When you are using the Horizon Cloud Connector virtual appliance with your Horizon pod, you must configure your firewalls to allow the appliance to access the Domain Name Service (DNS) addresses it needs. In addition, your proxy settings require configured ports and protocols and DNS must resolve specific names as described in this topic. Then, after the Horizon Cloud Connector virtual appliance is deployed and you have completed the steps to successfully connect the pod to Horizon Cloud, specific ports and protocols are required for ongoing operations between Horizon Cloud and the virtual appliance.
Beginning on June 28, 2025, Omnissa is initiating a controlled, region-by-region decommissioning of the First-Gen platform. Customers in each region must migrate to the Horizon Cloud platform and fully shut down the First-Gen infrastructure to avoid service disruption. See KB 6000900 for details about the shutdown and required migration.
General Introduction to this Page
-
Use this page solely when you have access to a first-gen tenant environment in the first-gen control plane. As described in KB-92424, the first-gen control plane has reached end of availability (EOA). See that article for details.
-
As described in When Onboarding a Horizon Pod to Use Horizon Subscription Licenses or Cloud-Hosted Services with that Pod, the Horizon Cloud Connector virtual appliance activates subscription licenses on a Horizon deployment and enables use of cloud-hosted services with that Horizon deployment.
-
(Horizon Cloud Connector 2.0 and later) Unless otherwise specified, the following DNS, ports, and protocols requirements apply alike to the primary node and worker node of the Horizon Cloud Connector appliance.
-
As described in Tight Integration Within the Ecosystem, you can use Horizon Cloud with other products available from the broader ecosystem. Those other products might have additional DNS requirements. Such additional DNS requirements are not detailed here. For such DNS requirements, see the documentation set for the specific products that you will be integrating with your cloud-connected Horizon pod.
DNS Requirements for Pod Connectivity and Service Operations that Apply on a Tenant-Wide Basis
This section describes the DNS requirements for pod connectivity and service operations that apply on a tenant-wide basis.
The steps for connecting Horizon Cloud with your Horizon pod using the Horizon Cloud Connector include the step to use a browser to navigate to the Horizon Cloud Connector appliance's IP address and a login screen will appear. To see that login screen requires Internet connectivity between the Horizon Cloud Connector appliance and the Horizon Cloud cloud control plane. The appliance establishes a connection to the Horizon Cloud cloud control plane initially using HTTPS, and then opens a persistent WebSocket connection, using outbound Internet port 443. For ongoing operations, the connection between the Horizon Cloud Connector appliance and Horizon Cloud requires that outbound Internet connection using port 443 open all the time. You must ensure the following Domain Name Service (DNS) names are resolvable and reachable using the specific ports and protocols as listed according to the following tables.
Important:
Keep in mind the following important points:
-
For all tenant accounts, reachability to the following endpoint name is required:
cloud.horizon.omnissa.com -
Reachability of the endpoints is required in addition to reachability to the regional control plane endpoint name for the region specified in your tenant account.
-
Horizon Cloud Connector uses SSL certificates signed by DigiCert, an industry-trusted certificate authority (CA). These certificates use CRL (Certificate Revocation Lists) and OCSP (Online Certificate Status Protocol) queries that refer to specific DNS names on the DigiCert domain. To ensure Horizon Cloud Connector connectivity, you must configure these DNS names to be resolvable and reachable by the virtual appliance. If these DNS names are not reachable, you will not be able to access the Horizon Cloud Connector configuration portal. The specific names are determined by DigiCert, and therefore are not in the Horizon Cloud service's control.
-
If you plan to enable Universal Broker for use with the pod, there are connectivity requirements in addition to the DNS names. For details, see System Requirements for Universal Broker and its related topics.
Your Welcome to Horizon Service email will indicate which regional control plane instance your tenant account was created in. Due to a known issue that existed when the welcome email was sent to you, the email you received might display the system string names used for the regions instead of human-friendly names. If you see a system string name in your welcome email, you can use the following table to relate what is shown in your email with the regional control plane endpoint names.
| Your welcome email says | Regional Endpoint Name |
|---|---|
USA |
cloud.horizon.omnissa.com
|
PROD1_NORTHCENTRALUS2_CP1 or USA-2 |
cloud-us-2.horizon.omnissa.com
|
Japan | cloud-jp.horizon.omnissa.com
|
| Source | Destination (DNS name) | Port | Protocol | Purpose |
|---|---|---|---|---|
| Horizon Cloud Connector |
The names in the first list plus the appropriate regional names from the second and third lists, depending on which regional control plane instance is specified in your Horizon Cloud tenant account. The regional instance is set when the account is created, as described in First-Gen Tenants - Horizon Cloud Deployments and Onboarding Pods.
| 443 | TCP |
Regional control plane instance.
Note: In addition to the appropriate regional instance, reachability to the primary endpoints cloud.horizon.omnissa.com is required by Horizon Cloud Connector for all tenant accounts.
|
| Horizon Cloud Connector |
*.digicert.com
If your organization discourages the use of wildcards in allowable DNS names, you can allow specific names instead. For example, at the time of this writing, the specific DNS names required for certificate validation are:
| 80, 443 | HTTP, HTTPS | CRL or OCSP queries used to obtain validation from the certificate authority, DigiCert |
| Horizon Cloud Connector |
One of the following names, depending on which regional control plane instance is specified in your Horizon Cloud tenant account. The regional instance is set when the account is created, as described in First-Gen Tenants - Horizon Cloud Deployments and Onboarding Pods.
| 443 | TCP |
Regional instance of the Universal Broker service
|
| Horizon Cloud Connector | hydra-softwarelib-cdn.azureedge.net | 443 | TCP | Used to download the necessary OVF and VMDK files from the CDN repository during automatic updates of the Horizon Cloud Connector. |
Ports and Protocols Required by the Horizon Cloud Connector Virtual Appliance
For ongoing operations between Horizon Cloud Connector and Horizon Cloud, the ports and protocols in the following table are required.
| Source | Target | Port | Protocol | Description |
|---|---|---|---|---|
| Horizon Cloud Connector | Horizon Cloud | 443 | HTTPS | Used to pair the Horizon Cloud Connector with Horizon Cloud and transfer data. |
| Horizon Cloud Connector | Connection Server | 443 | HTTPS | API calls to Connection Server. |
| Horizon Cloud Connector | Connection Server | 4002 | TCP | Java Message Service (JMS) communication between the Cloud Connector and the Connection Server |
| New version of the Horizon Cloud Connector appliance | Existing version of the Horizon Cloud Connector appliance | 22 | SSH | Listen for requests to start the update process. |
| Web browser | Horizon Cloud Connector | 443 | HTTPS | Listen for the initiation of the pairing process. |
| Horizon Cloud Connector | SDK endpoint of the vCenter Server, for example: https://<FQDN of vCenter Server>/sdk | 443 | TCP | This optional port configuration is required for use by the automated update feature. The automated update feature is deactivated by default and is only enabled on a per-pod basis by request. See Configure Automated Updates of the Horizon Cloud Connector Virtual Appliance. |
| Horizon Cloud Connector | SDK endpoint of the vCenter Server, for example: https://<FQDN of vCenter Server>/sdk | 443 | HTTPS | This optional port configuration is required for use by the Horizon Image Management Service. You only need to configure this port and protocol if the Horizon Image Management Service feature is enabled for your tenant account. See First-Gen Horizon Cloud - Image Management Service (IMS) Guide. |
Was this page helpful?