant) Subnet | Domain controller | Kerberos: 88; LDAP: 389, 3268; LDAPS: 636, 3269 | TCP, UDP | These ports are required for LDAP or LDAPS services for VM to domain controller connectivity. If the VDI is unable to reach any domain controller, session launch is not possible. |
| Desktop (tenant) Subnet | DNS Server | 53 and 853 | TCP, UDP | DNS services. |
| Desktop (tenant) Subnet | NTP server | 123 | UDP | NTP services. |
| Desktop (tenant) Subnet | *.blob.core.windows.net | 443 | TCP | DCT log bundle upload. When a customer admin clicks on the DCT log collection for any VM after request processing, the bundle will be uploaded from VDI to blob to make that bundle available to download from the Horizon Universal Console. |
| Desktop (tenant) Subnet | Horizon Edge | 31883 | TCP, MQTT, UDP | Horizon agent running on VM to MQTT running on Edge. |
| Desktop (tenant) Subnet | Horizon Edge | 32443 | TCP | Single Sign-On when the format of your Microsoft Azure Edge is Edge Gateway (VM). |
| Desktop (tenant) Subnet | Horizon Edge | 443 | TCP | Single Sign-On when the format of your Microsoft Azure Edge is Edge Gateway (AKS). |
| Desktop (tenant) Subnet and Management Subnet | softwareupdate.omnissa.com | 443 | TCP | Software package server. Used for downloading updates of the agent-related software used in the system's image-related operations and automated agent update process. Note: The management subnet is required for this target only if you plan to use the management subnet for importing and publishing images. |
| Desktop (tenant) Subnet | Private Link Endpoint | 443 | TCP | Desktop connectivity to the connection service in the cloud control plane. |
| Desktop (tenant) Subnet and Management Subnet | AD Certificate Services | 135, 445, and a port within the range of 49152 to 65535 | TCP (RPC) | To add desktops to domain. |
| Desktop (tenant) Subnet | CRL distribution point (CDP) Examples: - http://*.digicert.com- http://crl3.digicert.com/DigiCertGlobalRootCA.crl- http://crl3.digicert.com/DigiCertTLSRSASHA2562020CA1-4.crl- http://crl4.digicert.com/DigiCertTLSRSASHA2562020CA1-4.crl- http://ocsp.digicert.com | 80 | TCP | The bootstrapping process for the VM involves sending an HTTP POST request to the Horizon Cloud endpoint. To establish a secure connection, a Certificate Revocation List (CRL) check is performed. If this check is not permitted through the internet, VM customization fails. |
| Desktop (tenant) Subnet | - eventproxy.na1.data.workspaceone.com- eventproxy.eu1.data.workspaceone.com- eventproxy.eu2.data.workspaceone.com- eventproxy.uk1.data.workspaceone.com- eventproxy.ca1.data.workspaceone.com- eventproxy.ap1.data.workspaceone.com- eventproxy.ap2.data.workspaceone.com- eventproxy.au1.data.workspaceone.com- eventproxy.in1.data.workspaceone.com | 443 | TCP | Used by Digital Employee Experience (DEX) telemetry agent to send data to Omnissa Intelligence. Required only for DEX-enabled desktops. |
| Desktop (tenant) Subnet | - auth.na1.data.workspaceone.com- auth.eu1.data.workspaceone.com- auth.eu2.data.workspaceone.com- auth.uk1.data.workspaceone.com- auth.ca1.data.workspaceone.com- auth.ap1.data.workspaceone.com- auth.ap2.data.workspaceone.com- auth.au1.data.workspaceone.com- auth.in1.data.workspaceone.com | 443 | TCP | Used by Digital Employee Experience (DEX) telemetry agent to authenticate with Omnissa Intelligence. Required only for DEX-enabled desktops. |
Regional VM Hub DNS Hostname Reference
The following table maps Azure deployment regions to their corresponding Service Gateway and MQTT URLs. All entries use port 443, protocol TCP, for agent-related operations such as certificate signing using VM Hub and renewal.
| Azure Regions | Service Gateway URL | MQTT URL |
|---|---|---|
| - westus2 - usgovarizona - usgovtexas - westus - westus3 - westcentralus - centralus | cloud-sg-us-r-westus2.horizon.omnissa.com | cloud-sg-us-r-westus2-mqtt.horizon.omnissa.com |
| - eastus2 - eastus - usgovvirginia - southcentralus - northcentralus - canadacentral - canadaeast - brazilsouth - brazilsoutheast - mexicocentral | cloud-sg-us-r-eastus2.horizon.omnissa.com | cloud-sg-us-r-eastus2-mqtt.horizon.omnissa.com |
| - northeurope - norwaywest - norwayeast - uaecentral - uaenorth - westeurope | cloud-sg-eu-r-northeurope.horizon.omnissa.com | cloud-sg-eu-r-northeurope-mqtt.horizon.omnissa.com |
| - uksouth - ukwest - spaincentral | cloud-sg-eu-r-uksouth.horizon.omnissa.com | cloud-sg-eu-r-uksouth-mqtt.horizon.omnissa.com |
| - germanywestcentral - germanynorth - swedencentral - swedensouth - francecentral - francesouth - switzerlandnorth - switzerlandwest - italynorth - israelcentral - polandcentral - qatarcentral | cloud-sg-eu-r-germanywestcentral.horizon.omnissa.com | cloud-sg-eu-r-germanywestcentral-mqtt.horizon.omnissa.com |
| - japanwest - japaneast - koreacentral | cloud-sg-jp-r-japaneast.horizon.omnissa.com | cloud-sg-jp-r-japaneast-mqtt.horizon.omnissa.com |
| - australiaeast - australiacentral - australiacentral2 - australiasoutheast - newzealandnorth - southafricanorth | cloud-sg-jp-r-australiaeast.horizon.omnissa.com | cloud-sg-jp-r-australiaeast-mqtt.horizon.omnissa.com |
| - centralindia - jioindiawest - jioindiacentral - southindia - westindia - indonesiacentral | cloud-sg-jp-r-centralindia.horizon.omnissa.com | cloud-sg-jp-r-centralindia-mqtt.horizon.omnissa.com |
Note: Horizon Cloud has a localized active-active deployment in Japan to ensure infrastructure resiliency remains entirely within the region, adhering to local compliance policies. Traffic dynamically routes between the Horizon Cloud 1 instance (Japan East) and the Horizon Cloud 2 instance (Japan West) based on geographic affinity. If your organization enforces IP-based allowlisting, ensure your firewall rules include entries for both of the Horizon Cloud instances in Japan as listed in KB 6000374 — IP Addresses for Service Components.
End-User Connection Traffic Ports and Protocols Requirements
For detailed information about the various Horizon Clients your end users might use with your Horizon Edge Virtual Appliance, see the Horizon Client product documentation. Which ports must be opened depends on the choice you make for how your end users will connect.
| Source | Target | Port | Protocol | Purpose |
|---|---|---|---|---|
| Horizon Client | Microsoft Azure load balancer for Unified Access Gateway instances | 443 | TCP | To carry CDR, MMR, USB redirection, and tunneled RDP traffic. SSL (HTTPS access) is enabled by default for client connections. Port 80 (HTTP access) can be used in some cases. |
| Horizon Client | Microsoft Azure load balancer for Unified Access Gateway instances | 8443 or 443 | TCP | Blast Extreme via Blast Secure Gateway on Unified Access Gateway for data traffic from Horizon Client. The port used, 8443 or 443, is defined when the Horizon Edge Gateway is deployed. |
| Horizon Client | Microsoft Azure load balancer for Unified Access Gateway instances | 443 | UDP | Blast Extreme via the Unified Access Gateway for data traffic. |
| Horizon Client | Microsoft Azure load balancer for Unified Access Gateway instances | 8443 | UDP | Blast Extreme via Blast Secure Gateway on Unified Access Gateway for data traffic (adaptive transport). |
| Browser | Microsoft Azure load balancer for Unified Access Gateway instances | 443 | TCP | To carry CDR, MMR, USB redirection, and tunneled RDP traffic. SSL (HTTPS access) is enabled by default for client connections. Port 80 (HTTP access) can be used in some cases. |
| Browser | Microsoft Azure load balancer for Unified Access Gateway instances | 8443 or 443 | TCP | Blast Extreme via Blast Secure Gateway on Unified Access Gateway for data traffic from the Horizon Web Client. |
| Horizon Client / Browser | *.horizon.omnissa.com — After logging in, when an end user clicks to launch a desktop, protocol traffic is redirected to the Unified Access Gateway from the regional URL corresponding to the VM's location. The client needs access to the Service Gateway URL for each relevant region, such as cloud-sg-us-r-westus2.horizon.omnissa.com. Allowlist the URLs in the Regional VM Hub DNS Hostname Reference table above based on the global regions from which you deliver desktops and applications. | 443 | TCP | For end-user protocol traffic redirection to Unified Access Gateway based on the region in which the specified VM is located. |
| Horizon Client / Browser | cloud.omnissahorizon.com | 443 | TCP | If you have a restricted network, allowlist this URL to enable end users to access their applications and desktops. See Launch a Desktop with Horizon Client. If you have customized the Client Access URL, ensure that your custom URL is also added to your allowlist. See Configuring Client Settings. |
Was this page helpful?