Skip to main content

7 de octubre de 2026

Configure Network Settings for Google Cloud Platform Edge Deployments

Configure the required network settings for your Horizon Cloud on Google Cloud Platform (GCP) Edge deployments.

Note: Horizon Cloud on Google Cloud Platform is currently available in Limited Availability (LA) mode only.

Because GCP only allows multi-NIC VMs when each NIC is on a different VPC, Horizon on GCP requires three separate VPCs rather than subnets within a single VPC. The required three VPCs are Management, Desktop, and DMZ. Active Directory can be configured on the Management VPC or on-premises; the AD VPC is part of the customer's internal setup and is not covered here.

Critical: Confirm that your internal network CIDRs do not overlap the following values used by Kubernetes inside the Edge Gateway VM:

  • Service CIDR: 192.168.236.0/23
  • Pod CIDR: 192.168.240.0/21

Management VPC

Minimum /26 subnet required.

  1. Create a VPC network for management.
    1. Add Name, description, custom subnet with required region and dynamic regional routing.
    2. By default, egress traffic is allowed from subnets in GCP unless restricted. See VPC firewall rules and VPC networks.
  2. Create public Cloud NAT for the region in which the management subnet is placed so that internet access is enabled for the VM instance on the management network. The Edge VM requires internet access to download the latest configuration of the modules.
    1. Add Gateway name, NAT type — public.
    2. Select VPC network and the region (in which edge will be deployed).
    3. Create Cloud Router.
    4. Keep source endpoint type to VM instance, all other settings as default.
  3. AD reachability: AD module monitoring requires Edge VM to be able to resolve DNS on AD.
    1. In the DNS configuration of VPC, bind the AD peering managed zone created during AD setup.
    2. Add firewall rule to the VPC of AD server to allow ingress from management subnet CIDR.
  4. VPC peering:
    1. VPC peering with AD server VPC is required to enable the traffic flow between Edge VM and AD server VM.
    2. VPC peering between Desktop VPC and Management VPC is required, for the desktop VM to connect via SSO and MQTT telemetry path.
    3. VPC peering between DMZ VPC and Management VPC is required, for the Edge VM to connect to UAG management console for Day 2 operations.

Management VPC Firewall Rules

Firewall ruleDirectionSource IPv4 rangeTargetsProtocols and Ports
Allow Edge to connect to UAG management console on 9443 port (UAG uses edge management subnet for NIC1)IngressCIDR Range of the Management subnetAll instances in the networktcp:9443
Allow desktop VM Horizon Agent to connect with MQTT on edge and for SSO (Also required for internal Desktop VM connection)IngressCIDR Range of the Desktop/tenant subnetAll instances in the networktcp:31883, 32443 udp:31883
Allow Log collection and Diagnostic via SSH IAPIngress35.235.240.0/20 (Google's reserved range for IAP tunneling)All instances in the networktcp:22
Allow east-west traffic for topology (UAG-to-UAG state reroute path) Required only if UAG is being deployed in Advanced mode with /28 subnetIngressCIDR Range of the UAG Management subnetAll instances in the networkudp:8445

Desktop VPC

Minimum /27 subnet required.

Note: A pool can span multiple subnets across one or more VPCs, including a Shared VPC. Ensure each selected subnet has enough free IPs for its share of the pool's VMs.

  1. Create a VPC network for desktop.
  2. Attach Cloud NAT to desktop subnet; desktop VM (template) needs this for agent pairing connection to connection-service to redeem the OTP.
  3. AD reachability: Desktop VM needs line of sight with AD server to join the domain.
    1. In the DNS configuration of VPC, bind the AD peering managed zone created during AD setup.
    2. Add firewall rule to the VPC of AD server to allow ingress from desktop subnet CIDR.
  4. VPC Peering:
    1. VPC peering between Desktop VPC and Management VPC is required, for the desktop VM to connect via SSO and MQTT telemetry path.
    2. VPC peering with AD server VPC is required to enable the traffic flow between desktop VM and AD server VM.

Desktop VPC Firewall Rules

Firewall ruleDirectionSource IPv4 rangeTargetsProtocols and Ports
Allow Internal passthrough Network Load Balancer health check ranges from Google Cloud probers (Required if UAG has internal LB)Ingress130.211.0.0/22 209.85.152.0/22 + Edge Management subnet CIDR (Required for Omnissa private LB IP monitoring)All instances in the network or specify target tagsTCP: 443
Allow Internal user to connect to desktop VMsIngressCIDR Range of the desktop subnet / intranetAll instances in the networktcp: 80, 443, 8443 udp: 443, 8443
Allow Log collection and Diagnostic via SSH IAP (Required if UAG is 2-NIC / Internal Only)Ingress35.235.240.0/20 (Google's reserved range for IAP tunneling)All instances in the networktcp:22
Horizon display-protocol access to pool VMsIngress10000.0.0.0/0Pool VMs (HCS network tag)

Desktop VPC Firewall Rules (created by Horizon Cloud)

During pool provisioning (preparePool), Horizon Cloud creates one firewall rule per VPC referenced by the pool, targeting the pool's VMs via a network tag, to permit the Horizon display-protocol traffic (PCoIP, Blast, Side Channel; RDP/SSH only if enabled). If the firewall-management permissions (compute.firewalls.*, and for a Shared VPC the same permissions in the host project) are granted to the HCS service account, these rules are created automatically. If not, the customer admin must create equivalent rules manually.

DMZ VPC

Not required if you are deploying UAG in internal access mode only.

Minimum /27 subnet required.

  1. Create a VPC network for DMZ.
  2. Cloud NAT is required — this is required as the UAG VM needs to call Horizon to get the bootstrap data.
  3. VPC Peering:
    1. VPC peering between DMZ VPC and Management VPC is required, for the Edge VM to connect to UAG management console for Day 2 operations.

DMZ VPC Firewall Rules

Firewall ruleDirectionPrioritySource IPv4 rangeTargetsProtocols and Ports
Allow external passthrough Network Load Balancer health check ranges from Google Cloud probers (Required if UAG has external LB)Ingress100035.191.0.0/16, 209.85.152.0/22, 209.85.204.0/22All instances in the network or specify target tagsTCP: 443
Allow External Users to connect to UAGIngress10000.0.0.0/0All instances in the network or specify target tagsTCP: 80 (HTTP) TCP: 443 (HTTPS) TCP: 8443 (Blast TCP) UDP: 443 (Blast UDP) UDP: 8443 (Blast UDP)
Allow Log collection and Diagnostic via SSH IAPIngress100035.235.240.0/20 (Google's reserved range for IAP tunneling)All instances in the network or specify target tagstcp:22

Unified Access Gateway Requirements

Machine Type

Choose a machine type with minimum 4 vCPU and 16 GB Memory to support 2000 sessions.

Disk Type

Make sure the disk type chosen is compatible with the machine type; not all disk types are supported by all machine types. Refer to: Machine families resource and comparison guide.

DNS Configuration

Two GCP Cloud DNS zones must be configured before deployment to enable internal domain resolution from the Management and Desktop VPCs.

Step 1 — Create a Forwarding Zone for AD DNS (Required)

Create a forwarding rule for on-prem AD DNS from the AD server VPC to the AD VM IP:

Cloud DNS > Zone > Create Zone > Private > DNS name (on-prem DNS name) > Options > Forward query to another server > Network (select AD server VPC) > Destination DNS servers > add Private IP address of AD server > keep Private forwarding option unchecked.

Step 2 — Create a DNS Peering Zone (Required)

Create a DNS peering zone; this will forward the GCP Cloud DNS query to the Forwarding zone (on-prem AD server).

Make sure this is applied to management and desktop VPCs.

After deploying the Horizon Edge Gateway and Unified Access Gateway, configure the required external DNS records as described in Configure DNS Records After Deploying Horizon Edge Gateway and Unified Access Gateway.

¿Le resultó útil esta página?

Enviar comentarios sobre este tema

¿Le resultó útil este tema?

No incluya información personal ni confidencial.

Generando el enlace…