Skip to main content

First-Gen Tenants - Endpoints, DNS Names, Ports, and Protocols Requirements When Using Horizon Cloud Connector and a Horizon Pod

When you are using the Horizon Cloud Connector virtual appliance with your Horizon pod, you must configure your firewalls to allow the appliance to access the Domain Name Service (DNS) addresses it needs. In addition, your proxy settings require configured ports and protocols and DNS must resolve specific names as described in this topic. Then, after the Horizon Cloud Connector virtual appliance is deployed and you have completed the steps to successfully connect the pod to Horizon Cloud, specific ports and protocols are required for ongoing operations between Horizon Cloud and the virtual appliance.

Important: The endpoint URLs and ports and protocols requirements documented in this page can change from time to time. For notice when the endpoints change, see the First-Gen Horizon Cloud Release Notes.

Regional Control Plane Instance Shutdown

Beginning on June 28, 2025, Omnissa is initiating a controlled, region-by-region decommissioning of the First-Gen platform. Customers in each region must migrate to the Horizon Cloud platform and fully shut down the First-Gen infrastructure to avoid service disruption. See KB 6000900 for details about the shutdown and required migration.

General Introduction to this Page

  • Use this page solely when you have access to a first-gen tenant environment in the first-gen control plane. As described in KB-92424, the first-gen control plane has reached end of availability (EOA). See that article for details.

  • As described in When Onboarding a Horizon Pod to Use Horizon Subscription Licenses or Cloud-Hosted Services with that Pod, the Horizon Cloud Connector virtual appliance activates subscription licenses on a Horizon deployment and enables use of cloud-hosted services with that Horizon deployment.

  • (Horizon Cloud Connector 2.0 and later) Unless otherwise specified, the following DNS, ports, and protocols requirements apply alike to the primary node and worker node of the Horizon Cloud Connector appliance.

  • As described in Tight Integration Within the Ecosystem, you can use Horizon Cloud with other products available from the broader ecosystem. Those other products might have additional DNS requirements. Such additional DNS requirements are not detailed here. For such DNS requirements, see the documentation set for the specific products that you will be integrating with your cloud-connected Horizon pod.

DNS Requirements for Pod Connectivity and Service Operations that Apply on a Tenant-Wide Basis

This section describes the DNS requirements for pod connectivity and service operations that apply on a tenant-wide basis.

The steps for connecting Horizon Cloud with your Horizon pod using the Horizon Cloud Connector include the step to use a browser to navigate to the Horizon Cloud Connector appliance's IP address and a login screen will appear. To see that login screen requires Internet connectivity between the Horizon Cloud Connector appliance and the Horizon Cloud cloud control plane. The appliance establishes a connection to the Horizon Cloud cloud control plane initially using HTTPS, and then opens a persistent WebSocket connection, using outbound Internet port 443. For ongoing operations, the connection between the Horizon Cloud Connector appliance and Horizon Cloud requires that outbound Internet connection using port 443 open all the time. You must ensure the following Domain Name Service (DNS) names are resolvable and reachable using the specific ports and protocols as listed according to the following tables.

Important:

Keep in mind the following important points:

  • For all tenant accounts, reachability to the following endpoint name is required: cloud.horizon.omnissa.com

  • Reachability of the endpoints is required in addition to reachability to the regional control plane endpoint name for the region specified in your tenant account.

  • Horizon Cloud Connector uses SSL certificates signed by DigiCert, an industry-trusted certificate authority (CA). These certificates use CRL (Certificate Revocation Lists) and OCSP (Online Certificate Status Protocol) queries that refer to specific DNS names on the DigiCert domain. To ensure Horizon Cloud Connector connectivity, you must configure these DNS names to be resolvable and reachable by the virtual appliance. If these DNS names are not reachable, you will not be able to access the Horizon Cloud Connector configuration portal. The specific names are determined by DigiCert, and therefore are not in the Horizon Cloud service's control.

  • If you plan to enable Universal Broker for use with the pod, there are connectivity requirements in addition to the DNS names. For details, see System Requirements for Universal Broker and its related topics.

Your Welcome to Horizon Service email will indicate which regional control plane instance your tenant account was created in. Due to a known issue that existed when the welcome email was sent to you, the email you received might display the system string names used for the regions instead of human-friendly names. If you see a system string name in your welcome email, you can use the following table to relate what is shown in your email with the regional control plane endpoint names.

Your welcome email saysRegional Endpoint Name
USA cloud.horizon.omnissa.com
PROD1_NORTHCENTRALUS2_CP1 or USA-2 cloud-us-2.horizon.omnissa.com
Japancloud-jp.horizon.omnissa.com
Source Destination (DNS name) Port Protocol Purpose
Horizon Cloud Connector The names in the first list plus the appropriate regional names from the second and third lists, depending on which regional control plane instance is specified in your Horizon Cloud tenant account. The regional instance is set when the account is created, as described in First-Gen Tenants - Horizon Cloud Deployments and Onboarding Pods.
  • cloud.horizon.omnissa.com
  • cloud-us-2.horizon.omnissa.com
  • cloud-jp.horizon.omnissa.com
443 TCP Regional control plane instance. Note: In addition to the appropriate regional instance, reachability to the primary endpoints cloud.horizon.omnissa.com is required by Horizon Cloud Connector for all tenant accounts.
  • United States: Names that begin with cloud. and cloud-us-2.
  • Japan: Names that begin with cloud-jp.
Horizon Cloud Connector *.digicert.com If your organization discourages the use of wildcards in allowable DNS names, you can allow specific names instead. For example, at the time of this writing, the specific DNS names required for certificate validation are:
  • ocsp.digicert.com
  • crl3.digicert.com
  • crl4.digicert.com
  • www.digicert.com/CPS
These DNS names are determined by DigiCert and subject to change. For instructions on how to obtain the specific names required by your certificates, refer to Knowledge Base (KB) article 79859.
80, 443 HTTP, HTTPS CRL or OCSP queries used to obtain validation from the certificate authority, DigiCert
Horizon Cloud Connector One of the following names, depending on which regional control plane instance is specified in your Horizon Cloud tenant account. The regional instance is set when the account is created, as described in First-Gen Tenants - Horizon Cloud Deployments and Onboarding Pods.
  • connector-azure-us.omnissahorizon.com
  • connector-azure-jp.omnissahorizon.com
443 TCP Regional instance of the Universal Broker service
  • United States: Names that begin with connector-azure-us.
  • Japan: Names that begin with connector-azure-jp.
Horizon Cloud Connector hydra-softwarelib-cdn.azureedge.net 443 TCP Used to download the necessary OVF and VMDK files from the CDN repository during automatic updates of the Horizon Cloud Connector.

Ports and Protocols Required by the Horizon Cloud Connector Virtual Appliance

For ongoing operations between Horizon Cloud Connector and Horizon Cloud, the ports and protocols in the following table are required.

Horizon Cloud Connector Ports
Source Target Port Protocol Description
Horizon Cloud Connector Horizon Cloud 443 HTTPS Used to pair the Horizon Cloud Connector with Horizon Cloud and transfer data.
Horizon Cloud Connector Connection Server 443 HTTPS API calls to Connection Server.
Horizon Cloud Connector Connection Server 4002 TCP Java Message Service (JMS) communication between the Cloud Connector and the Connection Server
New version of the Horizon Cloud Connector appliance Existing version of the Horizon Cloud Connector appliance 22 SSH Listen for requests to start the update process.
Web browser Horizon Cloud Connector 443 HTTPS Listen for the initiation of the pairing process.
Horizon Cloud Connector SDK endpoint of the vCenter Server, for example: https://<FQDN of vCenter Server>/sdk 443 TCP This optional port configuration is required for use by the automated update feature. The automated update feature is deactivated by default and is only enabled on a per-pod basis by request. See Configure Automated Updates of the Horizon Cloud Connector Virtual Appliance.
Horizon Cloud Connector SDK endpoint of the vCenter Server, for example: https://<FQDN of vCenter Server>/sdk 443 HTTPS This optional port configuration is required for use by the Horizon Image Management Service. You only need to configure this port and protocol if the Horizon Image Management Service feature is enabled for your tenant account. See First-Gen Horizon Cloud - Image Management Service (IMS) Guide.

Was this page helpful?

Provide feedback for this topic

Was this topic helpful?

Please do not include any personal or confidential information.

Generating link…