Specific ports and protocols are required for deployment and ongoing operations of your Horizon Cloud on Google Cloud Platform environment. Configure the firewall rules described in this topic in your GCP VPC settings before deploying the Horizon Edge.
Note: Horizon Cloud on Google Cloud Platform is currently available in Limited Availability (LA) mode only.
Critical: Confirm that your internal network CIDRs do not overlap the following values used by Kubernetes inside the Edge Gateway VM:
- Service CIDR:
192.168.236.0/23- Pod CIDR:
192.168.240.0/21
Management VPC Firewall Rules
| Firewall Rule | Direction | Source IPv4 Range | Targets | Protocols and Ports |
|---|---|---|---|---|
| Allow Edge to connect to UAG management console on port 9443. UAG uses the edge management subnet for NIC1. | Ingress | CIDR range of the Management subnet | All instances in the network | TCP:9443 |
| Allow desktop VM Horizon Agent to connect with MQTT on Edge and for SSO. Also required for internal Desktop VM connections. | Ingress | CIDR range of the Desktop/tenant subnet | All instances in the network | TCP:31883, TCP:32443, UDP:31883 |
| Allow Log collection and Diagnostic via SSH IAP. | Ingress | 35.235.240.0/20 (Google's reserved range for IAP tunneling) | All instances in the network | TCP:22 |
| Allow east-west traffic for topology (UAG-to-UAG state reroute path). Required only if UAG is being deployed in Advanced mode with /28 subnet. | Ingress | CIDR range of the UAG Management subnet | All instances in the network | UDP:8445 |
Desktop VPC Firewall Rules
| Firewall Rule | Direction | Source IPv4 Range | Targets | Protocols and Ports |
|---|---|---|---|---|
| Allow Internal passthrough Network Load Balancer health check ranges from Google Cloud probers. Required if UAG has an internal load balancer. | Ingress | 130.211.0.0/22, 209.85.152.0/22 + Edge Management subnet CIDR (Required for Omnissa private LB IP monitoring) | All instances in the network, or specify target tags | TCP:443 |
| Allow internal users to connect to desktop VMs. | Ingress | CIDR range of the desktop subnet / intranet | All instances in the network | TCP:80, TCP:443, TCP:8443, UDP:443, UDP:8443 |
| Allow Log collection and Diagnostic via SSH IAP. Required if UAG is 2-NIC / Internal Only. | Ingress | 35.235.240.0/20 (Google's reserved range for IAP tunneling) | All instances in the network | TCP:22 |
Desktop VPC Firewall Rules (created by Horizon Cloud)
During pool provisioning (preparePool), Horizon Cloud creates one firewall rule per VPC referenced by the pool, targeting the pool's VMs via a network tag, to permit the Horizon display-protocol traffic (PCoIP, Blast, Side Channel; RDP/SSH only if enabled). If the firewall-management permissions (compute.firewalls.*, and for a Shared VPC the same permissions in the host project) are granted to the HCS service account, these rules are created automatically. If not, the customer admin must create equivalent rules manually.
| Firewall Rule | Direction | Priority | Source IPv4 Range | Targets | Protocols and Ports |
|---|---|---|---|---|---|
| Horizon display-protocol access to pool VMs | Ingress | 1000 | 0.0.0.0/0 | Pool VMs (HCS network tag) | TCP:4172, UDP:4172 (PCoIP); TCP:9427 (Side Channel); TCP:22443, UDP:22443 (Blast) |
DMZ VPC Firewall Rules
The DMZ VPC and its firewall rules are not required if you are deploying UAG in internal access mode only.
| Firewall Rule | Direction | Priority | Source IPv4 Range | Targets | Protocols and Ports |
|---|---|---|---|---|---|
| Allow external passthrough Network Load Balancer health check ranges from Google Cloud probers. Required if UAG has an external load balancer. | Ingress | 1000 | 35.191.0.0/16, 209.85.152.0/22, 209.85.204.0/22 | All instances in the network, or specify target tags | TCP:443 |
| Allow external users to connect to UAG. | Ingress | 1000 | 0.0.0.0/0 | All instances in the network, or specify target tags | TCP:80 (HTTP), TCP:443 (HTTPS), TCP:8443 (Blast TCP), UDP:443 (Blast UDP), UDP:8443 (Blast UDP) |
| Allow Log collection and Diagnostic via SSH IAP. | Ingress | 1000 | 35.235.240.0/20 (Google's reserved range for IAP tunneling) | All instances in the network, or specify target tags | TCP:22 |
AD Server VPC Firewall Rules
| Firewall Rule | Direction | Source IPv4 Range | Targets | Protocols and Ports |
|---|---|---|---|---|
| Allow connectivity from Desktop VPC into AD VPC | Ingress | Desktop VPC subnet CIDR | All instances in the network | TCP, UDP, ICMP |
| Allow connectivity from Management VPC into AD VPC | Ingress | Management VPC subnet CIDR | All instances in the network | TCP, UDP, ICMP |
| Allow GCP Cloud DNS to query AD DNS. Required for GCP infrastructure. | Ingress | 35.199.192.0/19 | All instances in the network | TCP:53, UDP:53 |
Outbound Endpoint Requirements for Horizon Edge Gateway
In addition to the VPC firewall rules described above, the Horizon Edge Gateway and desktop VMs must be able to reach specific external HTTPS endpoints for control-plane communication, monitoring, software updates, and container registry access. Ensure that Cloud NAT is configured and that the following destinations are reachable from the Management VPC subnet.
| Source | Target | Ports | Protocol | Purpose |
|---|---|---|---|---|
| Horizon Edge | *.horizon.omnissa.com | 443 | TCP | Control-plane communication. Region-specific service gateway endpoints. |
| Horizon Edge | Domain controller | Kerberos: 88, LDAP: 389/3268, LDAPS: 636/3269 | TCP UDP | Registering Horizon Cloud with the domain, SSO login, and periodic discovery of domain controllers. |
| Horizon Edge | DNS server | 53, 853 | TCP UDP | DNS services. |
| Horizon Edge | softwareupdate.omnissa.com | 443 | TCP | Software package server. Used for downloading updates of agent-related software used in image-related operations and the automated agent update process. |
| Horizon Edge | Container registry (GCP Artifact Registry or equivalent) | 443 | TCP | Used for authentication and downloading Docker images to create the required Horizon Edge modules, which are useful for monitoring, SSO, UAG updates, and such. |
| Horizon Edge | *.data.workspaceone.com | 443 | TCP | To send events or metrics to Workspace ONE Intelligence for monitoring data. Concrete endpoints include: eventproxy.na1.data.workspaceone.com, eventproxy.eu1.data.workspaceone.com, eventproxy.eu2.data.workspaceone.com, eventproxy.uk1.data.workspaceone.com, eventproxy.ca1.data.workspaceone.com, eventproxy.ap1.data.workspaceone.com, eventproxy.ap2.data.workspaceone.com, eventproxy.au1.data.workspaceone.com, eventproxy.in1.data.workspaceone.com. |
| Desktop (tenant) Subnet | *.horizon.omnissa.com | 443 | TCP MQTT | For agent-related operations, such as certificate signing and renewal. |
| Desktop (tenant) Subnet | Domain controller | Kerberos: 88, LDAP: 389/3268, LDAPS: 636/3269 | TCP UDP | LDAP/LDAPS services for VM-to-domain-controller connectivity. If the VDI is unable to reach any domain controller, session launch is not possible. |
| Desktop (tenant) Subnet | DNS server | 53, 853 | TCP UDP | DNS services. |
| Desktop (tenant) Subnet | softwareupdate.omnissa.com | 443 | TCP | Software package server. Used for downloading updates of agent-related software. |
| Desktop (tenant) Subnet | eventproxy.na1.data.workspaceone.com (and regional equivalents) | 443 | TCP | Used by Digital Employee Experience (DEX) telemetry agent to send data to Omnissa Intelligence. Required only for DEX-enabled desktops. |
| Desktop (tenant) Subnet | auth.na1.data.workspaceone.com (and regional equivalents) | 443 | TCP | Used by DEX telemetry agent to authenticate with Omnissa Intelligence. Required only for DEX-enabled desktops. |
End-User Connection Traffic Ports and Protocols Requirements
To connect to their Horizon Cloud-provisioned virtual desktops and remote applications from their devices, your end users use a compatible installed Horizon Client or their browser using Horizon Web Client. The following ports must be opened for traffic from the end users' clients to reach their Horizon Cloud-provisioned virtual desktops and remote applications.
| # | Source | Target | Port | Purpose |
|---|---|---|---|---|
| 1 | Horizon Client / Browser | *.horizon.omnissa.com | 443 TCP | Regional Service Gateway redirect — after login, when the end user clicks to launch a desktop, traffic is redirected to UAG via the region-specific Service Gateway URL |
| 2 | Horizon Client / Browser | cloud.omnissahorizon.com | 443 TCP | Client Access URL — required if the end user's own network is restricted/firewalled |
App Volumes Ports and Protocols
To support App Volumes features for use with Horizon Cloud on Google Cloud Platform, you must configure port 445 for TCP protocol traffic to the tenant (desktops) subnet. Port 445 is the standard SMB port for accessing an SMB file share on Microsoft Windows. The AppStacks are stored in an SMB file share located in the same resource group as the Horizon Edge Gateway VMs.
Note: If you use a self-managed Active Directory, on-premises or in the cloud, to manage identities and devices, you can add a Google Cloud Filestore file system to the Active Directory domain. See Google Cloud documentation about using a self-managed Microsoft Active Directory.
Port Requirements for App Volumes
| Source | Target | Port | Protocol | Purpose |
|---|---|---|---|---|
| App Volumes agent in the base imported VM, the golden images, desktop VMs, farm RDSH VMs | The IP address of the Google Cloud Filestore | 445 | TCP | App Volumes application virtualization on the VDI machines and application package capture on the VDI machines depend on access to the fileshares. |
Cloud NAT Requirements
Cloud NAT must be attached to the following VPC subnets to enable the required outbound internet access.
| VPC | Requirement | Reason |
|---|---|---|
| Management VPC | Required | Edge VM requires internet access to download the latest module configurations from the Horizon Cloud control plane |
| Desktop VPC | Required | Desktop VM template requires internet access for agent pairing and OTP redemption with the connection service |
| DMZ VPC | Required | UAG VM requires internet access to retrieve bootstrap data from Horizon Cloud |
VPC Peering Requirements
The following VPC peering connections must be configured before deployment. VPC peering is required in addition to firewall rules to allow traffic to flow between VPCs.
| Peering | Required | Reason |
|---|---|---|
| Management VPC ↔ AD Server VPC | Required | Enables traffic flow between the Edge VM and the AD server VM |
| Desktop VPC ↔ Management VPC | Required | Enables SSO and MQTT telemetry path from desktop VMs to the Edge |
| Desktop VPC ↔ AD Server VPC | Required | Enables desktop VMs to reach the AD server for domain join |
| DMZ VPC ↔ Management VPC | Required | Enables the Edge VM to reach the UAG management console on port 9443 for Day 2 operations |
DNS Configuration Requirements
Two GCP Cloud DNS zones must be configured before deployment to enable internal domain resolution from the Management and Desktop VPCs.
| Zone Type | Applied To | Purpose |
|---|---|---|
| Forwarding zone | AD Server VPC | Forwards internal domain DNS queries from GCP Cloud DNS to the private IP of the AD server VM |
| DNS peering zone | Management VPC and Desktop VPC | Forwards GCP Cloud DNS queries to the forwarding zone so that internal domain names resolve correctly from Edge and desktop VMs |
After deploying the Horizon Edge Gateway and Unified Access Gateway, configure the required external DNS records as described in Configure DNS Records After Deploying Horizon Edge Gateway and Unified Access Gateway.
War diese Seite hilfreich?